Privacy Policy
Last updated 8 September 2026. This policy explains what we collect, why, and what you control. It is written to be read.
1. What we collect
Account data — name, work email, company, and the billing contact for your plan. Workspace data — the documents, records, and messages you connect so Dutta can do its job. Usage data — feature usage, performance, and error telemetry.
Card numbers are deliberately absent from that list. They go straight to Stripe and never reach us — see Payments below.
2. Messaging and voice channels (WhatsApp, Telegram, Slack, SMS and voice calls)
Users may connect a WhatsApp, Telegram or Slack account, or a phone number for SMS and voice calls, to their Dutta account by sending a one-time verification code generated inside the Dutta web app. Linking is always initiated by the user.
WhatsApp is operated by Meta Platforms, Telegram by Telegram FZ-LLC, and Slack by Slack Technologies, a Salesforce company. Each of those integrations runs through that platform’s bot interface, which means your messages cross the operator’s own infrastructure, under its own terms and privacy policy, before they reach us. What the operator retains on its side is outside our control. Linking a channel gives Dutta no access to the rest of your WhatsApp, Telegram or Slack account — only the messages you send to the Dutta bot, or send in a Slack channel you invite it into.
SMS messages and voice calls do not run through a chat platform. They travel over the telephone network, and Twilio carries them for us — the texts and calls you send in, the assistant’s replies, and any call Dutta places to you. Twilio moves them on our instruction rather than on its own account, which is what makes it a processor and the chat platforms above independent operators: Twilio is listed in Sub-processors below, and they are not. The mobile networks either side of it carry your texts and calls on their own terms, exactly as they carry any other.
When a channel is linked, we process: the identifier that channel gives us — the phone number you message or call us from on WhatsApp, SMS and voice, and the platform account identifier on Telegram and Slack, which on Slack arrives with the workspace and the channel the message was sent in — the content of messages you send to the assistant, and any voice notes you send or turns you speak on a call, which are transcribed to text so the assistant can respond. A short rolling window of recent messages is retained on every channel to give the assistant conversational context; older messages are discarded.
This data is used solely to operate the assistant for the account you linked. It is not used for advertising, is not sold, and is not shared with other users or organisations. Message content is processed by our AI provider (Google Gemini) purely to generate a response.
You can unlink a channel at any time from Profile → Chat Channels, which stops all message processing and removes the stored conversation context. Channels are unlinked one at a time: removing WhatsApp leaves a linked Telegram, Slack or phone number exactly as it was, and unlinking a phone number ends both the SMS and the voice side of it.
3. Google Sign-In and connected Google data
You can sign in to Dutta with your Google account, and you can separately connect Google services so an AI employee can work in them on your behalf. These are two different grants, and the second one always names what it covers.
Signing in uses only the standard OpenID Connect scopes — openid, email and profile — which return your name, email address, profile picture, and Google account identifier. That is enough to create your account and recognise you on return. It gives us no access to anything else in your Google account.
Connecting a service is the second grant. Each one requests a single read-only scope, and nothing wider:
- Gmail — gmail.readonly. Reads the messages in the mailbox you connect. Dutta cannot send, reply to, modify, or delete mail.
- Google Calendar — calendar.readonly. Reads the events in the calendar you connect. Dutta cannot create, move, or cancel anything.
- Google Drive — drive.readonly. Reads the files in the Drive you connect. Dutta cannot edit, share, or delete them.
Each scope is requested on its own, at the moment you connect that service, and covers only that service: connecting Gmail grants nothing in Calendar or Drive. Google shows you the scope on its consent screen before anything is shared, you choose whether to approve it, and you can withdraw it at any time — from your Google account’s third-party access settings, or from inside Dutta. The tokens Google issues are stored encrypted, and we use what the scopes return only to perform the task you asked for.
Dutta’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In particular: we do not use data received from Google APIs to develop, improve, or train generalised AI or machine-learning models, we do not sell it, and we do not transfer it to others except as needed to provide the service you asked for, for security purposes, or where the law requires it. No human reads it except where you ask support to investigate an issue, or in those same narrow cases.
4. Payments
Subscriptions are paid by card, and payments are processed by Stripe. Card details are entered directly with Stripe and never reach Dutta’s systems — we do not see, handle, or store your card number. Stripe returns a reference that lets us charge the plan you agreed to.
What we hold is the billing contact, the plan, and the invoice history, which we keep for as long as tax and accounting law requires — this is the one category that outlives the deletion schedule in Retention below.
5. Why we process it
To provide the service, to bill you, to keep the platform secure, and to support you when you ask. We process workspace data solely on your instruction, as your processor.
6. What we never do
We do not sell personal data. We do not use your workspace data to train shared or third-party models. We do not read your workspace content except when you explicitly ask support to investigate an issue.
7. Cookies and tracking
This website runs no advertising or analytics trackers. There is no third-party advertising pixel on it — Meta’s included — which is why you are not being asked to dismiss a consent banner. Meta Platforms appears in this policy in one capacity only: as the operator of WhatsApp, for users who choose to link that channel.
Signing in to the Dutta application sets only the strictly necessary cookies that keep your session authenticated.
8. Sub-processors
We use a short list of infrastructure and model providers, each under a data-processing agreement. This is the current list, correct as of the date above. Customers on Company and Enterprise plans are notified before it changes.
- Nhost — hosts the application database, where your workspace data is stored.
- Netlify — hosts this website and receives anything you submit through the contact form (your name, work email, company and message).
- Twilio — carries SMS messages and voice calls between you and the assistant, on our instruction. It handles the phone number you linked, the text of those messages, and the audio of those calls, in transit.
- Stripe — processes subscription payments. Card details are entered directly with Stripe; they never reach our systems, and we never store them.
- Google — generates assistant responses from the message content you send, including messages received through a linked channel, and transcribes voice notes and spoken turns to text (Gemini). Google is also the identity provider behind Google Sign-In, and the source of any Google service data you connect.
Meta Platforms, Telegram FZ-LLC and Slack Technologies are not on this list. They operate WhatsApp, Telegram and Slack as independent providers rather than processing data on our instruction: if you link a channel, your messages cross their infrastructure on their terms, not ours. Twilio is on the list for the opposite reason — it carries SMS and voice for us, on our instruction. See Messaging channels above.
For a copy of the data-processing agreements, or to ask about a specific provider, contact privacy@dutta.io.
9. Your rights
Access, correction, export, and deletion — on request, or self-serve in the workspace settings. EU/UK users have the full set of GDPR rights; contact privacy@dutta.io.
10. Retention
Workspace data is retained while your account is active and for 30 days after cancellation, then permanently deleted. Audit logs are retained per your configured policy.
Messages from a linked messaging or voice channel are the exception: they are not retained on that schedule. Only a short rolling window of recent messages is kept, to give the assistant conversational context, and older messages are discarded as it moves. Unlinking the channel removes the stored context outright. See Messaging channels above.
Billing records are the other exception, and run the other way: invoices are kept for as long as tax and accounting law requires. See Payments above.
11. Contact
Data controller: Dutta Technologies. Data protection enquiries: privacy@dutta.io.