Privacy Policy
Effective date: August 4, 2026
1. Introduction
This Privacy Policy explains how Meerlume LLC, a limited liability company registered in the Republic of Armenia (operator of the Meerlume service, “Meerlume,” “we,” “us”) collects, uses, shares, and protects personal data when you use our bot-building platform for WhatsApp, Telegram, and related channels. It also describes the rights available to you under applicable data-protection law, including the EU and UK GDPR, the California Consumer Privacy Act (CCPA/CPRA), Brazil’s LGPD, and similar laws in other jurisdictions.
Two roles are relevant to this policy:
- For your account information and your use of Meerlume, we are the data controller.
- For data collected by your bots from your end customers (their messages, phone numbers, names, booking details), you are the controller and we act as your processor. A Data Processing Addendum (DPA) is available on request at privacy@meerlume.com.
2. Information We Collect
Account data. When you sign up we collect your email, name, password (stored hashed), and, if you sign in with Google or another OAuth provider, the basic profile information and tokens that provider returns. Account authentication runs on our own servers; we do not use a third-party authentication provider.
Bot configuration data. Bot names, descriptions, flow definitions, prompts, instructions, channel settings, and any drafts you save while using the builder, including the chat transcript of your conversation with the AI builder.
Channel credentials. If you connect a WhatsApp Business or Telegram bot, we store the relevant identifiers and tokens: your WhatsApp Business Account (WABA) ID, phone-number ID, display phone number, and access token; and, for Telegram, the bot token. These credentials are encrypted at rest.
Notification settings. If you enable owner notifications, we store your notification preferences and the delivery details needed to reach you — for example, the Telegram chat identifier created when you link our notification bot, or a per-bot notification address. Notifications themselves contain submission details (such as the booking summary your template includes).
Support requests. If you contact support, we receive the email address, subject, category, and message you submit, and we retain that correspondence to resolve your request.
End-customer data your bots collect. When your end customers interact with your bots on WhatsApp or Telegram, we receive and store their messages, the phone numbers or usernames the messaging platform exposes, the structured answers they provide to your bot’s questions, conversation transcripts (including messages you exchange with a customer when you take over a conversation), and any booking details they submit (including name, contact details, time slot, and notes). We process this data on your behalf to deliver the Service.
Payment data. Subscription payments are processed by Paddle as Merchant of Record. We do not receive or store full payment-card details; we receive only transaction-level data such as plan, status, last four digits, and billing country needed to provision your subscription.
Technical data. Our backend automatically logs IP addresses and request metadata for security, debugging, and abuse-prevention purposes. We also use a small number of cookies and local-storage entries described in section 10.
3. How We Use Information
- To provide, operate, and maintain the Service.
- To authenticate you, secure your account, and prevent abuse.
- To deliver your bot’s messages to and from end customers via the chosen messaging platform.
- To send you the notifications you have configured about activity in your bots — in the dashboard, by Telegram, or by email — such as new submissions awaiting your review.
- To improve the Service, diagnose issues, and develop new features.
- To communicate with you about service updates, security notices, and (with your consent where required) marketing.
- To comply with legal obligations and respond to lawful requests.
4. Legal Bases for Processing (GDPR / UK GDPR)
- Contract — to provide the Service you have signed up for.
- Legitimate interests — to keep the Service secure, prevent fraud, and improve our product.
- Consent — for any optional marketing communications and any non-essential cookies (we do not currently use any).
- Legal obligation — to comply with applicable law and respond to lawful requests from authorities.
5. Sub-processors and Third Parties
We share personal data with the following sub-processors strictly to provide the Service:
- Neon (database hosting, EU — AWS eu-central-1, Frankfurt). Receives account data, bot configuration, and end-customer data your bots store.
- Railway (application hosting, EU region). Runs our backend API and the services that send and receive WhatsApp and Telegram messages, so it processes everything those services handle, including message content and phone numbers.
- Cloudflare (static site hosting, DNS, CDN, and TLS termination for meerlume.com). Serves the dashboard and marketing site and processes connection metadata such as IP addresses in that role. Your bots’ conversations are not stored by Cloudflare.
- Google (Gemini API) for AI-assisted bot building. Receives the bot descriptions, prompts, and instructions you type into the builder. Live conversations with your end customers are executed by our own flow engine and are not sent to the Gemini API. Subject to Google’s API terms and data-handling policies.
- Brevo for email delivery. For transactional email (support correspondence and notifications you configure) it receives the recipient address and message content. If you opt in to product and marketing emails, we also sync your email address, first name, and consent state to Brevo’s contact list. If you later opt out, Brevo keeps your address on a suppression list so we cannot email you again by mistake.
- Meta Platforms (WhatsApp Business / Cloud API) for message routing on WhatsApp. Receives the messages, phone numbers, and metadata necessary to send and receive WhatsApp conversations.
- Telegram FZ-LLC for message routing on Telegram. Receives the messages and user identifiers necessary to operate your Telegram bot and, if you enable Telegram notifications, the owner notifications we deliver to you through our notification bot.
- Paddle as our Merchant of Record for billing, invoicing, and tax compliance. Receives transaction and billing-country data.
We do not sell, rent, lease, or trade your personal data or your end customers’ data; we do not share it for advertising, ad targeting, ad measurement, or cross-context behavioural advertising; and we do not use it to train machine-learning or AI models, our own or anyone else’s.
6. WhatsApp Business Platform Data
Where you connect a WhatsApp channel, Meerlume receives and processes data from Meta’s WhatsApp Business Platform (the WhatsApp Business / Cloud API) on your behalf, as your processor. This section states in one place how we handle that Platform Data.
What we receive and store. Inbound and outbound message content and any media attached to it; the end customer’s WhatsApp phone number and profile name; message and conversation identifiers and delivery status; the structured submission payloads your bot collects (form answers, booking details, names, contact details, notes); and your channel identifiers and credentials — WABA ID, phone-number ID, display phone number, and access token.
Why we process it. Solely to run the conversational flow you configured — receiving each inbound message, evaluating it against your flow, and sending the reply — and to deliver the resulting submissions to you in your dashboard and through the notification channels you enable. We do not process Platform Data for our own independent purposes.
How long we keep it. Conversations and submissions remain available while your account is active, because they are the record of your customer relationships and you decide when they go; you can delete any conversation, contact, or bot at any time. When you delete your account, or ask us to delete specific data, Platform Data is deleted within 30 days — in practice immediately for account deletion, which runs synchronously. Notification and delivery records containing submission details are pruned automatically 30 days after they settle, whether or not you ask. Server access and security logs are kept 30 days. Residual copies in our database provider’s point-in-time recovery window are overwritten within 24 hours.
What we never do with it. We do not sell, rent, lease, or trade Platform Data. We do not use it for advertising, ad targeting, or ad measurement. We do not use it to train machine-learning or AI models. Live conversations with your end customers are executed by our own flow engine and are never sent to a third-party AI provider — the Gemini API sees only the text you type into the builder while designing a bot, never your customers’ messages.
Who else sees it. Only the sub-processors in section 5 that are needed to operate the channel: Neon (storage), Railway (the services that run the flow), and, where you turn them on, Brevo or Telegram to deliver notifications to you. We do not share Platform Data with any other third party except where required by law.
Where it lives. In the European Union — see section 7.
How to have it deleted. Account owners can delete in-app from Settings, and anyone — including an end customer who messaged one of your bots — can write to privacy@meerlume.com. Our Data Deletion page sets out both routes, what is removed, and the timelines above.
7. Where Your Data Is Stored and Processed
Your account data, bot configuration, conversations, and the data your bots collect are stored and processed in the European Union. Our database runs on Neon in AWS eu-central-1 (Frankfurt, Germany) and our application services run on Railway in an EU region. We currently operate no other storage or compute region.
We may add regions in other locations in future — for example to put data closer to customers outside Europe. If we do, we will update this section before any data is moved, and material changes are announced as described in section 13.
Some processing necessarily happens outside the EU, because the service connects to platforms and providers that operate globally: Meta routes WhatsApp messages, Telegram routes Telegram messages, Cloudflare terminates connections at the edge location nearest the visitor, Brevo delivers email, Paddle processes payments, and the Gemini API answers builder prompts. Where those transfers leave the EU/UK they are made under appropriate safeguards, such as the European Commission’s Standard Contractual Clauses or the UK International Data Transfer Addendum.
8. Data Retention
We retain personal data only for as long as needed for the purposes described in this policy.
- Account data is retained while your account is active. When you delete your account we delete it immediately, along with your bots, conversations, and end-customer data. Residual copies may persist for up to 24 hours in our database provider’s point-in-time recovery window before being overwritten.
- Bot configuration and end-customer data is retained until you delete it or close your account, and in any case is deleted within 30 days of a deletion request.
- Notification and delivery records containing submission details are pruned automatically 30 days after delivery settles.
- Server access and security logs are retained for up to 30 days.
- We may retain limited information for longer where necessary to comply with legal obligations, resolve disputes, or enforce our agreements.
Our Data Deletion page sets out how to request deletion, what is removed, and the billing records we must keep.
9. Your Rights
Subject to applicable law, you have the right to:
- access the personal data we hold about you;
- request correction of inaccurate data;
- request deletion of your data;
- request restriction of, or object to, certain processing;
- request a portable copy of your data;
- withdraw any consent you previously gave (without affecting the lawfulness of prior processing);
- lodge a complaint with your local data-protection authority.
California residents have additional rights under the CCPA/CPRA, including the right to know what personal information we collect, the right to delete it, and the right to opt out of “sale” or “sharing” — note that we do not sell or share personal information as those terms are defined under the CCPA.
To exercise any of these rights, email us at privacy@meerlume.com. We will respond within 30 days, as required by the GDPR; if a request is complex or we receive a high volume of requests, we may extend that period by a further two months and will tell you why. If your request concerns data your bot collected from one of your end customers, that customer should contact you (the controller) directly; we will support you in fulfilling such requests under the DPA.
10. Cookies & Local Storage
We use only strictly necessary and functional storage:
- A session cookie we set to keep you signed in.
- A small
sidebar_statecookie that remembers whether you collapsed the dashboard sidebar. - Browser
localStorageentries that hold your theme preference, calendar view choice, panel-collapsed state, a flag recording whether you are signed in (used only to avoid a flash of the wrong layout), and the drafts and AI chat history you create in the bot builder before you sign up.
We do not use analytics, advertising, session replay, or cross-site tracking cookies. If we ever add any, we will update this policy and present a consent banner where required.
11. Children's Privacy
The Service is not directed to children under 16 and we do not knowingly collect personal data from them. If you believe a child has provided us personal data, please contact privacy@meerlume.com and we will delete it.
12. Security
We use industry-standard security measures including TLS in transit, encryption at rest for sensitive credentials (such as your WhatsApp access tokens and Telegram bot tokens), access controls, and least-privilege production access. No system can be guaranteed perfectly secure; if we become aware of a breach that affects you, we will notify you as required by applicable law.
13. Changes to This Policy
We may update this Privacy Policy from time to time. The “Effective date” at the top of this page reflects the latest revision. If a change is material we will provide reasonable notice (for example, by email or through the Service) before it takes effect.
14. Contact
Questions, requests, or complaints about this Policy can be sent to privacy@meerlume.com. See also our Terms of Service, Refund Policy, and contact page.
The data controller is Meerlume LLC, a limited liability company registered in the Republic of Armenia, registered at Moskovyan 28, apt. 159, 0002 Yerevan, Armenia.