Privacy Policy

Last updated: 31 July 2026

Published at chatify.chat/privacy. Older links to this policy on our chatify-app-chatifysg.vercel.app address continue to work and show the same document. The terms businesses use Chatify under are in our Terms of Service.

Who we are

Chatify (“Chatify”, “we”, “us”) provides an AI-assisted customer-messaging service that lets businesses receive and reply to customer messages from channels such as WhatsApp, Instagram and Messenger in one shared inbox, and handle everyday requests like bookings, trials and rentals in the chat. We are based in Singapore. This policy explains what information we handle and how. For any privacy question or request, contact us at support@chatify.sg.

Our role

Chatify is used by a business to talk to its own customers. For the messages and customer records inside a business’s account, that business decides what is collected and why, and we handle the information on its behalf and under its instructions. If you messaged a business and want your information corrected or deleted, contacting that business is usually fastest — but you can also write to us and we will help. For the business’s own account information (its users, logins and billing details) we decide the purposes ourselves.

Information we handle

  • Messages & conversation content you and your customers send through connected channels — text, voice notes, images and files — plus message metadata (timestamps, message IDs, delivery and read status).
  • Customer contact identifiers provided by the messaging platform — e.g. a WhatsApp phone number, an Instagram-scoped user ID, and a display name where available — together with tags and notes a business’s team adds.
  • Details a customer gives the assistant to complete a request: a name, a preferred class, service or date, an age or age group for a class, a vehicle or item being serviced or rented, and similar booking details. Where a business asks for them, this can include files a customer chooses to send as proof — for example a payment screenshot or a medical certificate supporting a membership pause.
  • Business account information for the people who use Chatify on a business’s behalf: email address and login credentials, team membership and role, and — if they turn on notifications — a browser push subscription for their device.
  • Knowledge a business adds (business facts, question-and-answer rules, uploaded documents, price lists) that the assistant uses to answer.
We do not ask customers for, and businesses should not collect through Chatify, sensitive financial credentials, full payment card numbers, or government identifiers.

How we use it

  • To deliver the service: receive incoming messages, generate AI-assisted replies from the business’s own knowledge, complete requests such as bookings and trials, and route conversations to human team members when needed.
  • To maintain conversation history and contact records so a team has context, and to notify staff about conversations and tasks that need them.
  • To send follow-ups, reminders and — where a business runs them and the customer has not opted out — campaign messages on that business’s behalf.
  • To operate, secure, and improve the service, including detecting spam, scams and abuse, and blocking senders a business marks as unwanted.
We do not sell personal information.

How the AI works

Replies are generated by Google’s Gemini models. To answer a message, the relevant part of the conversation and the matching pieces of the business’s own knowledge are sent to Google’s API and a reply comes back; uploaded documents are stored with Google’s managed file-search service so the assistant can retrieve passages from them. The assistant is built to answer only from the knowledge a business has given it, and to hand the conversation to a human rather than guess. Chatify can also propose new knowledge by reviewing past conversations, but a proposal is never used to answer anyone until someone from the business approves it. We do not use your conversations to train AI models of our own.

Service providers we share with

We use trusted providers to run Chatify, and information is processed by them only to provide the service:
  • Meta Platforms — message delivery via the WhatsApp Business, Instagram and Messenger messaging APIs.
  • Supabase — database, file storage and authentication hosting.
  • Google (Gemini API) — generating replies and retrieving answers from a business’s knowledge, including documents it uploads.
  • Vercel — application hosting.
  • Resend — sending account emails such as password resets.
  • Apple, Google and Microsoft push services — delivering notifications to a staff member’s device, if they switch notifications on.
  • Zapier — only where a business connects it, to pass a sign-up or booking it has just taken into that business’s own systems (for example its gym-management software). The destination is chosen and controlled by the business.
We may also disclose information if the law requires it, or to protect the rights and safety of our users and the public.

Where information is processed

Chatify is operated from Singapore, but the providers above process data on servers in other countries. Where information is transferred out of Singapore, we rely on those providers’ contractual commitments to protect it to a standard comparable to Singapore’s Personal Data Protection Act.

Data retention

  • Conversations, contacts and knowledge are retained for as long as a business’s account is active, or as needed to provide the service.
  • Proof files a customer sends to support a request — such as a payment screenshot or a medical certificate — are deleted, along with the links pointing to them, 30 days after the related request is resolved.
  • In-progress request details held while the assistant is completing a booking or sign-up are cleared automatically once the request finishes or is abandoned.
A business can request deletion of its data, and we delete or anonymise it within a reasonable period unless we must keep it to meet legal obligations.

Security

Each business’s data is isolated from every other business’s at the database level, and access is protected by authentication and per-business access controls. Files sent in a conversation are stored in a private bucket and opened through short-lived links issued only to people who belong to that business. Channel access tokens are stored encrypted, and data is transmitted over secure connections. No method of transmission or storage is perfectly secure, but we work to protect your information.

Your choices & rights

Customers can stop messaging the business at any time, and can reply STOP to opt out of marketing messages. Depending on your location, you may have rights to access, correct, or delete personal information. To make a request — as a business user or as a customer of a business using Chatify — email support@chatify.sg and we’ll respond. We may need to ask the business that holds your conversation to action it, and we will pass your request on. Step-by-step instructions for a deletion request are on our Data Deletion Instructions page.

Children

Chatify is a tool for businesses and is not directed to, or intended to be used by, children. Some businesses run classes and activities for children: in that case a parent or guardian may give us a child’s first name and age so a class can be booked, and we handle that information on the business’s behalf for that purpose only. We do not knowingly collect information directly from a child, and a parent or guardian can email us to have it removed.

Changes

We may update this policy; we’ll revise the “Last updated” date above when we do. Continued use after a change means you accept the updated policy.

Contact

Questions about this policy or your data? Email support@chatify.sg.