Privacy Policy
1. Who we are
Chatter is operated by Thrive LLC. We are the data controller for our own websites, and the data processor for customer data handled inside Chatter.
Thrive Holding, Appstairs and Chatter are brand names used by Thrive LLC. They are not separate legal entities and do not hold their own trade licences; the contracting entity for all of them is Thrive LLC.
- Legal form: Limited Liability Company
- Trade licence 1700077.01, issued by Sharjah Media City (Shams), United Arab Emirates
- Registered address: Sharjah Media City (Shams), Sharjah, UAE
- Office: Level 14, Boulevard Plaza Tower 1, Downtown Dubai, UAE
2. Who this policy covers
- Our customers — businesses that use Chatter and connect their own messaging accounts to it.
- End users — people who message one of those businesses. We handle their data on behalf of the business they contacted, and only under that business's instructions.
3. What we access from connected accounts
When a customer connects a messaging account, we access only what is needed to run their shared inbox:
- Message content — text, attachments and voice notes exchanged with the business.
- Sender identifiers — platform user ID, display name, profile picture, and phone number or handle.
- Comment content — public comments on the business's posts, where the channel supports handling comments in the inbox.
- Post metadata — identifiers, timestamps and captions of the business's own posts, used to give a comment its context.
- Account profile data — the connected business account's own name, ID, avatar and settings.
This applies to the channels a customer connects: WhatsApp, Instagram, Messenger, Telegram and live web chat. It will also apply to TikTok once that integration is available; TikTok is not currently a supported channel.
We access this data only through each platform's official API, using the permissions granted at connection. We do not scrape, and we do not use unofficial access methods.
4. Why we access it
Solely to operate the shared inbox for the business that authorized the connection — delivering and displaying messages, threading them by contact, routing them to the right agent, running the automations the customer configured, and producing that customer's own analytics.
We do not use connected-account data for our own purposes or for any other customer.
5. Separation between customers
Chatter is multi-tenant. All connected-account data is stored against the customer organization that owns it and is isolated at the data layer. No customer can access another customer's conversations, contacts or connected accounts, and there is no cross-tenant pooling or aggregation of message content.
6. What we never do
We do not sell personal data.
We do not share personal data with third parties for advertising, ad targeting or data brokerage.
We do not use customer message content to train AI models. Message content, comments and contact data belonging to our customers and their end users are never used to train, fine-tune or improve our own models or any third-party model. Our AI features process message content only to produce a response for that specific conversation, in real time, for the business that owns it.
7. AI features
Chatter includes AI reply suggestions, intent detection, voice transcription and translation. To provide these, message content may be sent to third-party model providers acting as our sub-processors, under agreements that prohibit training on our data and require short or zero retention.
We do not send message content to any AI provider except to deliver a feature the customer has enabled.
A current list of the sub-processors we use — for hosting, AI features, email delivery, analytics and payments — naming each provider, its purpose and the region it processes data in, is available on request from the contact address below.
8. Storage and security
- Where data is stored. Customer data — message content, contacts and connected-account tokens — is stored in the European Union, in Amazon Web Services' Ireland region (eu-west-1). Some sub-processors, such as AI model providers, may process message content outside the EU in order to deliver a feature the customer has enabled; where they do, transfers are covered by contractual safeguards.
- All data is encrypted in transit (TLS) and at rest, including message content.
- Platform access and refresh tokens are stored encrypted, never exposed in our interface or logs, and used only for the customer who authorized them.
- Access to production data is restricted to authorized personnel who need it to operate or support the service, and is logged.
9. Retention and deletion
We keep conversations and contacts while an account is active, so the business can access its own history.
When a channel is disconnected — from Chatter, or by revoking access on the platform itself — we stop accessing that account immediately and delete its stored access tokens. Message history already in the inbox remains available to the business unless it asks us to delete it, in which case we do so within 30 days.
When an account is closed, we delete or irreversibly anonymise its data within 90 days, except where we must keep records to meet a legal obligation. Encrypted backups containing that data are overwritten on a rolling cycle and are fully purged within 95 days of closure.
A business customer can request deletion at any time by contacting us, or by deleting data directly in the platform. An end user should contact the business they messaged, since that business controls its own conversation data; if they contact us instead, we will pass the request on and help action it. We respond without undue delay.
10. Disconnecting a channel
A business can disconnect any channel at any time — from Chatter's settings, or independently from the connected platform's own settings. Revoking access on the platform immediately ends our ability to access that account, and we cannot re-establish access without a fresh authorization from the business.
11. Your rights
You may ask us to access, correct, export or delete your personal data, or to restrict how we process it. Contact us using the details below. Where we act as a processor for a business customer, we will refer your request to that business and help them respond.
12. Changes to this policy
We may update this policy as the product changes. We will update the date above and, for material changes to how we handle personal data, notify customers before they take effect.
13. Contact us
For any privacy question or data request, contact letstalk@thriveme.ae, or write to Thrive LLC, Level 14, Boulevard Plaza Tower 1, Downtown Dubai, United Arab Emirates.