Legal

Privacy Policy

Effective 3 July 2026

Who we are

agentOS ("we", "us", "our") is a WhatsApp automation platform operated by Code Bunny ("the company"), based in India. You can reach us at notifications@codebunny.net.

This policy explains what personal data we collect when you use agentOS, how we use it, and the rights you have over it.

Data we collect

We collect only what we need to run the service:

  • Account data — your email address, hashed password, and display name.
  • Workspace configuration — WhatsApp provider credentials (Twilio API key / Meta Cloud API token), bot system prompt, qualification fields, follow-up rules, SMTP credentials, and event-type definitions. Provider secrets are stored server-side and never shown in the UI after entry.
  • Conversation data — WhatsApp messages exchanged between your bot and your contacts (phone number, name if provided, message body, timestamps, extracted qualification data).
  • Booking data — guest name, email, phone (optional), and answers to your custom questions when someone books via a public event-type link.
  • Meeting provider tokens — if you connect Google Meet or Zoom via OAuth, we store the resulting OAuth access & refresh tokens and the connected account email so we can create meeting links on your behalf. We never see your Google or Zoom password.
  • Operational logs — request logs, error traces and audit events (typically retained for 30 days).

How we use it

  • To operate the product — authenticate you, run your bot, send/receive WhatsApp messages via your configured provider, generate booking links, and deliver email notifications.
  • To generate unique meeting links on the Google or Zoom account you connect.
  • To debug and improve the service (aggregated, non-identifying).
  • To contact you about service updates, security notices, or billing.

We do not sell your data, do not use it to train third-party AI models, and do not share it with advertisers.

Third-party processors

agentOS uses the following sub-processors. Data touches these systems only for the purposes described:

  • MongoDB Atlas / self-hosted MongoDB — primary datastore.
  • OpenAI / Anthropic (via Emergent LLM key) — the qualification bot sends the current WhatsApp thread to the model to generate the next reply. No message data is retained by us at the model provider beyond the completion.
  • Twilio / Meta (WhatsApp Cloud API) — whichever provider you configure to actually send/receive WhatsApp messages.
  • Google (Calendar API) / Zoom (Meetings API) — only if you connect them, and only for the accounts you connect.
  • SMTP provider you configure (e.g. one.com) — used exclusively to send booking confirmation emails and .ics invites.

Google Meet integration disclosure

agentOS's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

We request access to the calendar.events scope solely to create calendar events with Google Meet conference links on your primary calendar when a guest books an event type you have set to "Google Meet". We do not read, modify, or delete any other events on your calendar, and we do not transfer this data to any third party.

Zoom integration disclosure

agentOS uses the meeting:write:meeting scope solely to create scheduled Zoom meetings under your account when a guest books an event type you have set to "Zoom". We never join, host, record, or read the contents of any meeting.

Data retention & deletion

  • Your account data is retained while your account is active.
  • Conversation data and booking records are retained until you delete them (contact-level) or delete your account.
  • OAuth tokens for Google/Zoom are deleted immediately when you click Disconnect in Settings.
  • Logs are retained for 30 days, then purged.

To delete your entire agentOS account and all associated data, email notifications@codebunny.net from the address on file. We complete deletion within 14 days and confirm by email.

Your rights

Depending on your jurisdiction (GDPR / DPDP Act 2023 / CCPA), you may have the right to access, correct, export or delete the personal data we hold about you. To exercise these rights, email notifications@codebunny.net.

Security

We use industry-standard practices: TLS everywhere, bcrypt-hashed passwords, secrets never exposed client-side, principle-of-least-privilege OAuth scopes, and rotating JWT session tokens. No system is perfectly secure — if you suspect a breach, email us immediately at notifications@codebunny.net.

Changes to this policy

We may update this policy from time to time. If we make a material change, we'll notify you by email or an in-app banner at least 14 days before the change takes effect.

Contact

Questions about this policy or your data? notifications@codebunny.net.

agentOS · a Code Bunny product