Privacy policy

SignalDesk Privacy Policy

SignalDesk is a read-only WhatsApp executive briefing proof of concept. This policy explains what data we process, why we process it, and how to request deletion.

Last updated

July 1, 2026

For privacy requests, contact thatoraphahlelo@tmrwtech.co.za.

Scope

This policy applies to the SignalDesk website, onboarding flow, OAuth account connection flow, WhatsApp command flow, and supporting backend services used for the executive briefing proof of concept.

SignalDesk does not sell personal data. The proof of concept is designed around read-only access: it may read connected inbox and calendar data to generate briefings, but it does not send emails, create provider-side drafts, modify calendars, or write back to your Google or Microsoft accounts.

What We Collect

Email data

Read-only message metadata and content from connected Gmail or Outlook accounts when needed to produce briefings, open selected items, and prepare internal suggested replies.

Calendar data

Read-only event details from connected Google Calendar or Microsoft calendar accounts so briefings can include schedule context.

WhatsApp interactions

Your WhatsApp number, command text, timestamps, and assistant responses used to route BRIEF, OPEN, and DRAFT requests.

Onboarding data

Your name, WhatsApp number, timezone, provider connection status, OAuth authorization data, briefings, item snapshots, and internal suggested replies.

We may also process technical data such as browser information, IP address, diagnostic logs, authentication events, and error reports to operate and secure the service.

How We Use Data

  • Create and maintain your evaluator profile.
  • Connect your Google and Microsoft accounts using OAuth.
  • Generate concise WhatsApp executive briefings from read-only inbox and calendar signals.
  • Resolve selected briefing items when you use commands such as OPEN 1.
  • Prepare internal suggested replies when you use commands such as DRAFT 1.
  • Operate, debug, secure, and improve the proof-of-concept service.

Sharing

We share data only as needed to operate SignalDesk, including with hosting, database, logging, communications, OAuth, email/calendar provider, and Meta or WhatsApp service providers. We may disclose information if required by law, to protect the service, or with your direction.

Retention

We keep evaluator profile data, provider connection records, stored briefings, source snapshots, WhatsApp command history, and suggested replies for as long as needed to run the proof of concept, support the evaluator, maintain security, or comply with legal obligations. We delete or de-identify data when it is no longer needed for those purposes.

Data Deletion

How to request deletion

Email thatoraphahlelo@tmrwtech.co.za with the subject SignalDesk data deletion request. Include the WhatsApp number or email address used for your evaluator profile so we can identify the account.

After we verify the request, we will delete the evaluator profile, OAuth tokens, provider connection records, stored briefings, source snapshots, WhatsApp command history, and internal suggested replies associated with that profile, unless we are required to keep limited records for legal, security, or abuse-prevention reasons.

You can also revoke connected account access directly through your Google or Microsoft account security settings. Revoking access stops future data access but does not automatically delete data already stored by SignalDesk, so use the email request above if you want stored SignalDesk data deleted.

Your Choices

  • Request a copy of the personal data associated with your evaluator profile.
  • Request correction of inaccurate profile details.
  • Request deletion of your evaluator profile, connected account tokens, stored briefings, source snapshots, and internal suggested replies.
  • Revoke provider access directly in your Google or Microsoft account settings at any time.

Security

We use reasonable technical and organizational safeguards to protect personal data, including access controls and secure OAuth-based account connection. No internet service can guarantee absolute security, so we limit the proof of concept to the data and access needed for the briefing workflow.

Children

SignalDesk is not intended for children under 13, and we do not knowingly collect personal data from children.

Contact

For privacy questions, access requests, correction requests, or deletion requests, email thatoraphahlelo@tmrwtech.co.za.