Devlogify ("Devlogify", "we", "us"), a product operated by Worldwide Admissions Hub (Pvt) Ltd, provides a multi-tenant customer-communication and AI-assistant platform (the "Service") that lets businesses ("Customers") manage conversations with their own contacts across messaging channels such as WhatsApp. This policy explains what we collect, how we use it, and your choices. It covers our websites and apps, including devlogify.com.
We do not sell personal data, and we do not use Customer conversation data for advertising or to train general-purpose models.
Data obtained through the WhatsApp Business Platform and other Meta products is used solely to provide messaging features to the connecting business, in accordance with Meta's Platform Terms and Developer Policies. It is isolated per business, not shared between businesses, and not used for advertising.
A Customer may connect their own Google Calendar so that appointments booked on their public booking page appear in their Devlogify workspace.
With the Customer's explicit consent we request a single, read-only scope, https://www.googleapis.com/auth/calendar.events.readonly. We use it to read events on the calendar the Customer connects. We cannot create, modify or delete anything on their calendar, and we request no other Google scope.
Event details — time, title, the contact details of the person who booked, and any notes carried on the booking — are used to show that appointment in the connecting Customer's own Meetings list, matched to an existing contact where possible. It is isolated to that Customer's workspace and never shared between Customers.
Where a Customer uses our assistant features, those appointment details may additionally be supplied to an AI service provider as context, so that a reply about that appointment is accurate. This happens only for the Customer whose calendar it is, only in relation to their own contact, and only at the moment a reply is produced. Our AI service providers are engaged under commercial terms that contractually prohibit them from using this content to train or improve any general-purpose or foundational model, and we do not permit any such use. We do not use Google user data to create, train or improve AI/ML models, in raw, aggregated, anonymised or derived form.
The Customer's Google refresh token, held server-side in an access-restricted store, together with the appointment records shown in their workspace. We do not copy their calendar wholesale, and we do not use Google user data for advertising or to train general-purpose models.
Google user data, raw or in any aggregated, anonymised or derived form, is shared only with the following types of third parties, and only to operate the Service for the Customer whose calendar it is: our cloud hosting, database and storage providers, which store the appointment records so the Customer can see them in their own workspace; and, where the Customer uses our assistant features and only at the moment a reply is produced, our AI service providers, under the contractual terms described above. It is not shared with any other third party. We do not sell it, and we do not transfer it to data brokers, advertising networks, credit bureaux or lenders, or to any party for advertising, credit, lending or any other purpose unrelated to providing or improving user-facing features of the Service.
A Customer can disconnect at any time in Settings, or from their Google Account at myaccount.google.com/permissions. Disconnecting deletes the stored token immediately.
We share data only with service providers ("subprocessors") that help us run the Service, under contract and confidentiality. These fall into the following categories:
A current list of the specific named subprocessors we use is available to Customers on request. We may also disclose data to comply with law or protect rights and safety.
We retain Customer data for as long as the Customer's account is active or as needed to provide the Service, then delete or anonymize it within a reasonable period, unless a longer period is required by law. Customers can request earlier deletion (see Data Deletion).
We use encryption in transit and at rest, strict per-tenant access controls (row-level security so one business cannot access another's data), and least- privilege handling of connection tokens. No system is perfectly secure, but we work to protect your data.
We may process data in countries other than yours. Where required, we use appropriate safeguards for such transfers.
The Service is for businesses and is not directed to children under 16. We do not knowingly collect their personal data.
We may update this policy; material changes will be posted here with a new effective date.
Questions or requests: info@devlogify.com.