Skip to content
Shathi App
How it worksUse casesPricingFAQ
বাংলা, Switch to Bangla English
Get started →

Privacy policy

What information Shathi uses, who processes it, and how to delete it.

Last updated: 8 October 2026 Draft policy · owner details and legal review pending
On this page
Who operates the serviceData collectedWhy we use itProcessors and service boundariesRetentionYour choices and rightsWhat erasure removes and retainsLimits of pause and deletionWebsite preferences and changesMessage verification and storage

In short

  • Your WhatsApp number and messages are used to run your reminders.
  • Meta, the configured AI provider and Cloudflare process data to run the service. The owner must confirm the AI provider before launch.
  • We don’t sell your data.
  • Write “delete my data” in the chat to delete it.

1. Who operates the service

Controller / legal entity: [owner must supply legal name, address and jurisdiction]. Support and rights contact: [owner must supply contact].

2. Data collected

WhatsApp number (wa_id), submitted WhatsApp number, bKash payer number (Send Money only), the name and optional email entered on the payment form, profile name, incoming message text, reminder text and schedules/status, bKash transaction ID (TrxID), bKash payment ID, payment method, merchant invoice reference, amount/date/status and paid date, monthly and daily usage counters, processed-message receipts, consent and waitlist number/name/source, and allowlist records. For online bKash checkout, bKash processes payment on its own page; Shathi sends bKash the amount and a random invoice reference (not your phone number). Shathi never sees your bKash PIN or OTP and does not receive or store your bKash wallet number for online payments. Hashed IP/number abuse counters protect the waitlist and payment form. Cloudflare Turnstile verifies both forms; the Worker uses Cloudflare’s connecting IP for abuse control. Tokens are used for verification, not as a customer profile.

3. Why we use it

To understand and manage requested reminders, send confirmations and reminders, handle subscriptions and owner payment review, provide requested invitation access, enforce quotas, prevent abuse and retry/replay duplication, and respond to deletion and pause requests. This service does not sell personal data. The owner must confirm applicable legal bases and local requirements before launch.

4. Processors and service boundaries

Meta (WhatsApp) processes your number and message content for messaging. bKash (payment gateway) processes online checkout payments on bKash’s own page; Shathi receives payment status, bKash payment ID, TrxID, amount and related metadata, not your wallet PIN, OTP or wallet number. The configured AI provider processes ordinary human-written request text and, for saved-item matching, up to five owned item names, kinds and explicitly confirmed aliases with bounded recent task hints. It does not receive file bytes, text-note bodies, captions, stored URLs, object keys, hashes or phone/payment identifiers as saved-item context. Cloudflare hosts the Worker and D1 database and verifies waitlist requests through Turnstile. The owner must name the configured AI provider, review processor agreements, and document any cross-border processing before launch. Erasure in this service does not erase independent Meta/provider records; their own policies apply.

5. Retention

Active reminders and account data remain while used, subject to [owner must set inactive-account, message-log, waitlist and backup retention]. Payment/legal records remain for [owner must set legal retention]. Hashed waitlist IP/number abuse counters, quota-prevention counters and hashed retry/replay receipts have [owner must set appropriate retention]. Current-month erased send totals reset with the next monthly window. The lifetime Free creation counter does not reset; retained cost/legal counters and replay records require an owner retention policy. No fixed retention period is claimed here.

6. Your choices and rights

Send stop or বন্ধ to pause subsequent sends without deleting schedules. Send start or শুরু to resume. Send delete my data or ডাটা মুছে দাও and confirm the sender-owned button within ten minutes. Contact the owner to request access, correction or other applicable rights. The owner must supply a working rights contact before launch.

See it step by step

7. What erasure removes and retains

Confirmation removes reminders, monthly/daily usage rows, message logs, waitlist and allowlist entries, profile name, referral and pending drafts. Payment rows retain WhatsApp identifier, TrxID, bKash payment ID, merchant invoice reference, payment method, amount, paid date and date with a retained marker and internal primary key; the bKash payer number, submitted WhatsApp number, the name and optional email entered on the payment form and claim data are cleared. A tombstone keeps wa_id/deleted_at, current-month erased create/send totals, the lifetime Free creation counter and lifetime confirmation/legal/cap-notice counters to prevent account recreation resetting limits. Processed receipts keep hashed message IDs, with sender/time blanked, to prevent retries rebuilding erased data. Hashed waitlist and payment abuse counters remain independently after erasure; their retention period must be set by the owner.

8. Limits of pause and deletion

Messages already accepted or in flight with Meta cannot be recalled. Subsequent sends pause, and generation guards prevent late work rebuilding erased service data. A later ordinary incoming message can reactivate the account, subject to service rules and retained quotas. Deletion does not reset current-month send allowances or the lifetime Free creation counter.

9. Website preferences and changes

Language choice is stored locally in your browser. No analytics or advertising pixel is enabled by default. Turnstile loads only when a configured form is activated; its verification is processed by Cloudflare. With analytics consent, Google Analytics 4 sets its own cookies and identifiers (such as _ga and client and session IDs) and receives the public page address without any query or fragment. With ads consent, the Meta pixel loads only when the referring page is empty, a site origin, or a public page of this site; it may set _fbp, and an ad click ID is stored as _fbc only after you agree. Online checkout with ads consent also sends the homepage address, and the checkout request records your browser’s user agent. Your name, email, phone number and payment transaction details are not shared for marketing. Consent is kept for the configured retention window (7 days by default); you can change it at any time with the marketing settings button. Withdrawal or erasure removes the stored marketing identifiers, attribution and checkout user agent. Contact: [owner must supply]. Changes to this policy will be dated here.

10. Message verification and storage

Shathi verifies Meta’s HMAC signature to confirm incoming messages are authentic; this does not hide message content. Cloudflare encrypts reminder data and files stored in D1 and R2 at rest. The service reads stored bytes when needed to deliver them, and privileged Cloudflare service operators may access service data. The configured AI provider processes ordinary request text and the bounded saved-item metadata described above; file bytes and text-note bodies are not provided.

Questions? Write to shathiapp@gmail.com

What’s on your mind tonight?

Write it down. Shathi will remind you when it’s time.

Get started →
Shathi App A little help remembering. For everyday tasks, small and large. Time zone: Asia/Dhaka.
PrivacyTermsFair useDelete data
Contact shathiapp@gmail.com Facebook ↗