Last updated: 2026-09-04
This Privacy Policy explains how MustAI ("we", "us", "the Service") collects, uses, and protects information when a business ("you", "the advertiser") uses our WhatsApp-based ad campaign assistant.
MustAI is operated by COVENANT DEXTEROUS SERVICES PRIVATE LIMITED (CIN U17299TG2020PTC141091), registered at SY NO. 32, 33, Beside #2-22/2/A, Rangampally, Peddapalli, Karimnagar, Telangana, India - 505172. For the information described below, we are the data fiduciary/controller — we decide why and how it is processed.
Everything you do with the Service happens in one of two places: a WhatsApp conversation with our business number, where you describe your business and approve campaigns, and an advertiser dashboard you sign in to with your WhatsApp number and a one-time code. There is no other way in, and no password anywhere.
We do not ask for or store a password. You sign in with your WhatsApp number and a one-time code.
We message you on WhatsApp because you started a conversation with our business number, and we use it for two things: replying to you as you build a campaign, and sending you a small number of updates we start ourselves — a payment confirmation, and a performance summary once a campaign finishes.
To stop the updates we start, reply STOP or UNSUBSCRIBE
to our WhatsApp number at any time. We record that immediately and check it
before every such message. Reply START to turn them back on. Stopping them
does not close your account, and you can still use the Service by messaging us.
We keep the messages you exchange with us, as described in Section 2, so we can operate the chat, resume it where you left off, and support you.
We process your information because it is necessary to perform our contract with you (operating the Service you signed up for), because you have consented to a specific action (such as connecting your Meta account or publishing a campaign), because we have a legitimate interest in keeping the Service secure and working, or because the law requires it — for example retaining financial records. Where we rely on consent, you can withdraw it at any time; see Section 14.
Before we do anything else, we ask you to accept this Privacy Policy and our Terms of Service — by tapping "I Agree" the first time we message you on WhatsApp, or, if you reach the advertiser dashboard first, by checking the box there. We record the date and time you do this. If you decline, we do not proceed with onboarding.
We use the following providers to deliver the Service. Each receives only what it needs for its own task.
| Provider | What it does for us | Processed in |
|---|---|---|
| Meta Platforms, Inc. | Publishes and manages your ads via the Marketing API, and carries WhatsApp messages between you and us via the WhatsApp Business Platform. For those messages Meta acts as a service provider on our behalf — we remain responsible for how that data is used within the Service. | United States / global |
| Anthropic | Drafts ad captions and conversation text on your behalf. | United States |
| OpenAI | Generates ad creative images you review and approve before publishing. | United States |
| Generates ad creative video you review and approve before publishing. We do not use Google Ads. | United States / global | |
| Razorpay | Processes your subscription payment and holds your card details. We never see or store your card number. | India |
| Amazon Web Services | Runs the servers and databases the Service operates on. | United States (N. Virginia) |
| Sucuri | Filters malicious traffic in front of this site. Every request to us passes through it, so it handles your IP address and the contents of your requests, including signing in to the dashboard. | United States / global |
These AI providers receive only the business details and campaign brief needed to generate the specific creative you requested — which may include a business phone number, address, or website you provided — never your Meta access token or payment information.
We do not use your content to train AI models, and we do not sell your data to third parties. We may disclose information where the law requires it, to protect our rights or someone's safety, or to a successor if the business is acquired.
Meta's rules for advertising data are stricter than our general purposes above, and we follow them. We use the campaign and performance data from your connected ad account only to run and report on your own campaigns. We keep each advertiser's data separate from every other advertiser's. We do not use it to retarget anyone, to build profiles of the people your ads reach, or to enrich any other dataset.
We are based in India, but the Service itself runs on Amazon Web Services infrastructure in the United States (N. Virginia) — so your account, conversation history and campaign records are stored and processed there, not in India. The other providers listed above may also process information outside India. Where a cross-border transfer is subject to legal requirements, we rely on the safeguards our providers offer, such as their standard contractual clauses.
Our advertiser dashboard uses a single session cookie to keep you signed in; it expires automatically. We do not use analytics, advertising, or tracking cookies anywhere on this site. Pages on this site, including this one, load fonts, icons, and styling from a third-party content delivery network, which may receive your browser's IP address and user-agent as a normal part of serving those files.
Meta access tokens are encrypted at rest (AES-256-GCM) and are never exposed in logs or client-facing responses. Traffic to and from the Service is encrypted in transit. Access to production data is restricted to authorized personnel who need it, and credentials are held in managed secret storage.
If we become aware of a security incident affecting your personal data, we will assess it and notify you and the relevant authority where the law requires it, and give you the information you reasonably need to meet any notification obligations of your own.
We keep each kind of information only as long as we need it, and no longer:
| What | How long we keep it |
|---|---|
| WhatsApp conversation history | 24 months from your last message to us |
| Campaign records — your brief, the creative we generated, campaign settings and results | 24 months after the campaign ends |
| Your Meta access token and the ad account and Page you selected | Deleted as soon as you disconnect, and in any case after 90 days without activity |
| Account and contact details | While your account is active, then deleted with everything above |
| Payment and invoice records | 8 financial years from the year of the payment, as the Companies Act 2013 requires |
The eight-year figure applies only to invoices and the payment records behind them, because Indian company law requires us to keep our books. It does not extend to your conversations, campaigns or access token. If you never make a payment, there is no such record and nothing is kept on this basis. Uploaded media stays on WhatsApp's media servers under Meta's own retention rules, not as files on our servers.
We delete your data when any of these happens:
The exception is data the law requires us to keep, such as financial records. To request deletion, see our Data Deletion page, which explains what gets deleted and how to ask — or contact us at the email below. You can also disconnect our app yourself at any time from your own Facebook settings, without asking us.
Our Service is intended for business owners and marketers and is not directed at children. We do not knowingly collect data from anyone under 18; if we learn that we have, we will delete it.
Depending on where you are, you can ask us to give you a copy of the personal data we hold about you, correct it, delete it, restrict or object to how we use it, or withdraw a consent you previously gave. You can also ask us to disconnect your Meta account from the Service. Contact us at the email below and we will respond within the time the applicable law allows; we may need to verify your identity first.
You can revoke this Service's access to your Facebook or Instagram account at any time from your own Facebook Settings, independently of contacting us.
The Service has no way to upload a customer list, contact file, or audience of your own. We do not ask for one and we hold no such data. Campaigns are targeted by the location and audience categories you choose, not by lists of individuals.
If we later add a feature that lets you give us personal data about your own customers or staff, you would be responsible for having a lawful basis to do so, and we would act as your processor — handling it only on your instructions, keeping it confidential, applying the security measures in Section 10, helping you respond to requests from the people concerned, and deleting or returning it when our work for you ends. We would sign a fuller data processing agreement on request.
We may update this policy as the Service, the law, or our providers change. The "Last updated" date above will reflect the most recent change, and we will tell you about material changes through the Service.
Questions about this policy, requests about your data, or complaints: mustsubscriptions@gmail.com. Please include the account phone number or email you use with the Service, the dates involved, and a description of the issue.
Grievance Officer: Jasper Herold M, CEO
COVENANT DEXTEROUS SERVICES PRIVATE LIMITED (CIN U17299TG2020PTC141091)
SY NO. 32, 33, Beside #2-22/2/A, Rangampally, Peddapalli, Karimnagar, Telangana, India - 505172
Phone: +91 99498 85474 · Email: mustsubscriptions@gmail.com