Privacy Policy
Effective 10 July 2026
Recepta is an AI receptionist that answers a business's WhatsApp messages, books appointments and reminds customers, in English, Hindi and Punjabi. This page explains, in plain language, what personal data we handle, why, for how long, and the rights you have under India's Digital Personal Data Protection Act, 2023 (DPDP Act).
Two kinds of people use Recepta
Business owners create a Recepta account and connect their business WhatsApp number. For their account data, Recepta is the data fiduciary.
Customers of those businesses simply message the business on WhatsApp. Their messages are processed by Recepta on the business's behalf and instructions: the business is the data fiduciary for its customers, and Recepta acts as its data processor. If you are a customer, direct requests about your data to the business you messaged; this page tells you what happens behind the scenes.
What we collect
| From business owners | From a business's customers |
|---|---|
| Phone number and password (stored only as a salted hash); business name, profile, opening hours and knowledge files you upload; billing records for UPI payments (order reference and bank UTR only - we never see card or bank credentials); WhatsApp connection credentials for your own number. | WhatsApp messages sent to the business, including voice notes and media; the sender's number and WhatsApp display name; bookings made (name, phone, service, time); short factual notes the AI keeps to serve the customer better (for example "prefers evening appointments"). |
What we use it for
- Answering messages, taking bookings, sending booking reminders and, where the business enables it, rebooking nudges and follow-ups.
- Showing the business its own conversations and bookings in its dashboard.
- Billing, abuse prevention and keeping the service running.
We do not sell personal data, we do not use it for advertising, and we do not use your conversations to train AI models.
AI processing
To generate replies, message content is sent to established third-party AI providers (currently Google's Gemini models, with fallbacks) under their API terms. Only what is needed to answer is sent; billing identifiers and passwords never are.
Storage and security
- All traffic is encrypted in transit (HTTPS/TLS).
- Third-party access tokens are encrypted at rest; passwords are salted hashes.
- Data lives on access-controlled cloud servers with automated, retention-limited off-site backups.
How long we keep things
- Chat history and bookings are kept for the business for as long as it uses Recepta, unless erased earlier (see rights below). Businesses can opt into automatic deletion of messages older than a period they choose.
- Operational exhaust (expired login sessions and one-time codes, cold answer caches, delivery-dedupe logs) is deleted automatically on rolling windows of 30 to 180 days.
- Billing records are kept as required for accounting.
Your rights (DPDP Act)
- Access and correction: owners see and edit everything in their dashboard; customers can ask the business what is stored about them.
- Erasure for a customer: the business can erase everything stored about one customer - the conversation, media, memory notes and identity on booking records - in one click from its dashboard. Ask the business you messaged.
- Erasure for an owner: deleting your account from the dashboard permanently removes your account, every business you own, and all their data, after re-confirming your identity.
- Grievances: write to support@recepta.in. We respond within 15 days. If you are not satisfied, you may complain to the Data Protection Board of India.
Children
Recepta is a tool for businesses and is not directed at children. We do not knowingly process children's data except incidentally as part of a business's customer messages, under that business's instructions.
Changes
If this policy changes materially, we will update this page and the effective date above, and notify business owners in the dashboard.