Privacy policy

1. Introduction

This Privacy Policy applies to your use of Ziptalk (the "Service") and governs how we collect, use, process and share user information.

The data controller is Ziptalk LTDA, company number (CNPJ) 62.586.587/0001-10, based in Piracicaba/SP, Brazil. Where we act as a processor rather than a controller, this Policy says so explicitly.

2. Information We Collect

a. Personal Information

We collect personal data such as your name, email and phone number, which we need to create and manage your account.

If you sign in through an external login provider, we receive your name and email from them. Some of those providers let you hide your real address and hand us a forwarding one instead. When that happens, the forwarding address is what we store, and it is where we send our messages.

b. Connecting your WhatsApp

To transcribe your voice messages we need to receive the messages sent to the number you connect. There are two ways to do this, and they work differently:

  • Official connection, through Meta's WhatsApp Business platform. You authorize Ziptalk in a window served by Meta, and from then on Meta delivers the number's events to us.
  • QR Code, scanned with the WhatsApp app on your phone. Here the connection is direct between us and your device, with Meta not involved.

In both cases we transcribe voice messages only, and we do not store the audio or the transcripts. Audio is processed in memory and discarded right after. None of your conversations are kept: the Service has nowhere to store messages.

c. What reaches us on the official connection

On the official connection, Meta decides what gets delivered, not Ziptalk. It offers no way to pick conversations or message types: it sends the number's events, and the filtering happens on our side. Since this differs from what most people assume, it is worth spelling out:

  • Messages received by the number. All of them arrive, of every type, including message text. We process voice messages only. Text, images, stickers and other types are discarded without being stored. Text is read solely to recognize the "/stop" and "/start" commands.
  • Messages you send from your own phone. After connecting, Meta also sends us a copy of what leaves your device, so transcription works in both directions. Same rule: voice only.
  • Your contact list, if contact sync is on. See item "e" below.
  • Account notices, such as the number being disconnected, reconnected or restricted, used only to keep the connection status accurate on screen.

We do not request your chat history. Meta's platform allows a provider to request up to six months of past conversations, and we do not. If any history reaches us anyway, it is discarded without being stored.

When a number is first connected, Meta may deliver whatever it had queued for it, including conversations that predate your arrival at Ziptalk. We discard any message older than ten minutes before even downloading the audio, so old conversations are never transcribed.

Groups, disappearing messages and view-once messages are not sent by Meta and therefore never reach us.

d. Technical Data

We collect technical information such as device type and model, operating system, and how you interact with the Service.

e. Contacts (optional)

We store only the name and phone number of the contacts on the connected number, and we use them to show who sent each voice message and to let you place calls from the app. How you authorize this depends on the connection:

  • QR Code: the option is pre-selected on the connection screen and can be declined there with one click.
  • Official connection: you authorize sharing your contacts inside Meta's own window while connecting, and sync is active from then on. The list updates by itself when you add, edit or remove a contact on your phone.

Either way, you can turn contact sync off in the number's preferences at any time. Stored contacts are deleted when you turn sync off, disconnect, or remove the number.

f. Payment data

To pay by card, card details are typed straight into our payment processor's screen and never reach our servers. We keep only what identifies the payment method, such as the brand and the last four digits.

To pay by Pix, and also to start a free trial with a Pix authorisation, we need the payer's full name and tax ID (CPF or CNPJ). Pix's rules require them to create the charge authorisation at your bank, and you are the one who confirms that authorisation inside your bank's app. On a trial they are collected before any charge, because the authorisation has to exist for the trial to start. We store the tax ID alongside the authorisation record, to identify the charges and to answer your bank if a charge is disputed.

g. Calls (optional)

If you enable call transcription, calls made through the app are recorded and transcribed, and both the recording and the transcript are sent to the chat you choose on WhatsApp. This feature is optional and off by default. Only record and transcribe calls with proper consent from everyone involved, as required by applicable law.

3. How We Use Information, and Legal Bases

Each purpose has its own legal basis under article 7 of Brazil's LGPD:

  • Performance of a contract — creating and maintaining your account, billing your subscription, receiving and transcribing voice messages on the connected number, product updates and support.
  • Consent — syncing the connected number's contact list; recording and transcribing calls, which is off by default; marketing cookies, accepted in the banner.
  • Legitimate interest — security, fraud prevention and troubleshooting.
  • Compliance with a legal obligation — access logs and tax obligations.

You may withdraw any of the consents above at any time by turning off the matching option in the app. Withdrawal does not affect processing already carried out.

4. Sharing and Disclosure

We do not sell your data and we do not share it for third-party advertising. Sharing happens only with the parties needed to run the Service, and always limited to what is necessary.

a. Who processes data on our behalf

  • Meta — on the official connection, delivers the connected number's messages. Meta's own processing is governed by its policies.
  • Speech recognition — transcription runs first on our own model, on servers we rent and only we use. When it fails, or when the audio runs longer than twenty minutes, the audio is sent to Deepgram and, if that fails too, to OpenAI. Audio from calls placed in the app is transcribed by Deepgram. These providers receive the audio only while processing it and do not retain it afterwards.
  • Text processing — when you enable summaries, translation or the offensive-language filter, the transcribed text is sent to OpenAI. All three are off by default; without turning them on, no text is sent to them.
  • Hosting and database — the Service's database is in São Paulo, Brazil.
  • Error monitoring — receives technical logs that may contain phone numbers, not message content.
  • Payments and tax invoicing — process billing and issue invoices. We never see your full card number. For Pix, the payer's name and tax ID are sent to the provider that registers the authorisation with your bank, because the authorisation cannot be created without them.
  • Sign-in and website analytics — authentication and usage measurement on our public pages.

None of these providers use your data for their own purposes or to train models. If you want to know who they are by name, just ask at [email protected] — we answer, as required by article 18, VII of the LGPD.

b. International Transfers

The Service's database is in Brazil. Some of the services above operate abroad, mainly in the United States, which means your data is transferred internationally. Those transfers rely on contractual clauses and the safeguards required by applicable data protection law.

c. Other cases

We may disclose data where required by law, court order or a request from a competent authority, and in the event of a corporate reorganization, in which case this Policy continues to apply.

5. Retention and Deletion

Different data has a different lifespan in the Service:

  • Audio and transcripts: never stored. Audio is processed in memory and discarded right after.
  • Message content: not stored. This also covers any history Meta might send.
  • Contacts: for as long as sync is on. Deleted when you turn it off, disconnect, or remove the number.
  • Official connection credentials: for as long as the connection exists. Deleted on disconnection.
  • Usage records (date, duration and the number that sent the voice message): kept as your consumption history and as the basis for billing, for as long as the account exists.
  • Numbers on "/stop": kept while the number stays connected, so we keep honoring the request not to transcribe.
  • Account, subscription and invoice data: for the statutory tax and accounting retention periods, even after a deletion request, under article 16, I of the LGPD.
  • Automatic debit authorisation and payer tax ID: for 5 years from the end of the authorisation, the retention period for billing records and any dispute.
  • Access logs: for the period set by article 15 of Brazil's Internet Civil Framework.

6. Roles on the Official Connection

When you use the official connection, Ziptalk acts as a processor: we handle the connected number's data on your instruction and for the purpose you signed up for, which is transcribing voice messages. We do not use that data for our own purposes, we do not pass it to third parties beyond the cases described in this Policy, and we do not train models on the content of your conversations.

If the connected number belongs to a company and the conversations involve customers and other third parties, that company is the controller towards those people. It is up to the company to inform them and to have a legal basis for the processing. The matching obligations are set out in our Terms of Use.

Meta processes the same data under its own policies, as the provider of the WhatsApp Business platform. Ziptalk has no control over Meta's processing.

7. Information Security

We apply security measures to protect your information, including encryption in transit, access control and credential segregation.

Official connection credentials are stored encrypted with AES-256-GCM, in a table with no public access, reachable only by the server components that need it. Requests Meta sends to our endpoint are signature-verified before being processed.

8. Your Rights

Under article 18 of the LGPD, you have the right to:

  • Confirm that processing exists and access your data;
  • Correct incomplete, inaccurate or outdated data;
  • Request anonymization, blocking or deletion of data that is unnecessary, excessive or processed unlawfully;
  • Request portability to another provider;
  • Delete data processed on the basis of consent;
  • Be told who we share your data with;
  • Be told that you may withhold consent, and what happens if you do;
  • Withdraw consent at any time;
  • Object to processing based on legitimate interest.

If you are a customer, supplier or contact of someone who uses Ziptalk rather than a user of the Service, there is a page written for your situation: Your data. It explains why your number may be here, what is kept, and how to stop the transcription yourself.

To exercise any of these rights, write to [email protected]. We respond within the period set by law.

9. Security Incident Response

We maintain procedures for handling data security incidents, including notifying affected users and Brazil's National Data Protection Authority within the deadlines and in the cases required by law.

10. Cookies

We use cookies to improve your browsing experience. You can manage your cookie preferences.

We also use Google Analytics with Google Signals: if you are signed in to your Google account and have allowed ad personalization, Google may associate your visit with aggregated demographic and interest data. We only receive this in aggregate, without identifying you. You can turn ad personalization off at myadcenter.google.com and delete this data at myactivity.google.com. Marketing cookies (Meta Pixel) are only activated with your consent in the cookie banner.

11. Changes to this Policy

We may change this Policy at any time. The date of the latest revision is shown at the bottom of this document. Material changes to how we handle your data are announced inside the app.

12. Contact and Data Protection Officer

For questions, requests about your data, or to reach our data protection officer, write to [email protected]

Ziptalk LTDA — CNPJ 62.586.587/0001-10 — Piracicaba/SP, Brazil.

13. Deleting your Account and Personal Data

If you want to delete your account and all associated data, first you need to:

  • Cancel your active subscription, if you have one.
  • Leave every secondary team, staying only in your main team.

Then follow these steps:

  1. Sign in to your Ziptalk account.
  2. Go to your profile page: https://ziptalk.ai/profile
  3. Scroll to the bottom of the tab and click the red "Delete account" button to request deletion.

The request is held for 31 days, in case you change your mind. After that it is processed automatically, and from then on it is irreversible.

What happens when the deletion runs:

  • Your personal data is erased. Your name and email leave our database, and account access is blocked permanently.
  • Saved contacts, connection credentials and your support conversations are deleted.
  • Connected numbers lose their identification — the phone number is removed from the record.
  • Usage history and invoices remain, stripped of anything identifying you. The law requires us to keep them (article 16, I of the LGPD), but they no longer point back to you.

If you belong to a team with other people, the team carries on for them. Only your membership goes.

If you have a number on the official connection, disconnect it before deleting your account. Disconnecting is what ends the link with Meta and stops messages from being sent to us.

Last updated: 26/08/2026