Privacy
Customer data leaks, or is kept forever
Pins are placed without leaving the server, numbers never appear on internal pages, customers can opt out or be erased, and silent customers are forgotten after a set time
The situation
A messaging app holds phone numbers, names, locations and conversations. Those leak through internal dashboards, third-party services, and data that is simply never deleted.
What the app does
Locations stay on our server. A dropped pin is placed in its country using map outlines stored with the app. The coordinates are never sent to a map or geocoding service.
Numbers do not appear on internal pages. Dashboards and reports refer to a customer by a handle (cust-xxxx), not their phone number.
Customers control their data. A customer can opt out of messages or ask for their data to be erased, on WhatsApp, and the app acts on it.
Silent customers are forgotten. A customer who has said nothing for the retention period (set on the server) is removed.
Customer words are never instructions. What a customer types is read as words; a message that tries to instruct the assistant is not obeyed.
Our catalogue stays internal. Part numbers are shared with customers; the scraped catalogue descriptions are not published.
The privacy notice customers see is docs/privacy-notice-whatsapp.md, and the services that process data for us are listed in docs/processors.md.
The tests that hold it
tests/unit/test_dropped_pin.py, test_currency_learning.py (no number on the report), and the security and erasure tests under tests/.
