Ceti Harness/privacy
O
Ceti Harness
Back to Home
GDPR & Meta Platform Compliant

Privacy Policy & Data Governance

Effective Date: August 25, 2026 · Domains: caseshow.info

1. Overview & Scope

Ceti Harness ("Ceti", "we", "our", or "us") provides an autonomous AI receptionist and multi-channel communication engine for businesses. The Service connects to messaging channels you own — WhatsApp Cloud API, Meta Messenger, Instagram Direct, and Meta Threads — and can be embedded on your website as a chat widget. This Privacy Policy governs how we collect, process, isolate, and safeguard data across our web dashboard, connected messaging channels, the embeddable widget, and our authentication and billing services.

This policy covers two audiences: (a) Business Subscribers who create Ceti accounts, and (b) End Customers — the people who message your business through connected channels or your embedded widget. If you are a business subscriber, you are the data controller for your end customers' communications, and Ceti processes that data on your behalf as a processor. If you are an end customer, the business you contacted decides how your inquiry is handled; we process it only to deliver their automated receptionist service.

2. Data We Collect & Process

  • Subscriber Account Information: Name, work email address, business name, timezone, and billing status. Payments are handled by Paystack; we never store full card numbers — only tokenized references and payment status.
  • Authentication Data: When you sign up with email and password, we verify your address with a one-time code. When you sign in with Google OAuth, we receive your verified email address, full name, and avatar solely to authenticate your identity and provision your business workspace.
  • Inbound Customer Communications: Message text, channel metadata (e.g. WhatsApp phone number, Instagram/Messenger handle), appointment requests and details, and timestamps — strictly needed to formulate responses, schedule bookings, and maintain conversation history.
  • Business Knowledge Assets: With your authorization, we crawl the website domain(s) you designate during onboarding (extracting titles, page descriptions, contact information, and subpage content) and ingest documents you upload, such as pricing tables, FAQs, and operating hours. Personally identifiable information encountered during crawling is filtered through sanitization routines before storage.
  • Derived Data: Your knowledge assets are structured into retrievable knowledge entries so the AI can answer accurately. We also generate conversation insights when you use features like Dream Mode and Intelligence analysis, which review recent transcripts to produce reports about your customers and conversations.
  • Website Widget Visitor Data: When a visitor chats through your embedded widget, we assign them a random persistent identifier stored in their browser's local storage (e.g. ceti_visitor_…) to recognize returning sessions, along with the messages they type and basic context needed to reply.
  • Product Analytics: Internal usage and funnel events tied to hashed, anonymized identifiers (SHA-256) so we can understand feature adoption and improve the product. We do not use third-party advertising trackers inside the app.

3. How We Use Data

  • To operate the AI receptionist: answering inquiries, booking appointments, and executing knowledge lookups on your behalf.
  • To provision and secure your account, workspace, and billing relationship.
  • To improve response quality for your business by retrieving your verified knowledge during conversations.
  • To produce insights you explicitly request (Dream Mode reports, Intelligence analyses).
  • To monitor reliability, prevent abuse, and comply with platform policies and law.

We do not sell personal data, and we do not use your customers' communications to advertise to anyone.

4. AI Processing & Model Providers

Ceti Harness is powered by large language models operated by third-party providers. To generate replies and insights, we transmit conversation history, relevant excerpts of your verified business knowledge, and agent configuration (such as brand voice) to these providers under API terms that prohibit them from using submitted data to train their public models:

  • DeepSeek (primary processing provider)
  • Google Gemini, OpenRouter, NVIDIA NIM, and Groq (automatic failover providers used when the primary provider is unavailable)

We never send more context than a given task requires, and provider routing is designed for resilience rather than data sharing. You acknowledge and accept this processing as a condition of using the Service. We do not permit these providers to contact your customers, and we do not use your private transcripts to train public AI foundation models.

5. Local Storage & Cookies

We use browser local storage strictly for essential functionality: keeping you signed in (auth session), remembering widget visitor session identifiers, and storing interface preferences. We do not run cross-site advertising or behavioral-tracking cookies.

6. Meta Platform & Social API Compliance

When connecting your Facebook Page, Instagram Professional Account, WhatsApp number, or Threads account, Ceti Harness requests only the minimal necessary permissions (such as pages_messaging, instagram_manage_messages, whatsapp_business_messaging, and threads_read_replies). Page access tokens are stored encrypted-in-transit and used solely to send and receive messages on channels you connect.

✓ We never sell or monetize platform data.
✓ We never share communication histories with third-party advertisers or data brokers.
✓ We never use private customer transcripts to train public AI foundation models.
✓ You can revoke our access at any time via Facebook/Instagram Settings & Privacy → Apps and Websites; revocation triggers our deauthorization handling and stops channel processing immediately.

7. Multi-Tenant Isolation & Security

All customer conversation data and business knowledge are stored in a secure cloud database protected by strict multi-tenant isolation boundaries that prevent any cross-business exposure. Data is encrypted in transit (TLS) and at rest (AES-256). Access to production data by personnel is restricted and logged, and service-level credentials are never exposed to the client.

8. International Data Transfers

Our infrastructure and AI model providers operate globally, including in the United States and other jurisdictions. Where required by applicable law, we rely on appropriate safeguards for international transfers. Because messaging platforms and AI providers are global networks, using the Service implies your data may be processed outside your country of residence.

9. Data Retention

We retain account records, conversation transcripts, and knowledge assets while your subscription is active and for as long as needed to provide the Service, comply with legal obligations, resolve disputes, and enforce our agreements. Analytics records are kept in aggregated or pseudonymized form. When you request deletion, data is permanently purged from production systems, subject to brief backup rotation cycles.

10. User Data Deletion Instructions

In accordance with Meta Platform Terms and global privacy standards, you can request full erasure of your account, messaging transcripts, tokens, and business knowledge at any time:

  1. Meta Self-Service Deletion: In your Facebook, Instagram, or Threads settings, go to Settings & Privacy → Apps and Websites → Ceti Harness → Remove, and choose "Delete your data". Our automated data-deletion callback will process the request and give you a confirmation code and status URL.
  2. Email Deletion Request: Send an email to privacy@caseshow.info from your registered address, including your Business ID or connected phone number. Our compliance team performs a full workspace purge — account profile, transcripts, knowledge assets, embeddings, and analytics records — targeting completion within 72 hours.

11. Children's Privacy

The Service is intended for businesses and is not directed to children under 13 (or the equivalent minimum age in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us personal data, contact us and we will delete it promptly.

12. Your Rights

Subject to applicable law (including the Kenya Data Protection Act, 2019 and the EU/UK GDPR where relevant), you may request access to, correction of, portability of, restriction of, or erasure of your personal data, and may object to certain processing. Business subscribers can export or purge workspace data at any time via the contacts below. We respond to verified requests within statutory timeframes.

13. Changes to This Policy

We may update this Privacy Policy to reflect changes in the Service or law. Material changes will be announced via the dashboard or email before taking effect. Continued use after the effective date constitutes acceptance of the updated policy.

14. Contact Us & Governance

If you have any questions or data requests regarding this Privacy Policy, contact our Data Protection Officer at:

Email: privacy@caseshow.info
Website: https://caseshow.info

© 2026 Ceti Harness / caseshow.info. All rights reserved.