Privacy Policy
Last updated: September 25, 2026 ·
Effective: September 25, 2026 ·
Operator: Chups Inc. (operating the Eesa AI service at eesa.ai)
This Privacy Policy describes how Chups Inc. ("we", "us", "our") collects, uses, stores, and shares information when you use the Eesa AI service (the "Service") accessible at eesa.ai and via integrated messaging channels including WhatsApp Business and Telegram.
By using the Service you agree to the practices described here. If you do not agree, do not use the Service.
If you use Eesa AI through your employer. When a business uses the Service for its staff — for example to record attendance — the business decides what is collected and why, and we process that information on its behalf as its service provider. You can direct questions and requests about it to your employer or to us (see section 13 if you are in California).
1. Information we collect
1.1 Information you provide
- Account information: email address, full name, role within your tenant, and (optionally) a profile picture if you sign in with Google.
- Business data: information about your business operations that you input or that flows in through integrated systems — customer orders, inventory data, staff records, schedules, vendor records, financial figures.
- Messages: the content of conversations you have with the Eesa AI agent through any channel (web chat, WhatsApp, Telegram, email).
- Configuration data: integration credentials and tokens you provide (e.g., access tokens for connected services). These are stored encrypted at rest using field-level Fernet encryption.
1.2 Information collected automatically
- Usage data: IP address, browser type, pages visited, time stamps, and interactions with the Service.
- Device data: approximate location derived from IP, device type, operating system, browser version.
- Cookies and session storage: JWT tokens for authentication, user preferences.
1.3 Information from third parties
When you connect an external account, we receive specific information from that service:
1.3.1 Google Workspace
When you connect Google Workspace, we request the following scopes:
openid, email, profile — to identify you and display your name in the app.
calendar.events — to read and create calendar events on your behalf when you ask the agent to.
spreadsheets — to read, create, and update Google Sheets when you ask the agent to.
drive.file — to upload files to your Google Drive and access only files that Eesa AI itself created on your behalf. Eesa AI cannot access pre-existing files in your Drive.
We only access Google data in response to your explicit requests through the agent. We do not bulk-scan, train models on, or share your Google data with any third party. Access tokens and refresh tokens are stored encrypted and used solely to fulfill your requests.
1.3.2 WhatsApp Business Cloud API (Meta)
When messages are exchanged through our WhatsApp Business number, we receive from Meta:
- Your phone number, WhatsApp display name, and message content.
- Message delivery status, read receipts, and timestamps.
We use this information only to: (a) route the message to the appropriate agent or workflow within your tenant, (b) compose and send a reply through the same WhatsApp number, and (c) maintain conversation history for support continuity.
1.3.3 QuickBooks Online (Intuit)
A QuickBooks company is connected once, by a person who holds the Primary admin or Company admin role in that company — Intuit permits no one else to connect an application. That connection is to a single QuickBooks company and can be revoked at any time (see below).
Through that connection we may read, when a member of your team asks us to:
- Company information: company name, address, fiscal year settings, currency.
- Lists: customers, vendors, employees, products and services, chart of accounts, classes, locations, payment terms and tax codes.
- Transactions: invoices, bills, payments, sales receipts, estimates, credit memos, purchases, purchase orders, deposits, transfers, journal entries and time activities.
- Reports: profit and loss, balance sheet, cash flow, trial balance, general ledger, and accounts-receivable and accounts-payable ageing.
What we do with it:
- We answer the question that was asked. QuickBooks data is read in response to a specific request from a member of your team and used to produce the answer, report or draft they asked for.
- We send it to a language-model provider to compose that answer. Your QuickBooks data is transmitted to the providers named in section 3 (Anthropic, OpenAI) acting as our processors under contractual data-processing terms. It is not used by us or by them to train generalised AI models.
- We do not copy your books. We do not bulk-download, warehouse, or continuously synchronise your QuickBooks company. Reads are made when asked for and returned in the answer; a large result may be held briefly so the agent can refer back to it within the same conversation.
- We keep a record of what we did. Every action taken against your QuickBooks company is written to an activity record — who asked, what was done, whether it succeeded — which your administrators can read. Where a change to QuickBooks is proposed, we store that proposed change, and for an edit or deletion a copy of the document as QuickBooks held it at that moment, so the person approving can see exactly what will happen. These records therefore contain QuickBooks data.
- We never change your books on our own initiative. Any change — creating, editing, voiding or deleting a record — is first proposed, then must be approved by a person your workspace has appointed, and only then is sent to QuickBooks. We do not write to QuickBooks by any other route.
Access follows QuickBooks, not us. What each member of your team can see and do through Eesa AI is limited to the role they hold in QuickBooks, recorded by your administrator. We do not grant access that QuickBooks would not grant.
Tokens. The credentials that keep the connection alive are held server-side only and are never sent to your browser. The refresh token is stored by the QuickBooks connector service on a private volume with file permissions restricted to that service; it is not stored in the main application database and is not exposed through any API.
Disconnecting. You can revoke the connection at any time, either from within QuickBooks (Settings → Apps) or by contacting us at mail@chups.com. On disconnection we stop all access immediately and delete the stored tokens. QuickBooks data already held in activity records and proposed changes is deleted on the schedule in section 4, or sooner on request.
1.3.4 Other connected integrations
If you connect additional integrations (Stripe, Telegram, etc.), we receive only the data necessary for that integration as described in its respective consent screen.
1.4 Attendance and location (Eesa AI mobile app)
Attendance is off unless your employer turns it on for its workspace and you turn it on in the app and allow location access. When it is on, we collect:
- Work zones your employer sets up: a name, a place and a size.
- Arrivals and departures: when your phone crosses the edge of a work zone, the time, the zone, where the phone was, and how accurate that position was.
- Readings while you are checked in: now and then while you are checked in — when a work zone is crossed, when you open the app, when your network changes while the app is open, and when the Service checks in with your phone by a silent notification (no more than a few times an hour) — we record where your phone is and how accurate that is; whether it has a network connection and of what kind (Wi‑Fi, cellular or none); how location access for Eesa AI is set; whether iOS reports the position as produced by software rather than GPS; whether the phone restarted since the previous reading; and the time that passed between readings, measured on the phone. If your phone is offline, these readings are kept on the phone and sent when it is back online. Each reading is linked to the one before it with a checksum, so that missing or altered readings can be detected.
- Whether attendance can see you leave: when the app notices that it can no longer record a departure (Location Services off, location access set to Never, While Using or approximate, or attendance switched off in the app), and when it can again.
- The state of attendance on your phone: the app version, whether attendance and notifications are on, how location access is set, and when the phone last reported.
When you are not checked in, we do not collect where you are, except for the arrival or departure itself when you cross a work zone. While the app is open it may check your position on the phone to show whether you are at work; that position is not sent to us unless it records an arrival or departure.
What it is used for. To record the hours you work, and to let your employer check a shift record — for example when your phone was well away from the work zone while you were checked in, was switched off, stopped answering, had location turned off, reported a location made by software, or had its clock changed. These markers are shown to your employer's managers as information to review. They never change your hours automatically: a person at your employer reviews them and decides. Your employer may choose to receive alerts about shifts that need a look, and its managers may ask the Eesa AI assistant about attendance, in which case the relevant records are processed by the language-model providers named in section 3.
Who sees it. Your employer's attendance managers and administrators. You can see your own hours in the app. Attendance information is not used for advertising and is not sold or shared.
Your choices. You can turn attendance off in the app, or decline or change location access in your phone's settings, at any time. If you do while you are at work, your employer will see that attendance could not be checked for that time. Signing out of the app sends anything it has kept and then deletes it from the phone.
2. How we use information
- To provide the Service: authenticate you, execute the workflows and agent actions you request, send replies through the channel you contacted us on.
- To operate your tenant: store your business data so it is available across sessions and to your authorized teammates.
- To provide attendance to your employer: record hours worked and help your employer check shift records, as described in section 1.4.
- To improve the Service: diagnose bugs, monitor performance, and improve agent quality. Aggregate usage statistics may be reviewed; individual messages are reviewed only if you ask for support or to investigate abuse.
- To communicate with you: service notifications, security alerts, billing notices.
- To comply with law: respond to lawful requests, prevent fraud, enforce our Terms.
3. How we share information
We do not sell your personal information. We share data only in these circumstances:
- With your tenant: data you upload or generate within a tenant is visible to other authorized members of that tenant per role-based permissions you control. Attendance information (section 1.4) is visible to your employer's attendance managers and administrators.
- With service providers we rely on: infrastructure (Amazon Web Services), application hosting (Railway), databases (Supabase / Postgres), large-language-model providers (Anthropic, OpenAI) for processing your messages, vector database (Qdrant Cloud), notification delivery (Google Firebase Cloud Messaging and Apple Push Notification service), Stripe (billing). These providers process data on our behalf under contractual data-processing terms.
- With integrations you connect: Google, Meta/WhatsApp, etc. — limited to the scope you granted.
- With law enforcement: only when legally required and after good-faith review.
- In a business transfer: if Chups Inc. is acquired or merges, your data may transfer to the successor under the same Privacy Policy.
4. Data retention
- Account data: retained while your account is active. Deleted within 90 days of account closure unless required to be retained for legal/tax reasons.
- Business data: retained while your tenant is active. Deleted within 90 days of tenant cancellation.
- Chat conversation history: retained for 12 months by default. You can request earlier deletion at any time.
- Operational logs: retained for up to 90 days for security and debugging.
- QuickBooks activity records and proposed changes: retained for 24 months, because they are the record of who authorised a change to your accounts and are the kind of record an audit asks for. Deleted within 90 days of the QuickBooks connection being revoked or your tenant closing, unless you ask us to keep them longer for your own audit purposes. Stored QuickBooks tokens are deleted immediately on disconnection.
- Attendance records (arrivals, departures and hours): retained while your employer's workspace is active, as part of its time records, and deleted within 90 days of the workspace closing. Your employer can export them first, and is responsible for keeping time records for as long as the law requires it to.
- Attendance readings and checks (section 1.4): the readings from your phone, the reports of location being off or on, and the checks sent to your phone are deleted after 12 months, or within 90 days of the workspace closing if sooner.
- On your phone: attendance readings are removed from the phone once we have received them (the most recent one is kept to link the next), and all of them are deleted when you sign out.
- Backups: backups containing your data are rotated and fully purged within 35 days of deletion.
5. Data security
- Transport: all connections to the Service use TLS 1.2+.
- Storage: integration credentials and other sensitive fields are encrypted at rest using Fernet symmetric encryption with keys held in a separate secret store.
- Access: tenant data isolation is enforced at the database query layer. Internal access to tenant data by Chups Inc. staff is limited to the minimum needed for support and security investigations, logged, and auditable.
- No system is perfectly secure; we use commercially reasonable safeguards.
6. Your rights
Depending on your jurisdiction, you may have the right to:
- Access the personal information we hold about you.
- Correct inaccurate information.
- Delete your account and associated personal information.
- Export your data in a portable format.
- Object to or restrict certain processing.
- Withdraw consent for integrations (you can revoke a Google or WhatsApp connection at any time from /settings/integrations; a QuickBooks company can be disconnected from within QuickBooks under Settings → Apps, or by emailing us).
To exercise any right, email mail@chups.com. We respond within 30 days. California residents have the specific rights described in section 13. We will not discriminate or retaliate against anyone for exercising a privacy right.
7. International transfers
The Service is operated from servers located in the United States. If you access it from outside the US, you are transferring your data to the US for processing. Where required, we rely on standard contractual clauses or your explicit consent for such transfers.
8. Children
The Service is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected such information, contact us and we will delete it.
9. Changes to this policy
We may update this policy from time to time. When we make material changes, we will notify users via email or an in-app banner at least 7 days before the change takes effect. Continued use of the Service after the effective date constitutes acceptance. The date at the top of this page says when it last changed.
Do Not Track and Global Privacy Control. We do not track you across other websites and do not sell or share personal information, so a browser's Do Not Track or Global Privacy Control signal does not change what we do. If that ever changed, we would treat a Global Privacy Control signal as a request to opt out.
10. Google API Services User Data Policy compliance
Eesa AI's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular:
- We only use Google user data to provide and improve user-facing features.
- We do not use Google user data to develop, improve, or train generalized AI models.
- We do not transfer Google user data to third parties except as necessary to provide the service, comply with applicable law, or as part of a merger or acquisition.
- We do not allow humans to read Google user data unless we have obtained explicit consent from the user, it is necessary for security purposes (such as investigating abuse), or to comply with applicable law.
11. Meta Platform Terms compliance
Eesa AI's use of the WhatsApp Business Cloud API complies with Meta Platform Terms. We do not sell, license, purchase, or otherwise share personal data obtained from Meta APIs with third parties for advertising or any other purpose prohibited by Meta's terms.
12. Intuit QuickBooks data
Eesa AI is an independent application. It is not produced, endorsed or certified by Intuit Inc., and "QuickBooks" and "Intuit" are trademarks of Intuit Inc. Our use of data obtained from the QuickBooks Online API is governed by the Intuit Developer terms in addition to this policy. In particular:
- We access a QuickBooks company only after an administrator of that company has authorised the connection, and only for the company they authorised.
- We use QuickBooks data solely to provide the features your team asks for — answering questions about the accounts, and preparing changes for a person to approve.
- We do not use QuickBooks data to develop, improve, or train generalised AI models, our own or anyone else's.
- We do not sell, rent, or license QuickBooks data, and we do not share it for advertising or any other purpose unrelated to operating the Service.
- We share QuickBooks data only with the processors named in section 3, only as needed to operate the Service, and under contractual data-processing terms.
- We do not allow our staff to read your QuickBooks data except where you have asked us for support, where it is necessary to investigate a security problem or abuse, or where the law requires it. Such access is limited, logged and auditable.
- We write to your QuickBooks company only through a change that a person in your workspace has explicitly approved.
- On disconnection we stop accessing the company immediately and delete the stored tokens.
13. Your California privacy rights
This section applies to residents of California, including employees and contractors of businesses that use the Service, under the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA") and other California law.
13.1 Our role
For information about a business's staff — attendance, staff records and the like — we act as a service provider (processor) to that business, which decides how the information is used; you can send a request to the business or to us, and we will help the business respond. For your own account with us, we are responsible for your information directly.
13.2 What we collect, where from, and why
In the last 12 months we have collected these categories of personal information, from you, your device, your employer and integrations you connect, for the purposes in section 2:
- Identifiers: name, email address, account and device identifiers, IP address.
- Internet or other electronic network activity: usage data and app diagnostics (section 1.2).
- Geolocation data: precise location for attendance (section 1.4) and approximate location derived from IP.
- Professional or employment-related information: role, work zones, attendance records and hours.
- Commercial information: subscription and billing records for account holders.
- Content you provide: messages, and files and business data you upload or connect.
- Sensitive personal information: precise geolocation (attendance), and account log-in details. We use these only to provide the Service as described and for security, which are uses that do not give rise to a right to limit them. We do not use sensitive personal information to infer characteristics about you.
We disclose these categories for business purposes to the service providers listed in section 3, and workspace information to the business that controls the workspace. How long we keep each category is set out in section 4.
13.3 No sale or sharing
We do not sell personal information, and we do not share it for cross-context behavioral advertising. We have not done so in the last 12 months, and we do not knowingly sell or share the personal information of anyone under 16. We do not disclose personal information to third parties for their own direct marketing purposes (California Civil Code § 1798.83).
13.4 Your rights
- Know and access: what personal information we have collected about you, its categories and sources, why we collected it, who we disclosed it to, and a copy of the specific pieces.
- Delete personal information we collected from you, subject to legal exceptions (for example, records a business must keep by law).
- Correct inaccurate personal information.
- Opt out of sale or sharing, and limit the use of sensitive personal information — although we do neither of the things these rights exist to stop.
- No discrimination or retaliation for exercising these rights. California law also prohibits an employer from retaliating against an employee, applicant or contractor for exercising them.
13.5 How to make a request
Email mail@chups.com with the subject "California privacy request". We confirm receipt within 10 business days and respond within 45 days; if we need longer (up to 45 more days) we will tell you why. We verify a request by matching it to information associated with your account, such as by confirming it from your account email. You may use an authorized agent, who must show your signed permission; we may still ask you to verify your identity directly. For information we hold for your employer, we may pass your request to your employer and help it respond.