Privacy Policy

Last updated: September 25, 2026 · Effective: September 25, 2026 · Operator: Chups Inc. (operating the Eesa AI service at eesa.ai)

This Privacy Policy describes how Chups Inc. ("we", "us", "our") collects, uses, stores, and shares information when you use the Eesa AI service (the "Service") accessible at eesa.ai and via integrated messaging channels including WhatsApp Business and Telegram.

By using the Service you agree to the practices described here. If you do not agree, do not use the Service.

If you use Eesa AI through your employer. When a business uses the Service for its staff — for example to record attendance — the business decides what is collected and why, and we process that information on its behalf as its service provider. You can direct questions and requests about it to your employer or to us (see section 13 if you are in California).

1. Information we collect

1.1 Information you provide

1.2 Information collected automatically

1.3 Information from third parties

When you connect an external account, we receive specific information from that service:

1.3.1 Google Workspace

When you connect Google Workspace, we request the following scopes:

We only access Google data in response to your explicit requests through the agent. We do not bulk-scan, train models on, or share your Google data with any third party. Access tokens and refresh tokens are stored encrypted and used solely to fulfill your requests.

1.3.2 WhatsApp Business Cloud API (Meta)

When messages are exchanged through our WhatsApp Business number, we receive from Meta:

We use this information only to: (a) route the message to the appropriate agent or workflow within your tenant, (b) compose and send a reply through the same WhatsApp number, and (c) maintain conversation history for support continuity.

1.3.3 QuickBooks Online (Intuit)

A QuickBooks company is connected once, by a person who holds the Primary admin or Company admin role in that company — Intuit permits no one else to connect an application. That connection is to a single QuickBooks company and can be revoked at any time (see below).

Through that connection we may read, when a member of your team asks us to:

What we do with it:

Access follows QuickBooks, not us. What each member of your team can see and do through Eesa AI is limited to the role they hold in QuickBooks, recorded by your administrator. We do not grant access that QuickBooks would not grant.

Tokens. The credentials that keep the connection alive are held server-side only and are never sent to your browser. The refresh token is stored by the QuickBooks connector service on a private volume with file permissions restricted to that service; it is not stored in the main application database and is not exposed through any API.

Disconnecting. You can revoke the connection at any time, either from within QuickBooks (Settings → Apps) or by contacting us at mail@chups.com. On disconnection we stop all access immediately and delete the stored tokens. QuickBooks data already held in activity records and proposed changes is deleted on the schedule in section 4, or sooner on request.

1.3.4 Other connected integrations

If you connect additional integrations (Stripe, Telegram, etc.), we receive only the data necessary for that integration as described in its respective consent screen.

1.4 Attendance and location (Eesa AI mobile app)

Attendance is off unless your employer turns it on for its workspace and you turn it on in the app and allow location access. When it is on, we collect:

When you are not checked in, we do not collect where you are, except for the arrival or departure itself when you cross a work zone. While the app is open it may check your position on the phone to show whether you are at work; that position is not sent to us unless it records an arrival or departure.

What it is used for. To record the hours you work, and to let your employer check a shift record — for example when your phone was well away from the work zone while you were checked in, was switched off, stopped answering, had location turned off, reported a location made by software, or had its clock changed. These markers are shown to your employer's managers as information to review. They never change your hours automatically: a person at your employer reviews them and decides. Your employer may choose to receive alerts about shifts that need a look, and its managers may ask the Eesa AI assistant about attendance, in which case the relevant records are processed by the language-model providers named in section 3.

Who sees it. Your employer's attendance managers and administrators. You can see your own hours in the app. Attendance information is not used for advertising and is not sold or shared.

Your choices. You can turn attendance off in the app, or decline or change location access in your phone's settings, at any time. If you do while you are at work, your employer will see that attendance could not be checked for that time. Signing out of the app sends anything it has kept and then deletes it from the phone.

2. How we use information

3. How we share information

We do not sell your personal information. We share data only in these circumstances:

4. Data retention

5. Data security

6. Your rights

Depending on your jurisdiction, you may have the right to:

To exercise any right, email mail@chups.com. We respond within 30 days. California residents have the specific rights described in section 13. We will not discriminate or retaliate against anyone for exercising a privacy right.

7. International transfers

The Service is operated from servers located in the United States. If you access it from outside the US, you are transferring your data to the US for processing. Where required, we rely on standard contractual clauses or your explicit consent for such transfers.

8. Children

The Service is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected such information, contact us and we will delete it.

9. Changes to this policy

We may update this policy from time to time. When we make material changes, we will notify users via email or an in-app banner at least 7 days before the change takes effect. Continued use of the Service after the effective date constitutes acceptance. The date at the top of this page says when it last changed.

Do Not Track and Global Privacy Control. We do not track you across other websites and do not sell or share personal information, so a browser's Do Not Track or Global Privacy Control signal does not change what we do. If that ever changed, we would treat a Global Privacy Control signal as a request to opt out.

10. Google API Services User Data Policy compliance

Eesa AI's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular:

11. Meta Platform Terms compliance

Eesa AI's use of the WhatsApp Business Cloud API complies with Meta Platform Terms. We do not sell, license, purchase, or otherwise share personal data obtained from Meta APIs with third parties for advertising or any other purpose prohibited by Meta's terms.

12. Intuit QuickBooks data

Eesa AI is an independent application. It is not produced, endorsed or certified by Intuit Inc., and "QuickBooks" and "Intuit" are trademarks of Intuit Inc. Our use of data obtained from the QuickBooks Online API is governed by the Intuit Developer terms in addition to this policy. In particular:

13. Your California privacy rights

This section applies to residents of California, including employees and contractors of businesses that use the Service, under the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA") and other California law.

13.1 Our role

For information about a business's staff — attendance, staff records and the like — we act as a service provider (processor) to that business, which decides how the information is used; you can send a request to the business or to us, and we will help the business respond. For your own account with us, we are responsible for your information directly.

13.2 What we collect, where from, and why

In the last 12 months we have collected these categories of personal information, from you, your device, your employer and integrations you connect, for the purposes in section 2:

We disclose these categories for business purposes to the service providers listed in section 3, and workspace information to the business that controls the workspace. How long we keep each category is set out in section 4.

13.3 No sale or sharing

We do not sell personal information, and we do not share it for cross-context behavioral advertising. We have not done so in the last 12 months, and we do not knowingly sell or share the personal information of anyone under 16. We do not disclose personal information to third parties for their own direct marketing purposes (California Civil Code § 1798.83).

13.4 Your rights

13.5 How to make a request

Email mail@chups.com with the subject "California privacy request". We confirm receipt within 10 business days and respond within 45 days; if we need longer (up to 45 more days) we will tell you why. We verify a request by matching it to information associated with your account, such as by confirming it from your account email. You may use an authorized agent, who must show your signed permission; we may still ask you to verify your identity directly. For information we hold for your employer, we may pass your request to your employer and help it respond.

Contact

Operator: Chups Inc.

Email: mail@chups.com

California privacy requests: mail@chups.com, subject "California privacy request"

Service URL: https://eesa.ai