Privacy Policy

Last updated: 31 July 2026

1. Introduction

BookMe AI | Your AI Receptionist That Never Sleeps ("BookMe AI", "we", "our", or "us") is operated by Mythril-Tech S.R.L., Str. Rapsodiei nr. 7, Sc. 1, Et. 4, Ap. 10, Cluj-Napoca, Cluj County, Romania (CUI 47085909). We provide an AI-powered appointment scheduling service that integrates with WhatsApp and Google Calendar. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service.

Our roles: For your business account, billing, and marketing site data, we act as an independent data controller. For personal data of your end customers that we process through WhatsApp and booking (names, phone numbers, messages, appointments), we act as a data processor on your behalf under our Data Processing Agreement.

2. Information We Collect

2.1 Information You Provide

  • Account Information: Name, email address, and Google account credentials when you sign in
  • Business Information: Business name, profession type, operating hours, services offered, and service pricing
  • WhatsApp Information: WhatsApp Business phone number, WhatsApp Business Account ID (WABA ID), and related credentials

2.2 Information Collected Automatically

  • WhatsApp Messages: Messages sent by your customers to your WhatsApp Business number, including message content, timestamps, and sender phone numbers
  • Calendar Data: Your Google Calendar availability, events, and appointment details (through Google Calendar API)
  • Appointment Data: Appointment requests, confirmations, cancellations, and rescheduling information
  • Usage Data: Log data, device information, and interaction with our service

3. How We Use Your Information

We use the information we collect for the following purposes:

  • Provide Our Service: Process appointment requests, check calendar availability, book appointments, and send confirmations via WhatsApp
  • AI Processing: Use Google Gemini AI to understand and respond to customer messages in natural language
  • Service Management: Manage your services, business profile, and operating hours
  • Communication: Send you service updates, technical notices, and support messages
  • Improve Our Service: Analyze usage patterns to enhance functionality and user experience
  • Security: Detect, prevent, and address technical issues and fraudulent activity
  • Legal Compliance: Comply with legal obligations and enforce our terms of service

4. How We Share Your Information

We share your information with third-party service providers and in the following circumstances:

4.1 Third-Party Service Providers (Subprocessors)

The full list is maintained at /subprocessors. Key subprocessors include:

  • Meta Platforms Ireland Limited (WhatsApp): WhatsApp Cloud API for sending and receiving customer messages.
  • Google LLC — Gemini API: AI processing of customer messages to generate scheduling replies (paid API tier; not used for model training).
  • Google LLC — Calendar API: Checking availability and creating appointments in your Google Calendar.
  • OpenAI, L.L.C.: Alternative AI provider when your account is set to use OpenAI instead of Gemini (API data not used for model training).
  • Supabase, Inc.: PostgreSQL database hosting (data stored in EU — Dublin, Ireland).
  • Vercel, Inc.: Application hosting and serverless compute.
  • Twilio Inc. (legacy only): Legacy WhatsApp path for tenants connected before migration to Meta Cloud API; not used for new tenants.

4.2 Billing

Revolut Ltd processes your subscription billing data. We act as controller for billing data; Revolut is listed here for transparency but is not a subprocessor under our Data Processing Agreement for your customers' data.

4.3 Legal Requirements

We may disclose your information if required by law, court order, or government regulation, or if we believe disclosure is necessary to protect our rights, your safety, or the safety of others.

4.4 Business Transfers

In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity.

5. Data Retention

We retain your information for as long as necessary to provide our service and comply with legal obligations:

  • Active accounts: Data is retained while your account is active and needed to provide the service.
  • Account deletion: When you delete your account, data is removed from production systems immediately. Encrypted backups are purged within 90 days.
  • Contract termination: If your subscription ends without account deletion, we delete or return your data within 30 days, unless you request earlier deletion.
  • Legal obligations: We may retain data longer only where required by applicable law, with documented justification.
  • OAuth Tokens: Stored securely and revoked when you disconnect your account or delete it.

6. Data Security

We implement appropriate technical and organizational measures to protect your information:

  • Encryption of data in transit (HTTPS/TLS)
  • Secure storage of OAuth tokens and API credentials
  • Database encryption at rest
  • Access controls and authentication mechanisms
  • Regular security assessments and updates

However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.

7. Your Rights and Choices

Depending on your location, you may have the following rights:

  • Access: Request a copy of the personal information we hold about you
  • Correction: Update or correct inaccurate information through your account settings
  • Deletion: Request deletion of your account and associated data
  • Portability: Request a copy of your data in a machine-readable format
  • Objection: Object to processing of your information for certain purposes
  • Withdraw Consent: Revoke calendar access or disconnect WhatsApp at any time through Settings

To exercise these rights, please contact us at the email address provided below.

8. WhatsApp Business Policy Compliance

Our use of WhatsApp is subject to WhatsApp Business Policy and WhatsApp Commerce Policy. We comply with Meta's requirements by:

  • Only processing messages for legitimate business purposes (appointment scheduling)
  • Not using messages for advertising or marketing without explicit consent
  • Respecting customer opt-out requests
  • Maintaining this publicly accessible privacy policy
  • Implementing appropriate security measures for message handling

9. Google API Services User Data Policy

BookMe AI | Your AI Receptionist That Never Sleeps's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • We only request calendar scopes necessary for appointment scheduling
  • Calendar data is used solely to check availability and create appointments
  • We do not share calendar data with third parties except as disclosed
  • We do not use calendar data for advertising or marketing purposes
  • You can revoke calendar access at any time through your Google Account settings

10. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence, including the United States, where some of our subprocessors operate. Production database storage is in the European Union (Dublin, Ireland). Transfers to the United States are protected by the EU-U.S. Data Privacy Framework or the 2021 EU Standard Contractual Clauses, as described for each subprocessor on our subprocessors page.

11. Children's Privacy

Our service is not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If you become aware that a child has provided us with personal information, please contact us, and we will take steps to delete such information.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new Privacy Policy on this page and updating the "Last updated" date. Your continued use of the service after changes become effective constitutes acceptance of the revised policy.

13. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:

Mythril-Tech S.R.L. (BookMe AI)

Str. Rapsodiei nr. 7, Sc. 1, Et. 4, Ap. 10, Cluj-Napoca, Romania

Email: contact@mythril-tech.com

For data subject requests (access, deletion, correction), please include "Privacy Request" in your email subject line.

Additional Resources