Privacy Policy · Last updated July 28, 2026
Your messages never reach us.
WhatAI has no servers, no accounts and no analytics. Everything the app knows about you is stored in a database on your phone. This page is the long version of that one sentence.
The short version. We do not collect, receive, store, sell or share any of your personal data — because there is no WhatAI server for it to go to. The only time any message text leaves your phone is if you deliberately turn on a cloud AI engine, and then it goes from your device straight to that AI provider under your own API key, without passing through us.
1. Who this policy is from
WhatAI (“the app”, “we”, “us”) is an Android application published by Martai. This policy explains what the app does with information on your device, and applies to the app and to this website.
WhatAI is an independent application. It is not affiliated with, endorsed by, or connected to WhatsApp LLC or Meta Platforms, Inc.
2. What we collect
Nothing. There is no sign-up, no login, no email address, no password and no user profile. The app contains no analytics SDK, no advertising identifier, no crash-reporting service and no third-party tracking library of any kind. We operate no backend service that the app talks to, so there is no place on our side where your data could be stored even by accident.
Because we hold no data about you, we cannot sell it, rent it, license it, trade it, or hand it to an advertiser or data broker.
3. What the app stores on your phone
To do its job the app keeps a local database on your device. This database is private to the app, is not readable by other apps, and is never uploaded to us. It holds:
- Captured messages — the text of WhatsApp and WhatsApp Business messages that arrive as notifications, together with the sender’s display name, the conversation title, whether it is a group, and the time it arrived.
- Phone numbers, when they can be determined — WhatsApp shows a raw number for senders who are not in your address book, and shows a saved contact’s name otherwise. If you grant contacts permission the app can map that name back to a number so chats group correctly. See section 6.
- Your reply setup — your rules, your reply profiles, the example replies and personal notes you write for the AI, and your list of picked contacts.
- A log of replies sent — what was sent, to whom, when, and which rule or profile produced it, so you can audit the app’s behaviour.
- Your settings — audience, group toggle, quiet hours, cooldown, chosen AI engine, and any AI provider API key you enter.
4. What leaves your phone — and only if you choose it
The app can generate replies three different ways. Which one you pick decides entirely whether anything leaves the device.
Word-for-word rules — nothing leaves
Rule-based replies are matched and sent locally. No network request is made. The app works with no internet connection at all in this mode.
On-device AI — nothing leaves
If you select the on-device engine, the language model runs on your phone’s own processor. The model file is downloaded or imported once from a source you choose; after that, generating a reply requires no internet connection and no message text is transmitted anywhere.
Cloud AI — the message text is sent to the provider you chose
If you select a cloud engine and enter your own API key, then each time that engine writes a reply the app sends the recent messages from that one conversation, plus the instructions and examples you wrote, directly to:
- Google (
generativelanguage.googleapis.com) if you chose Gemini, or - Anthropic (
api.anthropic.com) if you chose Claude.
The request goes from your phone straight to that provider over an encrypted connection, authenticated with the API key you supplied. It does not pass through any system operated by us, and we have no ability to read, log or retain it. What the provider does with that text is governed by their terms and privacy policy, under your own account with them — so read theirs before enabling a cloud engine. No other content is sent: not your contact list, not chats other than the one being answered, not your other rules.
If you never enable a cloud engine, WhatAI makes no outbound network request at all beyond the one-time model download you initiate yourself.
5. Messages we will never reply to
Before any automatic reply is sent, the incoming message is checked for sensitive content. If it appears to carry a one-time password, a verification or 2FA code, a password, a PIN or card details, no automatic reply is sent and the message is left for you to handle. The check runs entirely on your device. It is deliberately cautious, so it will occasionally skip a message that was harmless.
6. Permissions, and why each one exists
| Permission | Why it is needed |
|---|---|
| Notification access | The core function. It is the only way an Android app can read an incoming WhatsApp message and send a reply back to it. Without it the app cannot work at all. |
| Contacts (optional) | Used only to map a sender’s display name back to their phone number, so chats group correctly and you can pick contacts by name. The index is held in memory on your device and is never transmitted. Decline it and the app still works — messages are simply stored without a resolved number. |
| Internet | Used only for cloud AI replies and for the optional one-time on-device model download. Nothing else uses the network. |
| Notifications | Lets the app show its own status notice so you can see it is running. |
| Run at startup | Restarts the reply service after you reboot, so it does not silently stop. |
| Foreground service | Keeps the notification listener resident so Android does not kill it while your phone is idle. This is the difference between an auto reply app that works on day thirty and one that quietly stops on day two. |
| Ignore battery optimisation (optional) | You are asked, never forced. Without it, aggressive battery managers can stop replies while the phone sleeps. |
7. Third parties
The complete list of parties that can ever receive anything, and only at your instruction:
- Google (Gemini API) — only if you enable the Gemini engine with your own API key. Receives the conversation text being answered.
- Anthropic (Claude API) — only if you enable the Claude engine with your own API key. Receives the conversation text being answered.
- Google Play — distributes the app and, if in-app purchases are offered in future, would process payment. We never see or store card details.
- Whoever you share an export with — if you export a conversation to CSV or JSON, the file goes wherever you send it. That choice is yours, and after that the file is outside the app’s control.
There are no others. No ad network, no analytics vendor, no data broker, no CDN of ours.
8. Android backup
Android’s own backup feature can include the app’s message database in the automatic backup of your phone to your Google account, and in a device-to-device transfer when you set up a new phone. That backup belongs to you, is encrypted by Google using your device credentials, and is not accessible to us. You can turn it off for this app, or entirely, in your phone’s Settings under System → Backup.
9. Deleting your data
Because nothing is held on a server, deletion is immediate and entirely in your hands. You can delete individual conversations inside the app, clear the app’s storage from Android’s app settings, or uninstall the app — which removes the database and every setting with it. There is no account to close and no request to file. Full instructions are on the delete your data page.
10. Security
Your data sits in the app’s private storage area, which Android isolates from other apps. Cloud AI requests use encrypted HTTPS connections. That said, no method of storage or transmission is perfectly secure, and a device that is rooted, compromised or shared with someone else weakens every protection above — please lock your phone.
11. Children
WhatAI is not directed at children under 13, and we do not knowingly collect information from them. Since we collect no information from anyone, there is nothing for us to delete on request; a parent who wants the app’s local data removed can uninstall it from the child’s device.
12. Your rights
Privacy laws such as the GDPR, the CCPA and India’s DPDP Act give you rights to access, correct, export and delete the personal data a company holds about you. We hold none, so there is nothing for us to disclose or erase. In practice you already exercise every one of those rights directly: the data is on your device, you can read it in the app, export it to CSV or JSON, and delete it whenever you like.
13. Changes to this policy
If the app’s data handling ever changes — for example if a future version introduces an optional account — this page will be updated before that version ships, and the date at the top will change. Continuing to use the app after an update means you accept the revised policy.
14. Contact
Questions about this policy, or about anything the app does with your data, go to support@martai.in. We answer.