Is an AI agent safe for customer data? The questions to ask, and our answers
Handing customer conversations to a piece of software is a trust decision. Chats contain names, numbers, health details, addresses and photos. Before you connect an agent to your number, you should know exactly where that data goes, who can see it, and what it is used for. Here are the questions to ask, and our answers to each.
Quick answer
Ask any AI agent vendor six things: where data is stored, which third parties process it, whether conversations train AI models, who at the vendor can read chats and how that is logged, how customers exercise their rights, and what happens when you leave. ReplyKit's answers: on our servers with named sub-processors, no training on your data, reason-gated and logged staff access, export and deletion in Settings, and full deletion when you close the account.
The six questions
- Where is the data stored? Country, hosting provider, encryption in transit and at rest.
- Which third parties process it? The AI model provider, email provider, payment processor, hosting. Ask for the list.
- Is customer data used to train AI models? The answer should be no, in writing.
- Who at the vendor can read conversations, and is it logged? Support staff need access sometimes; it should be for a reason and recorded.
- How do customers exercise their rights? Export, correction, deletion, opt-out.
- What happens when I leave? Export first, then deletion, with a timeline.
ReplyKit's answers
- Storage. Conversations, contacts and knowledge live in your workspace on our servers, encrypted in transit. Nightly backups are kept, and an encrypted off-site copy is supported.
- Processors. Listed in our privacy policy: the AI model provider that generates replies, the email provider for notifications, Stripe for billing, and our hosting provider. We add to the list before we add a provider.
- Training. Your conversations and knowledge are not used to train shared AI models. They are sent to the model provider only to generate the reply to the message at hand.
- Staff access. Our operator console does not browse conversations. Opening a customer's conversations requires a stated reason, which is written to an audit log along with who and when. Agent instructions and knowledge are scanned for Acceptable Use violations; conversations are not scanned automatically.
- Rights. Export everything as JSON or CSV from Settings. Delete the account from Settings; it cancels billing, disconnects numbers and removes every record.
- Leaving. Export, then delete. Deletion is immediate for the live database; backups roll off on their retention schedule.
Your side of the responsibility
You are the controller of your customers' data; the vendor processes it for you. That means you decide what the agent collects (do not ask for what you do not need), you tell customers how their data is used, and you honour their requests. Under Malaysia's PDPA and Singapore's PDPA, a phone number and a chat are personal data. Our Acceptable Use Policy also forbids putting personal data you have no right to use into the knowledge base, and forbids configuring an agent to collect passwords, one-time codes or card details, which our platform rules refuse regardless of instructions.
Security basics you should expect
- HTTPS everywhere, with strict transport security and a content security policy.
- Passwords hashed, sessions expiring, password reset links single-use and short-lived.
- Every request checked against the workspace it belongs to, so one customer cannot see another's data.
- Rate limits on login, signup and public endpoints.
- Two-factor authentication on the vendor's own operator access.
- Dependency updates when advisories are published.
These are table stakes, and they are what ReplyKit runs. If a vendor cannot answer the six questions in plain language, that is the answer.
Frequently asked questions
Are my WhatsApp conversations used to train AI?
Not by ReplyKit. Conversations and knowledge are sent to the model provider only to generate the reply to the message at hand and are not used to train shared models.
Who can read my customers' chats?
You and your team. ReplyKit staff open conversations only with a stated reason that is written to an audit log.
Where is the data stored?
On ReplyKit's servers with the sub-processors listed in the privacy policy, encrypted in transit, with nightly backups.
Can I export or delete everything?
Yes. Export as JSON or CSV and delete the account from Settings; deletion removes every record and cancels billing.
What does the agent refuse to collect?
Passwords, one-time codes, PINs and card details. Platform rules refuse these even if a business asks for them.
Read the privacy policy before you connect
Named processors, no training on your data, logged access. Then start free.
Sources and further reading
- ReplyKit Privacy Policy · sub-processors and data handling
- Personal Data Protection Department, Malaysia (PDPA 2010)
- Personal Data Protection Commission, Singapore
- ReplyKit Acceptable Use Policy · what we refuse to automate
ReplyKit is an independent product and is not affiliated with or endorsed by Meta or WhatsApp. This article describes ReplyKit's practices at the time of writing and general questions to ask vendors. It is not legal advice on your data protection obligations.