Is an AI agent safe for customer data? The questions to ask, and our answers

Handing customer conversations to a piece of software is a trust decision. Chats contain names, numbers, health details, addresses and photos. Before you connect an agent to your number, you should know exactly where that data goes, who can see it, and what it is used for. Here are the questions to ask, and our answers to each.

By Ritchie, ReplyKit · Published 5 September 2026 · 7 min read

Quick answer

Ask any AI agent vendor six things: where data is stored, which third parties process it, whether conversations train AI models, who at the vendor can read chats and how that is logged, how customers exercise their rights, and what happens when you leave. ReplyKit's answers: on our servers with named sub-processors, no training on your data, reason-gated and logged staff access, export and deletion in Settings, and full deletion when you close the account.

The six questionsReplyKit's answersYour side of the responsibilitySecurity basics you should expectFAQ

The six questions

  1. Where is the data stored? Country, hosting provider, encryption in transit and at rest.
  2. Which third parties process it? The AI model provider, email provider, payment processor, hosting. Ask for the list.
  3. Is customer data used to train AI models? The answer should be no, in writing.
  4. Who at the vendor can read conversations, and is it logged? Support staff need access sometimes; it should be for a reason and recorded.
  5. How do customers exercise their rights? Export, correction, deletion, opt-out.
  6. What happens when I leave? Export first, then deletion, with a timeline.

ReplyKit's answers

Your side of the responsibility

You are the controller of your customers' data; the vendor processes it for you. That means you decide what the agent collects (do not ask for what you do not need), you tell customers how their data is used, and you honour their requests. Under Malaysia's PDPA and Singapore's PDPA, a phone number and a chat are personal data. Our Acceptable Use Policy also forbids putting personal data you have no right to use into the knowledge base, and forbids configuring an agent to collect passwords, one-time codes or card details, which our platform rules refuse regardless of instructions.

Security basics you should expect

These are table stakes, and they are what ReplyKit runs. If a vendor cannot answer the six questions in plain language, that is the answer.

Frequently asked questions

Are my WhatsApp conversations used to train AI?

Not by ReplyKit. Conversations and knowledge are sent to the model provider only to generate the reply to the message at hand and are not used to train shared models.

Who can read my customers' chats?

You and your team. ReplyKit staff open conversations only with a stated reason that is written to an audit log.

Where is the data stored?

On ReplyKit's servers with the sub-processors listed in the privacy policy, encrypted in transit, with nightly backups.

Can I export or delete everything?

Yes. Export as JSON or CSV and delete the account from Settings; deletion removes every record and cancels billing.

What does the agent refuse to collect?

Passwords, one-time codes, PINs and card details. Platform rules refuse these even if a business asks for them.

Read the privacy policy before you connect

Named processors, no training on your data, logged access. Then start free.

Read the privacy policy
Written by Ritchie, ReplyKitPart of the small team in Malaysia that builds and runs ReplyKit. Writes about WhatsApp automation, AI customer service and small business lead response.

How we know this. These are the questions ReplyKit customers ask us most, answered from how the product actually works: encryption in transit, no model training on customer data, access to conversations logged and reason-gated in our own operator console, and a published sub-processor list. Product figures in this article (limits, prices, per-reply costs) are taken from ReplyKit as it runs today and are re-checked when we update the page. Where we cite outside research, the source is linked below. We sell ReplyKit, so read our product claims with that in mind; we say where a different tool or no tool is the better choice. About ReplyKit.

Sources and further reading

  1. ReplyKit Privacy Policy · sub-processors and data handling
  2. Personal Data Protection Department, Malaysia (PDPA 2010)
  3. Personal Data Protection Commission, Singapore
  4. ReplyKit Acceptable Use Policy · what we refuse to automate

ReplyKit is an independent product and is not affiliated with or endorsed by Meta or WhatsApp. This article describes ReplyKit's practices at the time of writing and general questions to ask vendors. It is not legal advice on your data protection obligations.