Privacy Policy
Last updated: 17 August 2026
Who we are
Hyperbots is a platform operated by The Two Apps, identified by the domain thetwoapps.com. In this policy “we” and “us” mean The Two Apps. Our full registered company name is The Two Apps and we are registered in Pakistan.
This policy explains what personal information Hyperbots handles, where it comes from, why we handle it, who we share it with, how long we keep it and how you can ask us to delete it. It describes what the software actually does today. Where a control or a deletion routine is not yet built, this policy says so plainly instead of promising it.
Who this policy is about
Hyperbots is used by an agency to run the Meta accounts of client businesses. Two different groups of people therefore appear in this policy.
- Business users — staff of the agency and of each client business who sign in to Hyperbots. We decide how their account information is handled, so for them we are the data controller.
- Customers of those businesses — members of the public who send a WhatsApp message, a Messenger or Instagram message, a comment or an order to a business that uses Hyperbots. We handle their information only on that business’s instructions, so the business is the data controller and we act as its processor.
If you messaged a business and want to know what it holds about you, that business is the right first point of contact. You can also write to us at team@thetwoapps.com and we will help.
Where the information comes from
- From Meta. When a business connects its WhatsApp, Facebook Page, Instagram, Threads, advertising or commerce account, Meta tells us about those accounts and then sends us messages, comments and statistics as they happen.
- From the business. What its staff type into Hyperbots: posts, replies, message templates, advertising campaigns, product listings and settings.
- From the customer. The content of the messages and comments customers send to the business, exactly as Meta delivers them to us.
We do not buy personal information from data brokers, we do not track you across other websites, and Hyperbots sets no advertising cookies.
What we collect
The list below is written from the actual database this product uses. Each entry names what is stored and why it is there.
- Businesses and their staff. The business name, its plan and status, and for each staff member their email address, display name and sign-in identifier. Sign-in is handled by Amazon Cognito; Hyperbots never sees or stores a password.
- Connected Meta accounts. The identifiers, names and settings of the WhatsApp numbers, Facebook Pages, Instagram accounts, Threads profiles, advertising accounts and product catalogues a business connects, together with the permissions it granted and when it granted them.
- Meta access tokens. The credential that lets us act for a business at Meta. It is encrypted before it is stored and is the only field in the system held that way.
- Customer contact records. For each person who contacts a business: the name shown on their Meta profile, their WhatsApp number, and the account identifiers Meta gives us for WhatsApp, Messenger, Instagram and for comment authors.
- Conversations and message content. Every message in both directions is stored, including the message text exactly as it was sent, along with captions, file names, shared locations and shared contact cards. Delivery status, timing and the charging category Meta applies are stored beside it.
- Attachments. When a customer sends a photo, video, voice note or document we do not store the file. We store only the reference Meta gives us and fetch the file from Meta each time somebody opens it. Media that a business uploads itself in order to publish a post is stored in our own storage.
- Raw delivery records. A verbatim copy of each notification Meta sends us is kept separately so a failed delivery can be diagnosed and replayed. It contains the same customer content described above.
- Posts, templates and broadcasts. The content a business writes, who it is aimed at, when it was scheduled and what Meta did with it.
- Advertising. A mirror of the campaigns, ad sets and adverts a business runs, their budgets and their targeting settings, plus daily performance figures such as spend, impressions, clicks and reach.
- Commerce. Product listings a business syncs to Meta: names, descriptions, prices, availability, links and images.
- Statistics. Aggregate figures for Pages, Instagram accounts and adverts. These are counts and totals, not profiles of individuals.
- Spending records. A running ledger of what a business has spent on advertising, WhatsApp messaging and AI usage, and the limits it has set. We do not hold payment card numbers, bank details or billing addresses.
- AI activity. Each assistant run, the steps it took, the proposals it put up for approval and the decision a person made. A step can contain a customer’s message, because that is what the assistant was reading.
- Audit records. An add-only record of every action taken through the platform: who did it, which capability was used, what was submitted, what came back and when. No user of the platform can edit or delete it.
- Alerts and system health. Notices about WhatsApp quality ratings, messaging tiers and spend limits, and technical measurements of how close we are to Meta’s rate limits. These contain no personal information.
- Deletion requests. When Meta tells us somebody has asked for their data to be deleted we record the account identifier Meta gives us for that person, the confirmation code we issued, and the state of the request.
We do not record IP addresses or browser fingerprints in the product database. Our hosting provider produces ordinary server logs; we deliberately keep personal identifiers, message content and deletion confirmation codes out of them.
Why we process it
- To provide the service the business signed up for: showing its inbox, sending its replies, publishing its posts, running its adverts and syncing its catalogue.
- To identify who is signing in and make sure they can only see the business they belong to.
- To let an AI assistant draft replies and prepare actions for a person to approve.
- To keep spending within the limits a business sets, and to stop an action that would exceed them.
- To keep an audit record, so a business can see what was done on its behalf and so we can investigate a complaint or a security incident.
- To diagnose faults, retry failed deliveries and keep the service reliable and secure.
- To meet our obligations under Meta’s Platform Terms and under applicable law.
We do not sell personal information and we do not use it to build advertising profiles. Message content is sent to our AI provider only to produce a draft or decide a next step for the business, as described below.
The AI assistant, and what it does not remember
Hyperbots includes an assistant that can carry out the same tasks a person can. By default it proposes an action and a person must approve it before anything is sent, published or spent. A business can switch on an automatic mode for particular low-risk actions; the spending limits and the audit record apply either way.
To do its work the assistant is given the recent messages of the conversation it is helping with and the name shown on the customer’s profile. That text is sent to our AI provider. Content that arrives from the public is always handled as data to be read and never as instructions to be followed, so a message cannot direct the assistant to act on its own.
Hyperbots also has a design for a long-term memory in which the assistant would keep distilled facts between conversations. That feature is not switched on. The component that would convert text into the form the memory needs has not been built, so nothing is written to that store and the assistant carries nothing from one run to the next. We state this because it is a feature the product describes and does not currently perform.
Who we share it with
- Meta Platforms. The other side of every action. We send messages, posts, adverts and catalogue updates to Meta and receive messages, comments and statistics back. Meta handles that information under its own terms.
- Moonshot AI. Our AI provider. Message text, conversation context and the settings the assistant needs are sent to its service in order to produce a draft or a proposed action.
- Amazon Web Services. Our hosting provider. All data is stored and processed on AWS infrastructure, which AWS does not use for its own purposes.
- Nobody else. We do not share personal information with advertisers, data brokers or any other third party. If the business is ever merged or sold, this policy continues to apply until you are told otherwise.
A second provider, Zhipu AI, is named in our design as the source of the numerical form the long-term memory would need. Because that feature is not switched on, no data is sent to it today. If that changes, this policy will be updated before it does.
Where it is stored
Hyperbots runs on Amazon Web Services in the Europe (Frankfurt) region, eu-central-1, in Germany. Meta and our AI provider run their own infrastructure in their own locations, so information shared with them under the section above may be processed outside the country you are in.
How we protect it
- Separation between businesses is enforced by the database itself and not only by the application. Every record carries the identity of the business it belongs to, and a database rule refuses to return another business’s rows even if the application asks for them wrongly.
- The identity of the business is taken from the signed identity token issued at sign-in, never from anything typed into a web address or a form.
- Meta access tokens are encrypted with a key held in AWS Key Management Service and bound to the specific business, account and token type. The stored value alone is useless.
- The database is reached through three separate roles with different powers, so ordinary application traffic cannot bypass the separation rules or alter records only an administrator may alter.
- Every notification from Meta is checked against a cryptographic signature over the exact bytes received before any of it is trusted.
- The audit record can be added to but not edited or removed.
No system is perfectly secure. If a breach affects personal information we will tell the affected businesses and, where the law requires it, the relevant authority.
How long we keep it
This is the section where we are most careful to describe what the software does rather than what a policy usually promises.
- Business accounts, connected accounts, contacts, conversations, message content, posts, adverts, spending records and audit records are kept for as long as the business account is open. No automatic deletion routine runs against these records today. They are removed when the business account is deleted, or when we act on a deletion request.
- A short-lived record used to make sure the same notification from Meta is not processed twice is kept for 48 hours and then removed automatically.
- Raw delivery records carry a marker saying they should be removed after 30 days. The routine that would act on that marker has not been built, so today those records stay until the account is deleted. We say this rather than claim a 30-day period we do not yet enforce.
- Attachments a customer sends are not stored by us at all. Meta keeps the file for its own period, which its documentation gives as seven days for a file received through a notification.
- A proposal waiting for approval stops being actionable after 72 hours.
- A record that a deletion request was made, and that it was honoured, is kept as the evidence that we did what was asked.
We intend to introduce automatic deletion periods for the records above, and this policy will be updated with the exact periods once they are running. Until then, a request under the next section is the way to have data removed sooner.
How to ask us to delete your data
Anyone can ask us to delete their information, whether or not they have an account with us. There are two routes.
- Through Meta. If you used Facebook or Instagram to reach a business that uses Hyperbots, you can remove this app in your Meta account settings and choose to delete your data. Meta then sends us a signed deletion request automatically. We check the signature, record the request, and return to Meta a confirmation code and a web address where you can check the state of that request at any time.
- By writing to us. Send an email to team@thetwoapps.com with enough detail for us to find your records — for example the business you contacted and the phone number or account name you used. We will confirm receipt, tell you what we hold, and tell you what we have removed.
Deletion is carried out by our team by hand rather than by an automatic routine. We say this plainly because a confirmation code is a promise, and you should know how that promise is kept.
Two things are deliberately not deleted: the audit record that an action happened, and the record that you asked for deletion. Both are the evidence that the platform did what it was asked, and each holds the minimum needed for that purpose.
Your rights
Depending on where you live you may have the right to ask for a copy of the information we hold about you, to have it corrected, to have it deleted, to object to how it is used, to restrict its use, or to have it moved to another provider. Write to team@thetwoapps.com and we will respond.
Where a business uses Hyperbots to handle your information we will pass your request to that business and help it answer. You also have the right to complain to your local data protection authority.
Children
Hyperbots is a tool for businesses and is not intended for children. We do not knowingly collect information from a child. Messages sent to a business by a member of the public are stored as the business receives them; if you believe we hold information about a child and it should be removed, write to team@thetwoapps.com and we will remove it.
Changes to this policy
If we change this policy we will change the date shown at the top of this page. Where a change materially affects how we handle personal information we will tell the businesses that use Hyperbots before it takes effect.
Contact us
Write to team@thetwoapps.com. Our postal address is [REGISTERED POSTAL ADDRESS — TO BE COMPLETED]. Where one is required, the details of our data protection officer or of our representative in the European Union or the United Kingdom are [DATA PROTECTION CONTACT — TO BE COMPLETED IF REQUIRED].