Last updated: July 11, 2026

Privacy Policy

Privacy summary

AutoChat v1.1.0 is a Windows desktop application that primarily stores business and customer-support data on the business user's own device. Information is sent outside the device only when a connected feature requires it, such as WhatsApp, a user-configured AI or cloud voice provider, licensing, updates, Microsoft Store services, or user-requested support. Indus Automation Labs does not sell personal information.

This summary highlights the main points. The complete policy below explains the data, purposes, providers, controls, retention, and responsibilities in more detail.

Introduction

This Privacy Policy explains how Indus Automation Labs ("Indus Automation Labs," "we," "us," or "our") handles information in connection with the AutoChat v1.1.0 desktop application, the Indus Automation Labs website, licensing and purchase requests, customer support, and related services. It applies to website visitors, AutoChat business users, customers and license users, and people who contact us for support or other business purposes.

Indus Automation Labs is an independent software brand operated by Muhammad Hamza Shoaib. References to "Indus Automation Labs," "we," "us," or "our" in this policy refer to Muhammad Hamza Shoaib operating under the Indus Automation Labs brand.

AutoChat is intended for small and medium-sized businesses across different industries and store types. In this policy, a "business user" means the organization or person who installs, configures, or operates AutoChat, while a "customer" may mean an individual whose conversation or order information is processed by that business user.

Effective date and last updated: July 11, 2026.

Information processed by the website

The website is a public informational website. The website's hosting and network providers may automatically process ordinary server and security logs, which can include an IP address, browser type, device or operating system information, requested page, referring page, request date and time, and error or security information. Whether and how such logs are created depends on the hosting provider and the request.

The current website does not provide a functioning customer account login or public checkout. Its visible inquiry form is a local interface preview and does not transmit or store the entered form data on our server. If you contact us by email, we may process the name, email address, business name, message, attachments, and communication history you choose to provide so we can respond and provide support.

We do not currently add website analytics or advertising trackers in the application code. If the website later adds a working account, checkout, contact submission, analytics, or similar feature, this policy will be updated before or when that change applies.

Information processed by AutoChat

Depending on how a business user configures and uses AutoChat, the application may process:

  • authorized WhatsApp customer conversations, including contact identifiers, customer names, phone numbers, incoming and outgoing message text, timestamps, drafts, reply status, and recent conversation history;
  • customer profile and memory information, such as names, phone numbers, delivery addresses, cities or towns, preferences, notes, payment-method labels, and previous order summaries;
  • carts and order information, including products, quantities, variants, prices, stock context, delivery or pickup details, address, city, province, phone number, email address, payment-method choice, order status, and related customer notes;
  • business data such as business profile settings, catalog and product information, FAQs, policies, business knowledge, supplier records and cases, workflow rules, payment instructions, and application configuration;
  • training items, owner decisions, customer-specific memory, contact-control settings, pending AI drafts, and operational events used to provide the configured workflow;
  • application settings, enabled features, model and voice settings, license status, a pseudonymous device identifier, application version, update state, security events, diagnostic/error information, and support information; and
  • voice-note audio, reply text, generated audio files, and transcripts when the corresponding voice feature is enabled and used.

AutoChat does not require every category above for every user. The information processed depends on the features the business enables, the data it enters, and the content customers send to its authorized WhatsApp account.

Local storage and user controls

AutoChat primarily stores operational data locally on the Windows device running the application. In a packaged installation, the application data is normally held under the Windows application-data location for AutoChat, commonly %APPDATA%\autochat. Local files can include business settings, products, messages, pending drafts, customer memory, carts, orders, training data, business knowledge, suppliers and supplier cases, license information, API settings, support and security events, update state, WhatsApp Web session information, and generated voice files.

AutoChat provides controls to delete certain individual records, including products, customer memories, business knowledge, suppliers, and supplier cases; clear a customer cart; reset setup status; and clear saved AI or voice provider credentials. It also provides a business-data backup export and restore feature. The backup excludes license, API-secret, and security-state files by default, but it can contain other business and customer data. Product catalog data can also be exported in supported formats.

AutoChat v1.1.0 does not provide one in-app control that erases every local file. Uninstalling AutoChat may not automatically delete every file in the Windows application-data folder, exported backup, product export, generated audio folder, or other user-selected location. Users should review and securely remove those files separately when they are no longer needed. Data stored only on the user's device is generally not available to Indus Automation Labs for remote deletion.

AI and voice processing

When a business user configures and uses AI features, AutoChat may send relevant content to OpenRouter and to the model provider made available through the user-selected OpenRouter model. The transmitted context can include a customer message, recent conversation history, business profile or policies, matching catalog data, business knowledge, customer memory, cart or order context, and instructions needed to generate, classify, or structure a response. AutoChat sends this information only as part of the configured AI workflow.

Optional cloud voice features use ElevenLabs when enabled. Voice-note transcription may send the selected audio file and transcription instructions to ElevenLabs. Cloud text-to-speech may send reply text and voice/model settings to ElevenLabs and store the returned audio locally. AutoChat's Local Basic voice-generation mode uses local model files for supported text-to-speech and does not require sending that reply text to an online voice provider. Local voice-note transcription is not currently implemented in AutoChat v1.1.0.

OpenRouter, the model provider selected through it, and ElevenLabs process information under their own terms, account settings, and privacy policies. Their retention, training, security, and international-transfer practices are not controlled by Indus Automation Labs. Business users should review the OpenRouter Privacy Policy and ElevenLabs Privacy Policy, as well as the terms for the specific model they select.

WhatsApp integration

AutoChat connects through a WhatsApp Web session that the business user authorizes, normally by scanning a QR code from the linked-device controls of its own WhatsApp account. Session information is stored locally so the authorized connection can continue. Messages and media also pass through WhatsApp's systems and are subject to the account holder's agreement with WhatsApp and the applicable WhatsApp Privacy Policy.

The business user is responsible for account authorization and for the lawfulness of its customer communications, notices, permissions, consent, retention, and use of customer data. AutoChat and Indus Automation Labs are not affiliated with, endorsed by, sponsored by, or officially connected to WhatsApp or Meta.

API keys and credentials

User-provided OpenRouter and ElevenLabs credentials are stored locally. AutoChat is designed to use Electron's protected safeStorage mechanism when encryption is available on the Windows device. The interface displays masked credential status and provides controls to clear saved provider credentials. WhatsApp session information is also stored locally as part of the authorized session.

Protection depends on the Windows environment, device configuration, account security, and availability of the platform storage mechanism. No storage method is completely secure. Users are responsible for securing their Windows account, device, WhatsApp account, AI and voice provider accounts, license key, and API credentials; for limiting access to authorized personnel; and for revoking or rotating credentials when compromise is suspected.

Licensing, purchase requests, and Microsoft Store

AutoChat may process a license key, license status, plan, activation and verification dates, application version, and a pseudonymous device identifier derived locally from device and Windows-account attributes. These details may be sent to the AutoChat license service to activate, verify, restore, secure, or manage access and to prevent misuse or fraud.

If a user submits an AutoChat license purchase request through the application, the request can include the customer or business name, phone number or email address, voucher code, selected payment method, payment-proof image, device identifier, application version, purchase identifier, status, and related approval information. These details are used to quote, review, approve, activate, and support the requested license. The current website does not process this purchase request.

When AutoChat is acquired, updated, entitled, or paid for through Microsoft Store, Microsoft may process Microsoft account, device, acquisition, installation, entitlement, transaction, payment, update, and Store-usage information under the Microsoft Privacy Statement. AutoChat may use entitlement or transaction status needed to provide access where such Store functionality is enabled. Microsoft controls its Store processing, and Indus Automation Labs does not receive full payment-card details from Microsoft. Store-packaged AutoChat builds use Microsoft Store as their update channel; non-Store builds may check the AutoChat update service using the installed version and ordinary network request information.

Purposes of processing

We process information as reasonably necessary to:

  • operate, deliver, and maintain the AutoChat application and website;
  • provide customer messaging, conversation management, AI drafts, product search, carts, orders, customer memory, training, supplier, voice, backup, configuration, and support functionality;
  • activate, verify, restore, and manage licenses, entitlements, purchase requests, and updates;
  • respond to support, privacy, billing, legal, security, and business requests;
  • diagnose errors, maintain reliability, secure systems, and improve features and user experience; and
  • detect, investigate, prevent, and respond to misuse, fraud, tampering, security incidents, or legal obligations.

Data sharing

Indus Automation Labs does not sell personal information.

Information may be disclosed only as relevant to the feature or purpose involved, including to:

  • WhatsApp/Meta for the user-authorized messaging session, and OpenRouter, model providers available through it, or ElevenLabs when the corresponding external feature is configured and used;
  • Microsoft for Microsoft Store distribution, updates, purchases, or entitlements where applicable;
  • infrastructure, website-hosting, license, update, email, and support-service providers that help us operate the relevant service;
  • professional advisers, auditors, transaction counterparties, or service providers where reasonably necessary and subject to appropriate obligations; and
  • courts, regulators, law-enforcement bodies, or other authorities when required by law or reasonably necessary to protect rights, safety, systems, users, or the public.

Bug reports and diagnostic details are sent to our support service only when the user submits the relevant report or starts the relevant support workflow. Limited license, security, and tamper-event information may also be sent to protect licensed access and prevent misuse. Support payloads are designed to redact API keys, tokens, passwords, and similar secrets, but users should still review information before submitting it.

Retention and deletion

Local AutoChat data remains on the user's device until the user deletes an applicable record, clears or resets an applicable setting, removes files, deletes the application-data folder, or otherwise removes the data. Uninstalling AutoChat may not remove every locally stored file. Exported backups and files saved outside the AutoChat data folder remain until separately deleted by the user.

Website-hosting logs, support communications, license and purchase records, security information, and related service records are retained only for as long as reasonably necessary for operations, support, licensing, security, billing, fraud prevention, legal compliance, dispute resolution, and enforcement. We do not promise a fixed retention period where one has not been implemented or where legal and operational needs differ.

External providers determine retention for information they process under their own terms and policies. A request to us does not automatically delete information held independently by WhatsApp, Microsoft, OpenRouter, a selected model provider, ElevenLabs, an email provider, or another third party. Users may need to make a separate request to that provider.

Security

We use reasonable technical and organizational measures appropriate to the nature of the service and information. Depending on the feature, these measures include local application-data storage, Windows account and device protections, protected local storage for provider credentials where available, credential masking, secret redaction in support payloads, license-integrity and abuse controls, restricted application interfaces, update verification controls, and limiting processing to operational purposes.

No device, application, transmission, provider, or storage system is completely secure. We do not guarantee absolute security. Business users should maintain Windows and AutoChat updates, use appropriate device encryption and access controls, protect backups, restrict operator access, and promptly revoke exposed credentials.

International processing

Indus Automation Labs and external providers may process information in countries other than the country where the business user or customer is located. This can occur when using website hosting, email, WhatsApp, OpenRouter and its model providers, ElevenLabs, Microsoft Store, licensing, updates, payment-related services, or support infrastructure. Those countries may have different privacy laws. Where required, the responsible party should use applicable legal safeguards for international transfers.

Children

AutoChat is intended for businesses and adult business operators. It is not directed to children, and Indus Automation Labs does not knowingly solicit children's personal information through AutoChat or the website. Business users must avoid intentionally using AutoChat to process children's information unless they have a lawful basis, provide required notices, obtain any required parental or guardian consent, and comply with all applicable child-privacy laws.

User and business responsibilities

The business user controls which WhatsApp account, customer data, catalog, business knowledge, provider accounts, and workflows are connected to AutoChat. Depending on applicable law, the business user may be the controller or primary responsible party for the customer and employee information it imports or processes.

Business users are responsible for:

  • having authority to use the connected accounts and process the imported or received information;
  • providing legally required privacy notices and obtaining required permissions or consent;
  • configuring access, operating modes, retention, providers, and customer communications lawfully;
  • avoiding unnecessary sensitive information in customer messages, AI prompts, support reports, voice requests, catalogs, memory, and order notes;
  • not requesting or storing full payment-card numbers, security codes, passwords, government identifiers, health information, or other highly sensitive data unless strictly necessary, lawful, and appropriately protected; and
  • responding to customer privacy requests relating to data held on the business user's own device or accounts.

Privacy rights

Depending on applicable law and the circumstances, an individual may have rights to request access, correction, deletion, restriction, portability, or objection; to withdraw consent; or to complain to a privacy regulator. These rights can be subject to identity verification, legal exceptions, and the roles of the relevant business user and third-party provider.

For data stored only on a business user's computer, WhatsApp account, provider account, or exported backup, the request normally must be handled directly by that business user or through the relevant device, application, or provider controls. Indus Automation Labs cannot access or delete local-only AutoChat data remotely. For information we control, send a request to support@indusautomationlabs.com. We may ask for reasonable information to verify the request and locate the relevant records.

Changes to this policy

We may revise this Privacy Policy when AutoChat, the website, providers, distribution, legal requirements, or data practices change. The revised policy will be posted at this same /privacy route with an updated effective or last-updated date. Material changes may also be communicated through the application, website, Store listing, email, or another appropriate channel where required.

Contact

For privacy questions, requests, or concerns, contact Indus Automation Labs at support@indusautomationlabs.com.

Website: https://www.indusautomationlabs.com/