GyroGyro
← Back to Gyro

Privacy Policy

Last updated: August 16, 2026

Gyro ("Gyro," "we," "us") is operated by Ali Asif, a sole proprietorship registered in Islamabad, Pakistan. Gyro provides an AI-assisted WhatsApp messaging service and a web dashboard that help local businesses answer customer questions and manage appointment bookings. This policy explains what information we handle when a business uses Gyro and when that business's customers message it on WhatsApp, who that information is shared with, how long it is kept, and the choices available to you.

Who this policy is for, and who decides what

Two different groups interact with Gyro, and the distinction matters for your rights.

  • Businesses that use Gyro to handle their bookings. A business decides what information it collects from its own customers and why. For that information, Gyro acts on the business's instructions — we process it to run the service for them, and for no independent purpose of our own.
  • Customers of those businesses, who message a Gyro-connected WhatsApp number. Your relationship is with the business you are messaging. We hold your information on their behalf, which is why some requests about your data are best directed to them — see "Your choices and rights" below.

For dashboard accounts — the business owner and their staff — we act on our own behalf, since that account exists to give you access to Gyro itself.

Information we handle

  • WhatsApp messages. When a customer messages a business's Gyro-connected number, we receive and store the message content, the sender's WhatsApp phone number, and message metadata (timestamps, message type) via Meta's WhatsApp Business Platform. Conversation history is retained so the assistant can follow a conversation across several messages, and so the business can read what was said.
  • Appointment records. Bookings created through WhatsApp or the dashboard: customer name, phone number, service, date and time, any notes a staff member adds, and — where an appointment is cancelled or moved — the reason given and a record of whether the change was made by the customer via the assistant or by a member of staff.
  • Handover records. When the assistant cannot answer something, it flags the conversation for the business's staff along with the customer's number, their name if given, and a short summary of what they asked. This is how a question the AI cannot handle reaches a person.
  • Business configuration. Information a business gives us about its operations — name, address, contact numbers, opening hours and breaks, services, pricing, policies, time zone, and an optional logo — so the assistant can answer accurately.
  • Dashboard account data. For owners and staff with dashboard access: name, email address, phone number, and a cryptographic hash of your password. We do not store your password itself and cannot recover it. We also record when your email was verified and when you last signed in.
  • Operational logs and diagnostics. Server logs and technical traces recording how a message was handled — which steps ran, how long they took, and what failed. See "Service providers" for what these contain and where they are stored.

How we use information

  • To respond to customer messages and answer questions about a business's services, hours, pricing, and policies.
  • To create, reschedule, and cancel appointments on behalf of a business, and to check which times are free.
  • To flag conversations the assistant cannot handle so a member of staff can follow up.
  • To display appointments, conversation history, and flagged conversations to business owners and staff on the dashboard.
  • To send transactional email to dashboard users — email verification and team invitations. We do not send marketing email.
  • To monitor reliability, diagnose faults, and improve the accuracy of the assistant.
  • To meet legal, security, and fraud-prevention obligations.

We do not sell personal information. We do not use customer WhatsApp messages for advertising. We do not use customer messages, appointment records, or business data to train artificial-intelligence models, and our agreements with the AI provider named below are on terms that prohibit them from doing so.

Sensitive and health-related information

Many businesses using Gyro are clinics and healthcare practices. Customers messaging them sometimes describe symptoms, pain, treatments, or reasons for a visit in the body of a message. Gyro does not ask for this information and does not require it in order to make a booking, but where a customer chooses to send it, it is stored with the rest of the conversation and is visible to that business's staff on the dashboard.

Because free-text messages cannot be filtered reliably, information of this kind may also be included in the diagnostic traces described below. We treat it as confidential and it is never used for any purpose other than operating the service.

Please do not send national identity card numbers, payment card details, bank information, or medical records through WhatsApp. Gyro never needs them, and WhatsApp is not the right channel for them.

Service providers

To operate Gyro, information passes through the following providers, each acting under its own privacy and security terms:

  • Meta Platforms, Inc. (WhatsApp Business Platform) — delivers and receives WhatsApp messages on our behalf. Messages sent over WhatsApp are also subject to WhatsApp's own terms and privacy policy.
  • Google LLC (Gemini API) — generates the assistant's replies. The content of a customer's message and the business's configuration are sent to Google for the purpose of producing a reply. We use Google's paid service tier, under which Google does not use this content to train or improve its models.
  • MongoDB, Inc. (MongoDB Atlas) — stores business configuration, conversation history, appointment records, and dashboard accounts.
  • Vercel Inc. (hosting and file storage) — runs the application backend and dashboard, and stores logos uploaded by a business.
  • Langfuse GmbH (application monitoring) — receives diagnostic traces of how each message was handled, on servers in the United States, retained for up to 30 days. Traces include the text of the customer's message and the assistant's reply. Phone numbers, email addresses, and national identity card numbers are automatically removed before transmission, as are customer names where they appear in structured booking data. Personal details typed into the body of a message — including names and descriptions of symptoms or reasons for visiting — are not detected by this removal and may be included. Appointment records and stored contact details are not sent to this provider.
  • Resend, Inc. (email delivery) — sends verification and team-invitation emails, and receives the recipient's name and email address for that purpose.

Where your information is held

Gyro is operated from Pakistan, but every provider listed above operates infrastructure outside Pakistan — principally in the United States and the European Union. Using Gyro therefore involves the transfer of information across international borders. We choose providers that offer contractual privacy and security commitments, and we do not transfer information to anyone other than the providers named above except as described in the next section.

Who can access your information

  • The business you are messaging. Its owner and the staff members they have invited can see conversations, appointments, and flagged questions. Owners control which staff can view or change what.
  • The Gyro operator. Ali Asif can access stored data through an administrative interface, in order to provide support, investigate faults, and act on abuse. This access is used for those purposes only.
  • The providers listed above, to the extent described for each.
  • Legal authorities, where we are required by applicable law to disclose information.

Each business's data is isolated from every other business's. Staff at one business can never see another's conversations or appointments. The assistant, when checking free times, can see only that a period is unavailable — never who booked it, or why.

Data retention

  • Conversation history and appointment records are retained for as long as the business maintains an active account with Gyro.
  • When an account is closed or a business asks us to delete its data, the records are first marked for deletion and taken offline — the assistant stops answering and the dashboard stops serving them — and are then permanently erased after approximately 30 days. The grace period exists so that an accidental deletion can be reversed; once it passes, erasure is final.
  • Diagnostic traces are deleted automatically after 30 days.
  • Dashboard account details are retained while the account exists. Where a staff member's access is withdrawn, their name may remain attached to appointments they created or changed, so that the business's own records stay accurate.

Your choices and rights

  • Customers can stop receiving messages from a business's Gyro number at any time by blocking the number on WhatsApp.
  • Customers can ask for access to, correction of, or deletion of their information. Because we hold that information on behalf of the business you were messaging, contacting that business directly is usually fastest — but you can also write to us at aliasif1171@gmail.com and we will act on their instructions.
  • Businesses can request export or deletion of their data by emailing aliasif1171@gmail.com.
  • Staff members can ask their organisation's owner to remove their access, or contact us at the address above.

We will respond to requests within a reasonable period, and will ask you to verify your identity before acting on a request about personal information.

Data security

Measures we apply include:

  • Encrypted connections (HTTPS) between all services.
  • Cryptographic signature verification on our WhatsApp webhook, so that messages that did not come from Meta are rejected.
  • Passwords stored only as salted scrypt hashes, held in a field that application code has to request explicitly rather than one it receives by default.
  • Team invitation links stored only as hashes, so a copy of the database does not let anyone join an organisation they were not invited to.
  • Identifiers in diagnostic traces derived using a keyed hash, so a customer's messages can be grouped together without their phone number leaving our systems.
  • Strict separation of each business's records, enforced on every query rather than by convention.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

Children's information

Gyro is intended for use by businesses and by adults contacting them. It is not directed at children and children should not use it directly.

We recognise that a parent or guardian may book an appointment for a child, and in doing so may give us the child's name and other details. We handle that information the same way as any other appointment information, on behalf of the business concerned. A parent or guardian can ask for it to be corrected or removed using the contact details below.

Governing law

This policy, and any dispute arising from it, is governed by the laws of the Islamic Republic of Pakistan, and the courts of Islamabad, Pakistan have jurisdiction.

Changes to this policy

We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date above, and where a change materially affects businesses using Gyro, we will notify them directly.

Contact us

Questions about this policy or your data can be sent to aliasif1171@gmail.com, or by post to Ali Asif, Islamabad, Pakistan.