Misho Privacy Policy

Last updated: 20 July 2026

Misho (“Misho”, “we”, “us”) is a product of Seabraes LLC. Misho provides businesses (“Customers”) with an AI-assisted operations service that receives, triages, and manages fault reports and related requests over messaging channels such as WhatsApp, SMS, and email. This policy explains what personal data we process, why, and the choices available to you.

Who is responsible for your data

Each Misho workspace is operated by a Customer — the business you contact (for example, your facility management provider). For messages you send to a Customer’s intake line, the Customer decides the purposes of processing and Misho processes that data on the Customer’s behalf as a service provider. For account data of workspace users (names, emails, sign-in credentials) and for operating the platform itself, Seabraes LLC is the responsible party.

Data we process

WhatsApp and Meta data

Misho connects Customers to the WhatsApp Business Platform as a Meta technology provider: the WhatsApp Business account belongs to the Customer, and Misho operates it on the Customer’s behalf. When you message a Customer’s WhatsApp line, we receive the message content, your phone number, and basic profile information from Meta via the WhatsApp Business Platform, and we send replies through the same platform. We use this data solely to provide the service to that Customer — receiving fault reports, triaging them, coordinating work, and responding — and in accordance with applicable Meta platform terms, including the WhatsApp Business Terms of Service. Your use of WhatsApp itself is governed by WhatsApp’s own terms and privacy policy. We do not sell WhatsApp user data, use it for advertising, or use it to train general-purpose AI models.

AI processing

Misho uses large language models to read incoming messages, draft replies, and manage requests. Message content necessary for this is processed by our AI infrastructure provider under terms that prohibit using it to train their models. Actions with real-world consequences follow a propose-and-approve flow with the Customer’s staff.

Tenant isolation and security

Every Customer workspace is isolated: workspace data is segregated with database-level row security enforced on every table, channel credentials are stored encrypted, all traffic is encrypted in transit, and access within a workspace is role-based. Our staff access production data only when required to operate or support the service.

Sub-processors

We use a small set of infrastructure providers to run Misho: Hetzner Online GmbH (hosting, Germany), Cloudflare (DNS and email routing), Resend (transactional email), Meta Platforms (WhatsApp Business Platform), Twilio (SMS, where enabled), and Anthropic (AI processing). Each processes data only as needed to provide their function to us.

Retention

Workspace data is retained for as long as the Customer’s account is active. When a workspace is closed, its data is deleted within 90 days; encrypted backups age out within a further 30 days. Customers may request earlier deletion of specific records. Server logs are retained for up to 90 days.

Your rights

Depending on where you live — including under the Nigeria Data Protection Act 2023 and similar laws — you may have rights to access, correct, or delete personal data about you. For messages you sent to a Customer’s intake line, contact that Customer first; we support Customers in fulfilling these requests. For anything else, or if you cannot reach the Customer, contact us and we will help.

Children

Misho is a business tool and is not directed at children.

Changes

We will post any changes to this policy on this page and update the date above. Material changes are additionally notified to Customers by email.

Contact

Seabraes LLC — privacy@gomisho.com

← gomisho.com · Terms of Service