top of page

Privacy

Privacy Policy

 

App: AutoResponder for WhatsApp ("the App")

Website: https://www.autoresponder.ai and its subpages ("the Website")

Provider / Data Controller: Tim Kosmala (Germany)

Email: info@autoresponder.ai

Full postal address: see Section 2 and our legal notice (Impressum) at https://www.autoresponder.ai/legal

 

Last updated: 23 June 2026

 

This Privacy Policy explains what data the App and the Website access, how it is used, stored, shared, retained and deleted. It applies to users of the App and Website. Because the provider is established in Germany, this policy is primarily based on the EU General Data Protection Regulation (GDPR) and German privacy/ePrivacy rules (including the TDDDG). Additional region-specific rights may apply where required by local law. This policy also contains the disclosures required by the Google API Services User Data Policy (including the Limited Use requirements) and the Google APIs Terms of Service.

 

In this policy, "the Service" means the App and the Website together.


 

1. Summary (Plain Language)

 

• The App's core purpose is to send automatic replies to incoming messages of third-party messengers (e.g. WhatsApp) directly on your device.

• In the default configuration, message content is processed locally on your device and is not sent to our servers. We do not operate a server that receives or stores your message content.

• Some optional features (AI-generated replies, Google Sheets answers, webhooks, Dialogflow) send data to third-party services that you choose and configure yourself. These features are off until you enable them.

• We use Google Firebase and Google AdMob for app functionality, diagnostics and advertising.

• If you connect a Google account for the Google Sheets feature, the App requests only a narrow, per-file scope (Google's drive.file) limited to the spreadsheet you select through Google's file picker — it cannot access your other files. We do not collect or share Google Sheets content with our servers or third parties; the App communicates directly with Google's Sheets API to provide the feature.

• The Website is hosted on Wix, which sets necessary cookies and processes server log data; optional cookies (e.g. analytics) are used only with your consent where required.


 

2. Who We Are (Data Controller)

 

The data controller responsible for any processing of personal data described in this policy is:

 

Tim Kosmala

Weimarer Str. 2

96484 Meeder

Germany

Email: info@autoresponder.ai

 

If you have any questions about this policy or wish to exercise your rights, please contact us at the email address above (English or German).


 

3. How the App Works (Processing Location)

 

The App relies on Android's Notification Access (Notification Listener Service) to read incoming notifications from supported messenger apps so that it can detect incoming messages and trigger the automatic replies you have configured in your rules.

 

• This detection and the generation of replies happen locally on your device.

• Your rules, replies, answer replacements, reply history and statistics are stored only in the App's local storage on your device (local database and app settings).

• Message content is transmitted off your device only if you explicitly enable an optional feature that requires it (see Section 6).


 

4. Data We Access and Process (App)

 

4.1 Data processed locally on your device

 

• Notification / message content from supported messengers (sender name, message text, group name) — used solely to match your rules and generate replies.

• Your configuration — rules, reply texts, answer replacements, schedules.

• Reply history and statistics — stored locally so you can review activity.

• Contacts (optional): If you use the contact picker to choose specific recipients for a rule, the App reads your device contacts (READ_CONTACTS permission) on the device only to let you select a name or number. Contact data is not uploaded to us.

 

4.2 Data processed by third-party services we integrate (see Section 8)

 

• Google Firebase (Analytics, Cloud Messaging, Remote Config, In-App Messaging): app usage and diagnostic data, an app-instance identifier, device and OS information, approximate region, and a push token used to deliver notifications and important service messages.

• Google AdMob (advertising): advertising identifier, IP address, and ad interaction data used to show and measure ads (including, where permitted, personalised ads).

• Google Play Billing / License verification: to validate purchases of the Pro version, your purchase token, product ID and the App's package name are sent to our own server (our backend operated by us as the provider). This does not identify you personally to us beyond the purchase itself.

 

4.3 Data sent to services only when you enable optional features

 

See Section 6. This may include the content of incoming messages and your reply configuration, sent to the third party you have chosen.


 

5. Google User Data (Google API Services User Data Policy)

 

This section specifically addresses data obtained through Google APIs and Google Sign-In, as required by the Google API Services User Data Policy and the Google APIs Terms of Service.

 

5.1 What Google user data we access

 

The App offers an optional Google Sheets feature that lets you use a Google spreadsheet as a source of automatic answers and lets the App write data back to a spreadsheet you select (for example, to log incoming messages or sent replies). If — and only if — you choose to connect a Google account for this feature and select a spreadsheet through Google's file picker, the App requests the following via Google Sign-In / OAuth:

 

• email (basic profile email) — grants your Google account email address. We request it to display which account is connected and let you manage the connection.

https://www.googleapis.com/auth/drive.file — grants per-file access limited to the specific Google Sheets files you open or select through Google's file picker (and any files the App itself creates). It does not grant access to your other Drive files or spreadsheets. We request it to read the cells of, and write entries (such as message/reply logs) to, only the spreadsheet you select for this feature.

The https://www.googleapis.com/auth/drive.file scope is a narrow, per-file scope. It grants the App access only to the specific spreadsheet you choose through Google's file picker (or a file the App creates on your behalf) — not to any of your other files or spreadsheets. The App has no ability to search, list, or open any Drive file you have not explicitly selected, and it does not access your other Google data (such as Gmail or contacts).

 

5.2 How we use Google user data

 

• The email address is stored locally on your device only, to show you which account is connected. It is not transmitted to us.

• The Google Sheets data is read directly between your device and Google's servers (https://sheets.googleapis.com) using the OAuth access token, solely to retrieve the answer values and sheet/tab names needed to generate your automatic replies. The spreadsheet contents are used on your device to produce replies and are not collected by us.

• The App also writes only the data you have configured (for example, incoming message text, the reply sent, sender name, and a timestamp) directly from your device to the spreadsheet you selected. This data is sent only to your own Google spreadsheet and is not collected by us.

 

5.3 How we share Google user data

 

We do not share, sell, rent, or transfer your Google user data (your email or your Google Sheets data) to any third party. It is not sent to our servers and is not used for advertising. The only transfer that occurs is the direct, encrypted request between your device and Google's own Sheets API.

 

5.4 Limited Use disclosure

 

The App's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

 

• We use Google user data only to provide and improve the user-facing features described above (the Google Sheets answer feature).

• We do not transfer or sell this data for advertising, marketing, or any other unrelated purpose.

• We do not use this data for serving ads.

• We do not allow humans to read this data. Because the data is processed only on your device and is never transmitted to our servers, we have no access to it and no one on our side can read it. The only way we could ever see your Google Sheets content is if you choose to send it to us yourself — for example, by including it in a support email or screenshot — and in that case we would use it solely to handle your request, or where access is required for security purposes or by applicable law.

 

5.5 Storage, protection and revocation of Google user data

 

• The Google access token is held only on your device and is managed by Google Play Services; it is transmitted only to Google over encrypted HTTPS connections.

• You can disconnect / revoke the App's access at any time inside the App (sign out of the Sheets feature) or via your Google Account settings at https://myaccount.google.com/permissions. Revoking access deletes the locally stored email and stops all Sheets access.


 

6. Optional Third-Party Features You Can Enable

 

The following features are disabled by default. They send data off your device only after you enable and configure them. When you do, the content of your incoming messages and/or your configured prompts may be transmitted to the respective third party, which processes the data under its own privacy policy and terms — not ours. Please review the provider's policy before enabling a feature.

 

• AI replies – OpenAI (ChatGPT, GPT Assistants, content moderation). Data sent: incoming message text and your prompt/instructions. Third party: OpenAI (api.openai.com). Provider policy: https://openai.com/policies/privacy-policy

• AI replies – Google Gemini (google-genai). Data sent: incoming message text and your prompt/instructions. Third party: Google. Provider policy: https://policies.google.com/privacy

• Dialogflow (legacy chatbot integration). Data sent: incoming message text and a session identifier. Third party: Google / Dialogflow. Provider policy: https://policies.google.com/privacy

• Webhook. Data sent: a fixed payload — app and messenger package name, sender name, message text, group flag and group participant, rule ID, and a test-message flag. Third party: the server URL you specify (with optional headers you set). Provider policy: determined by you / the server operator.

• Google Sheets. Data sent: the spreadsheet ID and cell range you specify (to read answers); and, for write-back, the entries you configure (e.g. message text, reply, sender, timestamp). Third party: Google. Provider policy: see Section 5.

 

For the AI features you typically provide your own API key. We do not receive, store, or have access to your API keys or the data you exchange with these providers.

 

6.1 Your responsibility for other people's personal data

 

The App processes incoming messages from other people, which may contain their personal data — such as their name, phone number, group name, and the content of their messages, which can include sensitive information. You decide which rules to create and whether to enable optional integrations, and you therefore control how this data is used.

 

• Local processing: When messages are matched and answered locally on your device, you act as the party responsible (the controller) for that processing. We do not receive this data.

• Optional transmission to third parties: When you enable a feature that sends message content off your device — to an AI provider (OpenAI, Google Gemini), Dialogflow, a Google Sheets lookup or write-back, or a webhook — you direct that transmission and choose the recipient.

 

You are responsible for ensuring that your use of the App is lawful, including where incoming messages contain the personal data of other people. In particular, before enabling features that transmit message content to AI providers, Dialogflow, Google Sheets, or a webhook, you should ensure that you have an appropriate legal basis or the necessary permission where required, and that you inform the senders where the law obliges you to do so.

 

Special-category (sensitive) data: Message text can contain special categories of personal data within the meaning of Article 9 GDPR — for example information revealing health, political opinions, religious or philosophical beliefs, sexual orientation, ethnic origin, or trade-union membership. You should not enable AI replies, webhook forwarding, message logging, or similar features for conversations that may contain such data unless you have a valid legal basis under Article 9 GDPR (for example, the explicit consent of the person concerned) and any other permission required by applicable law.


 

7. The Website (autoresponder.ai)

 

Our Website is hosted and operated through Wix.com Ltd. ("Wix") as our hosting provider and data processor. When you visit the Website, the following data may be processed:

 

7.1 Server log data

 

Like virtually all websites, the Website (via Wix) automatically processes technical information your browser sends, including your IP address, browser type and version, operating system, the page you visited, the referring page, and the date and time of access. This data is used to deliver the Website securely and reliably, to maintain stability, and to detect and prevent abuse. The legal basis is our legitimate interest in operating a secure website (Art. 6(1)(f) GDPR).

 

7.2 Cookies and similar technologies

 

The Website uses cookies and similar technologies:

 

• Strictly necessary cookies set by Wix to operate the Website, keep it secure, and remember basic preferences. These are required for the Website to function (legal basis: Art. 6(1)(f) GDPR / § 25(2) TDDDG).

• Optional cookies (e.g. analytics or marketing) are used only with your consent where consent is required. Where a cookie/consent banner is shown, you can accept, reject, or change your choices at any time.

 

You can also control or delete cookies through your browser settings. Disabling necessary cookies may impair Website functionality.

 

7.3 Contact

 

The Website does not provide a contact form. If you contact us by email (e.g. at info@autoresponder.ai), we process the data you provide (such as your email address and the content of your message) solely to handle your request. The legal basis is the performance of a contract or pre-contractual steps (Art. 6(1)(b) GDPR) and/or our legitimate interest in responding to enquiries (Art. 6(1)(f) GDPR).

 

7.4 Wix's role

 

Wix processes certain Website data on our behalf as a service provider/processor (for hosting and operating the Website) and may also process limited data as an independent controller for its own purposes where described in Wix's own privacy documentation. Wix may store data on its infrastructure, which can include servers outside the EU/EEA (e.g. in the United States). Such transfers are covered by appropriate safeguards (e.g. EU Standard Contractual Clauses). For details on how Wix processes data and in which role, see the Wix Privacy Policy: https://www.wix.com/about/privacy

 

Note: The Website may also embed or link to third-party content (for example videos, app-store badges, or social media). When you interact with embedded third-party content, that provider may receive data under its own privacy policy.


 

8. Third-Party Services and SDKs

 

The Service includes the following third-party components:

 

• Google Firebase – Analytics, Cloud Messaging (push notifications), Remote Config, In-App Messaging (App).

• Google AdMob – advertising (free version of the App).

• Google Play Services / Google Sign-In – authentication for the Google Sheets feature, OSS license display, Wear OS connectivity (App).

• Google Play Billing – in-app purchases / subscriptions (App).

• Google Sheets API – optional answers feature (Section 5).

• OpenAI, Google Gemini, Dialogflow – optional AI features (Section 6).

• Wix – hosting and operation of the Website (Section 7).

 

The role each recipient plays depends on the specific service. Based on these providers' current documented terms, the roles are as follows:

 

• Google – Firebase (Analytics, Cloud Messaging, Remote Config, In-App Messaging): Google acts as our data processor under the Firebase Data Processing and Security Terms.

• Google – AdMob (advertising): Google acts as an independent (separate) controller for serving and measuring ads, under the Google Ads Data Protection Terms.

• Google – Google Play (Billing, app distribution, Play services): Google acts as an independent controller.

• Google – Google Sign-In, Google Sheets, Gemini: Google acts as the controller of your Google account and associated Google services data under Google's Privacy Policy; for the Gemini API specifically, Google processes the request content the App sends to generate a response under the applicable Google API/Gemini terms.

• OpenAI (optional AI feature): OpenAI processes the request content you send via the API to generate a response, under OpenAI's applicable API/data-processing terms.

• Wix (Website hosting): role as described in Section 7.4 (processor for hosting; may also act as an independent controller for its own purposes).

 

These roles reflect the providers' current documented terms and may change if a provider updates its terms; the authoritative position is set out in each provider's own privacy documentation, which we encourage you to review.

 

These providers may process data outside your country, including in the United States. Where data is transferred outside the EU/EEA, such transfers are based on appropriate safeguards (e.g. the EU Standard Contractual Clauses and/or the EU–U.S. Data Privacy Framework) as implemented by the respective provider.

 

Relevant Google policies:

• Google Privacy Policy: https://policies.google.com/privacy

• How Google uses data from apps that use its services: https://policies.google.com/technologies/partner-sites


 

9. Advertising

 

The free version of the App shows ads via Google AdMob. To serve and measure ads, advertising partners may use device identifiers (including the advertising ID), your IP address, and ad-interaction data, and may store and access information on your device.

 

9.1 Consent in the EEA, UK and Switzerland (CMP)

 

For users in the European Economic Area, the United Kingdom and Switzerland, the App presents a consent message through Google's User Messaging Platform (UMP). This message is operated by Google acting as a Google-certified Consent Management Platform (CMP) and runs under the IAB Transparency & Consent Framework (TCF v2.2). It is used to obtain consent before personalised ads are served and before non-essential information is stored on or read from your device, in line with Google's EU User Consent Policy.

 

• The consent message is presented when the App starts, where required, so you can make your choice before personalised advertising is used.

• If you refuse (or have not consented to) personalised ads, the App continues to serve only non-personalised ads. Non-personalised ads rely on contextual information rather than your personal advertising profile, but they are not free of data processing: depending on Google's ad stack and your consent choices, they may still involve limited processing of device information, your IP address, and identifiers for purposes such as ad delivery, security and fraud prevention, frequency capping, and aggregated measurement. "Non-personalised" therefore does not mean "no personal data." The App requests ads only once the CMP indicates that ad requests are permitted for your consent choice.

 

9.2 Changing or withdrawing your choice

 

You can reopen the ad/privacy consent settings at any time inside the App: open the About screen and tap the privacy / consent options entry. This lets you review and change or withdraw your previous choices. Where this option is not shown, it means a consent form is not required in your region.

 

In addition, you can opt out of personalised ads at the device level in your Google settings ("Ads" / "Reset advertising ID").


 

10. Legal Bases for Processing (GDPR)

 

Where the GDPR applies, we rely on the following legal bases:

 

• Performance of a contract (Art. 6(1)(b) GDPR): providing the App's core functionality, processing purchases, handling enquiries, and operating optional features you enable.

• Consent (Art. 6(1)(a) GDPR): personalised advertising, optional analytics and non-essential cookies where consent is required, and connecting optional third-party services such as your Google account. You may withdraw consent at any time.

• Legitimate interests (Art. 6(1)(f) GDPR): ensuring the security and stability of the App and Website, preventing abuse/fraud, basic diagnostics, and responding to enquiries. We balance these interests against your rights.


 

11. Data Storage, Security and Protection

 

• Your rules, replies, history, statistics and settings are stored locally on your device. We do not maintain a central database of your message content.

• All network communication described in this policy uses encrypted HTTPS/TLS connections.

• We apply reasonable technical and organisational measures to protect data within our control. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.

• Data handled by third-party providers (Sections 7 and 8) is protected under their respective security programs.


 

12. Data Retention and Deletion

 

• On-device data (rules, history, statistics, settings, locally stored Google email): retained until you delete it within the App or uninstall the App. Uninstalling the App removes this local data from your device.

• Google Sheets access: revoked immediately when you sign out in the App or remove access in your Google Account; the locally stored email is then deleted.

• Firebase Analytics data: retained according to our configured retention period and Google's defaults, after which it is automatically deleted or anonymised.

• Purchase/license data: retained as required to provide the purchased features and to comply with legal (e.g. tax/accounting) obligations.

• Website server logs and cookies: retained for the limited period necessary for security and operation, or as configured by Wix; cookie lifetimes vary by cookie.

• Enquiry/contact data: retained for as long as needed to handle your request and to comply with any legal retention obligations.

• Data sent to optional services (OpenAI, Gemini, Dialogflow, your webhook): the retention of that data is governed by each provider's policy.

 

No AutoResponder account

 

The App does not require or provide a separate AutoResponder user account. Connecting a Google account for the optional Google Sheets feature does not create an AutoResponder account; you can disconnect it as described above. Because there is no app account to delete, you control your data directly through the steps below.

 

How to request deletion

 

You can delete your data at any time by:

1. Deleting individual rules/history within the App, or clearing the App's data, or uninstalling the App;

2. Revoking Google access in the App or at https://myaccount.google.com/permissions; and

3. Clearing cookies in your browser for the Website.

 

To request deletion of any personal data held by us (for example analytics/diagnostic data associated with your app instance, purchase records, or enquiry data), email info@autoresponder.ai. We will respond within the timeframe required by applicable law (under the GDPR, normally within one month).


 

13. Your Privacy Rights

 

Depending on where you live, you may have the right to:

 

• Access the personal data we hold about you;

• Rectify inaccurate data;

• Erase your data ("right to be forgotten");

• Restrict or object to processing;

• Data portability;

• Withdraw consent at any time, without affecting prior processing;

• Lodge a complaint with a supervisory authority.

 

To exercise any of these rights, contact info@autoresponder.ai.

 

EU/EEA users: You may lodge a complaint with your local data protection authority. The competent authority for the provider is the Bavarian State Office for Data Protection Supervision (Bayerisches Landesamt für Datenschutzaufsicht, BayLDA).

 

California users: Where California privacy laws (the CCPA/CPRA) apply to us, you have the right to know, access, delete, and correct your personal information, to opt out of the "sale" or "sharing" of personal information, and not to be discriminated against for exercising these rights. We do not sell personal information for money. Note, however, that we currently understand we do not meet the thresholds that make the CCPA/CPRA's business obligations applicable to us, so these rights apply only to the extent the law applies. Regardless, you can stop the use of your advertising identifier for personalised ads via your device's Google ad settings or the in-App privacy/consent options (see Section 9), and you may contact us at info@autoresponder.ai with any privacy request.


 

14. Children's Privacy

 

The Service is not directed to children. We do not knowingly collect personal information from children under the age of 13 (or the minimum age required in your jurisdiction). Users between 13 and the age of majority should use the Service only with the involvement and consent of a parent or guardian. If you believe a child has provided us with personal data, contact info@autoresponder.ai and we will delete it.


 

15. International Use and Data Transfers

 

The Service is available worldwide. By using the App, the Website, and their third-party integrations, your data may be processed in countries other than your own, including the United States, where data-protection laws may differ.

 

The main destinations and safeguards for transfers outside the EU/EEA are:

 

• Google (Firebase, AdMob, Google Play, Google Sheets, Gemini): primarily the United States. Google relies on the EU Standard Contractual Clauses (SCCs) and its certification under the EU–U.S. Data Privacy Framework (DPF) for such transfers.

• Wix (Website hosting): may include the United States and other countries where Wix or its sub-processors operate, on the basis of the EU Standard Contractual Clauses.

• OpenAI (optional AI feature, if you enable it): primarily the United States, on the basis of the EU Standard Contractual Clauses.

 

These safeguards are implemented by the respective provider, and the applicable mechanism may change as providers update their compliance programs. You may request information about the relevant transfer safeguards by contacting us at info@autoresponder.ai.


 

16. Changes to This Policy

 

We may update this Privacy Policy from time to time. The current version is always available at https://www.autoresponder.ai/privacy and the "Last updated" date above reflects the latest revision. Material changes will be communicated through the App or the Website where appropriate.


 

17. Contact

 

Tim Kosmala, Germany

Email: info@autoresponder.ai (English or German)

Full postal address: see Section 2 (Data Controller) or our legal notice (Impressum) at https://www.autoresponder.ai/legal 

bottom of page