Is Your Customer Data Safe With an AI Chatbot? 10 Questions to Ask
Your customers send you their address, their phone number, sometimes a photo of a receipt, and they send it on WhatsApp because it feels private. Put an AI in front of that inbox and a reasonable question follows: where does all of that go now, and who else can see it?
Customer data can be safe with an AI chatbot, but the answer depends on three parties, not one. On WhatsApp, each message passes through Meta's Cloud API, which says it encrypts messages at rest and keeps them for a maximum of 30 days; through the chatbot vendor's own systems; and through an AI model provider, where OpenAI, Anthropic and Google all say they do not train on API data by default. The middle party, the vendor, is where policies differ most. Ask it the ten questions below before you connect your number, and get the answers in writing.
This is a practical guide, not legal advice. For a regulated business, take the answers to your lawyer.
Where a WhatsApp chatbot message actually goes
Picture one message, "can you deliver to Jounieh tomorrow", on its way to an answer.
| Step | Who holds it | What they say about it |
|---|---|---|
| 1. Meta's WhatsApp Cloud API | Meta | Encrypted at rest, kept for a maximum of 30 days for features like retransmission, not automatically used for ads |
| 2. The vendor's platform | Your chatbot provider | Varies by vendor. This is where conversation history, contacts and analytics usually live |
| 3. The AI model | OpenAI, Anthropic, Google or another provider | Major APIs say no training on API data by default, with logs kept for a limited period |
| 4. Your own systems | You | Order lookups, stock, CRM records the chatbot reads or writes |
Steps one and three are documented by companies with large legal teams. Step two is the one you are actually choosing when you choose a vendor, and it is the step most sales pages say least about.
What the AI providers say about your data
Checked on each provider's own page on 3 October 2026.
- OpenAI: data sent to the API has not been used to train or improve its models since 1 March 2023, unless the customer opts in. Abuse monitoring logs are kept for up to 30 days unless law requires longer. Zero data retention exists for certain endpoints with prior approval, and its data residency regions include the United Arab Emirates.
- Anthropic: by default, inputs and outputs from its commercial products, including the API, are not used to train models. It deletes API inputs and outputs within 30 days by default.
- Google Gemini API, paid tier: prompts and responses are not used to improve Google's products, and are logged for a limited period only to detect policy violations. No duration is stated.
- Meta's WhatsApp Business Platform terms go further on the platform side: businesses may not use platform data to create or train AI models, with an exception for fine tuning a model customised for their own exclusive use.
So "will the AI learn from my customers and tell my competitor" has a reassuring default answer at the model layer. The real question is whether your vendor changed that default, and which provider it uses at all.
The regional part: where the law and the servers are
This is where a brand selling in Lebanon and the Gulf has questions a global vendor's FAQ will not answer.
Saudi Arabia. The Personal Data Protection Law came into force on 14 September 2023, with compliance expected by 14 September 2024, and SDAIA is the competent authority. It covers processing of data about people in the Kingdom even when done from outside it. Sending data abroad is conditioned, not banned: SDAIA's regulation on transfers outside the Kingdom relies on a published list of adequate countries, or on safeguards such as standard contractual clauses.
United Arab Emirates. Federal Decree-Law No. 45 of 2021 on personal data came into force on 2 January 2022 and sets requirements for cross-border transfers. Businesses in the DIFC fall under its own Data Protection Law, DIFC Law No. 5 of 2020.
Lebanon. Law No. 81 of 2018 on electronic transactions and personal data covers the collection, recording, storage and other processing of personal data, whatever the medium.
And the servers. Meta lets a business choose local storage for Cloud API message content at rest. The region codes listed in its registration reference include the UAE and Bahrain, but not Saudi Arabia or Lebanon. So a UAE brand can ask for its WhatsApp messages to rest in the UAE; a Saudi brand currently cannot pick Saudi Arabia through that option, and should ask how its vendor handles the transfer question instead.
The 10 questions to ask any AI chatbot vendor
- Which AI model provider do you use, and on which plan? Consumer apps and business APIs have different data terms.
- Have you opted into any training or data sharing with that provider? The default is no. Make sure it still is.
- Where are my conversations stored, in which country, and for how long? Get a number of days, not "securely".
- Who on your team can read my customers' messages, and when? Support access should be limited and logged.
- Do you use my conversations for anything other than serving my customers? Benchmarks, demos and training other clients' bots all count.
- Can I export every conversation and contact, in a usable format, at any time?
- What happens to my data on the day I cancel? Deletion timeline, and what you get to keep.
- Which countries does my data pass through, and on what basis? Essential if you sell in Saudi Arabia.
- How does a customer reach a human, and how do I see what the AI said? Meta's messaging policy requires prompt, clear and direct escalation paths when you automate replies.
- How do you verify a customer before sharing their order or account details? A phone number alone is identity, not authorisation, for anything sensitive.
A vendor that answers all ten plainly is one you can work with. A vendor that answers with a security badge and no numbers has told you something too.
How plumcut answers them
plumcut builds and runs plum, the AI that answers, sells and books on your WhatsApp, for commerce brands in Lebanon, Saudi Arabia and the wider region. Data ownership is part of the product rather than a clause, because plumcut's whole offer is that the conversations and the customer insight inside them belong to you.
- Your data stays yours. The conversations, the patterns and what they show about why customers buy or do not are the brand's, not locked inside a platform you would lose if you left, and not handed to anyone else.
- Your own accounts. Meta messaging and AI usage are billed to you at cost, on your own accounts, so the relationship with Meta is yours.
- A human route, built in. Tricky and sensitive conversations are handed to your team at the right moment, which is both good service and what Meta's policy requires.
- Arabic and English, from the region. The questions in the regional section above are the ones the team works with every week, not a footnote.
Bring the list. Ask all ten on the first call and compare the answers with whoever else you are considering. For what the rest of the bill looks like, see what AI customer service really costs.
What to do this week
- List every tool that touches your WhatsApp inbox today, including the ones a freelancer connected once and nobody checked since.
- Send each one questions 1, 3 and 7. Those three answers tell you most of what you need.
- If you sell in Saudi Arabia, add question 8 and keep the reply on file.
- Write down how a customer reaches a person on your WhatsApp today. If you cannot, fix that before you automate anything.
Questions people also ask
Is customer data safe with an AI chatbot on WhatsApp?
It can be, but safety depends on the chain, not the chatbot. A WhatsApp AI usually passes each message through three parties, Meta's WhatsApp Cloud API, the vendor's own servers, and an AI model provider. Meta states that Cloud API messages are encrypted at rest and kept for a maximum of 30 days. The major AI model APIs from OpenAI, Anthropic and Google say they do not train on API data by default. The weakest link is usually the vendor in the middle, so ask where it stores conversations, for how long, and who can read them.
Does the AI train on my customers' WhatsApp messages?
Not by default at the major model providers. OpenAI says data sent to its API has not been used to train its models since 1 March 2023 unless the customer opts in. Anthropic says it does not use inputs or outputs from its API to train models by default. Google says paid Gemini API prompts and responses are not used to improve its products. Meta's WhatsApp Business Platform terms also restrict using platform data to train AI models, other than fine tuning a model for the business's exclusive use. Ask your vendor to confirm in writing which provider it uses and whether it opted into anything.
Can WhatsApp chatbot data be stored in Saudi Arabia or the UAE?
For data at rest on Meta's Cloud API, partly. Meta offers a local storage option that keeps message content at rest in a chosen region after processing. The supported region codes listed in Meta's registration documentation include the United Arab Emirates and Bahrain, but not Saudi Arabia or Lebanon. Messages are still processed in Meta data centers before that. Separately, the vendor's own database and the AI provider may store data elsewhere, so ask each one.
What does Saudi Arabia's PDPL mean for a chatbot?
Saudi Arabia's Personal Data Protection Law came into force on 14 September 2023, with organisations expected to comply by 14 September 2024, and SDAIA is the competent authority. It applies to processing the data of people in the Kingdom even by parties outside it. Transfers outside the Kingdom are conditioned rather than banned, under a separate SDAIA regulation that relies on an adequacy list or safeguards such as standard contractual clauses. A brand selling in Saudi Arabia should ask its chatbot vendor where data goes and which transfer basis it relies on.
Who owns the conversations a chatbot has with my customers?
Check the contract, because it varies. Some platforms keep conversation history and analytics inside their product, so leaving means losing it. Ask whether you can export every conversation and contact in a usable format, what happens to your data on the day you cancel, and whether the vendor can use your conversations for anything beyond serving your own customers. plumcut's position is that the conversations, and what they show about your customers, belong to the brand and are not locked into a platform or handed to anyone else.
Have a question? Ask plum.
See it for yourself
Put all ten questions to plum on your first call. Your customers, your conversations and what they teach you stay yours.