Last updated: October 7, 2026
Help, privacy and terms
Quick answers about Bridgus and how we handle the information of your company and your customers.
Frequently asked questions
What is Bridgus?
An omnichannel CRM: it brings your company's WhatsApp, Instagram and Messenger conversations into a single inbox, with a sales pipeline, automatic replies, flows and an optional AI assistant.
How do I connect WhatsApp, Instagram or Messenger?
An administrator connects each channel in Settings → Channels with the details of the company's Meta app. Bridgus receives messages through webhooks signed by Meta and replies through the official API.
How does WhatsApp Cloud API differ from the QR connection?
Cloud API is Meta's official integration, and Meta bills conversations directly to your company's business account. The QR connection is optional and unofficial: it links a WhatsApp account as a device and may be limited or blocked by WhatsApp. Bridgus applies pauses, limits and typing simulation to reduce that risk, but cannot remove it.
Why can't I reply to a conversation?
WhatsApp, Instagram and Messenger only allow free-form messages within 24 hours of the customer's last message. Outside that window Bridgus blocks the send.
How is AI billed?
The assistant is optional and uses the OpenRouter key your company sets up; that provider bills usage directly. Bridgus stores the key encrypted and only shows its last four characters.
Who can see conversations?
Only the members of your organization. Agents work the inbox and the pipeline; administrators also set up channels, rules, flows and AI. No organization can see another one's data.
Data deletion
You can ask us to delete your data at any time.
- If you are a user of a company, ask an administrator of your organization to remove you, or write to us from your account's email.
- If you wrote to a company over WhatsApp, Instagram or Messenger, ask that company to delete your conversation, or write to us with the company's name and your number or username.
- If you connected a Meta page or account, disconnect the channel in Settings → Channels and remove the app from Facebook's business integrations settings. We will stop receiving its data.
- We will confirm the request and delete the data within 15 days at most, except what the law requires us to keep.
Send your privacy and deletion requests to [email protected].
Privacy policy
This policy explains what data Bridgus processes, why, and how you can exercise your rights. It applies to the users of the companies that use Bridgus and to the people who write to them through their channels.
Service operator
Bridgus
Data we process
Account: each user's name, email and password. The password is stored only as an irreversible hash.
Conversations: the content and metadata of the messages that reach the connected channels, the contact's name, number or username and, when a message comes from an ad, the ad identifier.
Credentials: Meta access tokens and the AI assistant key, encrypted at rest with AES-256-GCM.
Technical data: access logs without message content, the cookies needed for the session, request forgery protection and language, and the theme preference saved in your browser.
Why we use it
Only to provide the service: show and answer conversations, organize the pipeline, run the automations the company sets up, protect accounts and diagnose failures. We do not sell data or use it for advertising or to train AI models.
Data from Meta platforms
Information received from WhatsApp, Instagram and Messenger through Meta's APIs is used only to run the inbox of the company that connected the channel, in line with Meta's Platform Terms, and is not shared with third parties other than the processors listed below.
Who we share it with
The infrastructure providers that host the service; Meta, to deliver the company's replies; and, only if the company turns on the AI assistant, the model provider it chooses through OpenRouter, which receives the recent conversation history to write the reply.
Retention
Messages and contacts are kept while the company keeps its account or until it asks for their deletion. Technical webhook events are deleted after 30 days and expired sessions are removed automatically.
Security
HTTPS-encrypted connections, secrets encrypted at rest, strict isolation between organizations, access roles and protected session cookies (HttpOnly and Secure).
Your rights
You can access, correct and update your data, request its deletion, object to or ask to suspend its processing, request its portability and not be subject to decisions based solely on automated processing, under Ecuador's Organic Law on Personal Data Protection and other applicable laws. You may also file a complaint with the Superintendency of Personal Data Protection. If you wrote to a company that uses Bridgus, that company controls your data and Bridgus acts as its processor: send your request to the company or to us and we will pass it on.
Send your privacy and deletion requests to [email protected].
Terms of service
Bridgus is a platform to manage conversations, contacts, sales and automations over messaging channels. By using it you accept these terms on behalf of your company.
The company keeps ownership of its data, contacts, messages and settings; Bridgus processes them only to provide, maintain and protect the service.
The company must use Bridgus lawfully, in line with the WhatsApp, Instagram and Messenger policies and with its contacts' consent. A contact's request to opt out or object must be honored immediately.
Official channels depend on Meta: their pricing, templates, messaging windows and account quality are set by Meta and are not part of the Bridgus service.
The QR connection is unofficial and may suffer disconnections, limits or blocks from WhatsApp. Bridgus applies careful sending measures but cannot guarantee that WhatsApp will not limit a number.
AI assistant replies are automatic and can be wrong. The company reviews its settings and business information; AI does not replace professional, medical, legal or financial judgment.
The company manages its users and roles. Any action taken with valid credentials is considered taken by the corresponding organization; tell us at once if you suspect unauthorized access.
We take reasonable steps to keep the service available and secure, but we do not guarantee it will run without interruptions. We may update these terms; the last updated date shows when.