Encrypted both ways
All traffic runs over TLS; stored data is encrypted at rest, and WhatsApp access tokens carry extra AES-256-GCM field-level encryption.
PRIVACY & TRUST
DialogSignal’s launch standard is simple: state what is live, expose useful controls, and never turn a roadmap item into a trust badge.
AT A GLANCE
What a careful buyer needs to know first. Every claim below is expanded — and honestly qualified — further down the page.
All traffic runs over TLS; stored data is encrypted at rest, and WhatsApp access tokens carry extra AES-256-GCM field-level encryption.
DialogSignal reads a chat file you export yourself. No plugin, no number registered, no message sent for you — the WhatsApp Business connection is built but not switched on.
One account-deletion flow removes your data from the database, file storage, AI vendor stores, and analytics — with an audited record.
Full data access and portability exports are built into the product, covering your conversations and derived results.
AI processing runs only with your recorded consent, and you can withdraw it. No raw chat text goes into logs or error tracking.
The application runs on Vercel; your data sits in Supabase, with row-level security enforced in the database itself. Moving to Google Cloud with regional servers is planned for launch — so it is not claimed here yet.
TRANSPARENT CONTROL
Conversation intelligence can be valuable only when the boundaries are understandable. DialogSignal’s trust architecture separates what you upload, what is processed, what becomes an insight, and what you can export, correct, restrict, or remove.
If a storage region, retention window, subprocessor, or legal status is not finalized, the website says so plainly.
Each step has a different responsibility: deliberate input, bounded processing, private results, and controls that remain available after analysis.
PLAIN LANGUAGE
No invented certifications. No vague ‘bank-grade’ claims. Just the controls and commitments that matter.
Analysis begins with the conversations you deliberately provide.
Remove an upload or begin account deletion from the product.
Take structured output and account data out of DialogSignal.
Marketing and product measurement are treated as an explicit choice.
Your workspace separates your results from other users.
Access, correction, restriction, objection, and deletion are product-level workflows.
HOW IT WORKS
The visual path distinguishes what you choose, what DialogSignal processes, what appears privately, and what remains under your control.
SECURITY & YOUR DATA
Encryption, location, retention, backups, access, audit, subprocessors, AI, deletion, and breach response — answered specifically, with anything unfinished labeled as unfinished.
The early-access box stores your email address. The optional questions after it, and the contact form, store what you choose to give: name, company, role, sector, team size, region, working language, and your message. That is held in our own Cloudflare D1 database and emailed to the DialogSignal team through Resend so we can reply. It is used to run early access and to answer you — never sold, never passed to advertisers, and kept separate from any conversation you later upload for analysis.
Marketing email is opt-in: joining the list means we may tell you when the product opens, and anything beyond that only happens if you tick the box asking for it. You can request deletion through the contact form at any time.
Both forms also run a Cloudflare Turnstile check before they accept anything, which is what keeps bots out of the list. It loads a small script from Cloudflare and, for almost everyone, clears silently with no puzzle to solve. It is a bot check rather than an advertising or tracking tool: it does not read what you typed and it is not used to profile you.
Today the application runs on Vercel and your data sits in Supabase — managed PostgreSQL — while this website and its forms run on Cloudflare. Those are United States-managed platforms, and we are not going to claim a Gulf residency option we have not built. Planned, not live today: at launch the application migrates to Google Cloud with regional servers, and the exact region — including a Gulf, PDPL-aligned option — will be published here before open signup rather than promised in advance.
Yes, both. All traffic uses TLS/HTTPS end to end, and stored data is encrypted at rest by the database platform. The app also ships strict browser-security headers — HSTS with preload, and a strict Content Security Policy. Where the product stores a third-party access token, it carries additional AES-256-GCM field-level encryption with versioned keys, on top of the platform’s own encryption.
Concrete rules, and these are the ones a scheduled job actually enforces every night rather than intentions. Your uploads and results are kept while your account exists and until you delete them — there is no fixed expiry on an inactive account, and nothing is removed behind your back. Operational logs are deleted after 180 days. IP addresses inside those logs are anonymised after 90 days, well before the logs themselves go. Generated report exports expire automatically. Anything you send through this website’s forms is kept until you ask us to delete it.
Yes — Supabase takes automated backups of the production database as part of its managed platform. What we are not going to claim yet is a stated backup-retention period, point-in-time recovery, or documented restore testing, because those are configured with the Google Cloud migration. This is a trial-stage answer. A published backup and restore policy — retention period, point-in-time recovery, and tested restores — is part of the launch standard and lands with the Google Cloud migration, written here once each number is real rather than promised now.
Every record is scoped to your account inside the database itself. Row-level security is enabled table by table, with several hundred access policies, so one customer’s query cannot reach another customer’s rows even if the application layer were wrong.
Operationally, production access is limited to the 2 founders — Ahsan Naeem Minhas and Naeem Ahmed Minhas — protected by two-factor authentication. An elevated key that bypasses row-level security does exist; it is used only by scheduled maintenance jobs such as the retention, deletion and export workers, never for interactive browsing.
Nobody reads your conversations except for support you have asked for, or where the law requires it. Planned, not live today: in-app team roles and per-member permissions for multi-user workspaces.
Sensitive operations are audited today, in dedicated tables rather than as a side effect of ordinary logging: every deletion, every data-rights request and every consent change writes a durable record, and every AI call is metered and logged without raw message text. Planned, not live today: a general in-app activity log of team-member actions.
7 of them, named plainly, with what each one touches.
Cloudflare — this website, the database behind its forms, and the Turnstile bot check. Vercel — application hosting. Supabase — the production database, file storage and sign-in. Google — Gemini, on the paid API tier, for analysis, summaries, cited answers and translation. Resend — the transactional email that lets us reply to you. Sentry — error monitoring, scrubbed of message content. PostHog — product analytics, which does not run without your consent.
Meta is deliberately not on that list: the WhatsApp Business connection is not enabled, so no customer data reaches Meta at all. Planned, not live today: Vertex AI replaces the direct Gemini API at launch, alongside the move to Google Cloud.
All AI features run on Google Gemini through the paid API tier — analysis, summaries, cited answers and translation. Google’s paid API terms do not use your data to train its models, and being on that tier rather than the free one is the reason we can say so; the free tier reserves that right, which is exactly why we do not use it. AI processing is consent-gated: it runs only after you record consent, and withdrawing consent stops new processing. Raw chat text is never written to logs or error tracking. Planned, not live today: Vertex AI at launch.
From inside the product, today. You can delete individual uploads or your whole account; account deletion removes your data from the database, file storage, AI vendor file stores, and analytics — child records first, with a completion audit trail.
Data-rights requests — access, portability, rectification, restriction, objection, deletion — are product workflows carrying a 30-day service-level commitment, and a job runs every morning to flag any request approaching that deadline. One gap we will name rather than hide: during the trial stage we do not publish how long deleted data survives in encrypted backups. That number arrives with the backup policy at launch, and not before — the same standard applies to it as to everything else here.
If a breach affects your data, we commit to telling affected customers within 72 hours of confirming it — what happened, what data was involved, and what we are doing about it. Notice goes to the email address on your account. Use the contact form for questions about this page.
YOUR RIGHTS
The precise legal scope is finalized with the privacy notice; the product surfaces are already part of the DialogSignal architecture.
Swipe to compare the rights and controls
| Right | What it means | Product surface |
|---|---|---|
| Access | See what data the service holds | Access request |
| Portability | Take a copy with you | Data export |
| Rectification | Correct something wrong | Correction request |
| Restriction | Pause specific processing | Restriction control |
| Objection | Object to specific processing | Objection control |
| Deletion | Erase an upload or account | Deletion flows |
RELIABILITY & SUPPORT
Uptime numbers are easy to print. What matters is the behavior underneath them.
During the trial stage, none — and we would rather say that than print a number we cannot yet stand behind. The application runs on Vercel and Supabase, each carrying its own platform availability terms, and DialogSignal adds no separate guarantee on top of them while the product is in trial.
This is a trial-stage position, not a permanent one. A stated application service level and a public status page are part of the launch standard, published with the move to Google Cloud, and this answer will carry both numbers rather than describe them.
During the trial stage we commit to a first reply within 4 hours. Use the contact form and you will get a person, not a queue — with a two-person team, the person replying is usually a founder.
That is a commitment we are making now rather than a number we grew into, so if we ever miss it we would rather you hold us to it than find the promise quietly removed. Per-plan response times are set to standard when paid plans open at launch.
The pipeline is built to fail safely rather than silently. Long-running work — uploads, analysis runs, embeddings, exports — is watched by scheduled reapers that catch anything stalled and mark it, instead of leaving you looking at a spinner that will never finish, and one failing step does not take down the rest of the run.
The outbound WhatsApp send path is built to the same standard — idempotent sends that cannot double-send, rate limiting, and reconciliation of anything unconfirmed — but none of it is running, because the WhatsApp Business connection is not enabled. Planned, not live today: a customer-facing view of failed work and proactive alerts in the dashboard.
WHATSAPP INFRASTRUCTURE
The integration is built and switched off. Until it is on, the honest answer to most of these questions is that there is nothing to answer.
No. DialogSignal reads a chat file that you export yourself from WhatsApp and upload. Nothing connects to your WhatsApp account, no plugin is installed, no phone number is registered, and no message is ever sent on your behalf. The WhatsApp Business API integration exists in the codebase but is not switched on. Planned, not live today: connecting your own WhatsApp Business Account through Meta’s official Cloud API.
No — and we are not going to describe a partnership we do not have. There is no BSP relationship and no Meta integration running today. If that changes, this answer names the partner.
You would, structurally rather than just contractually. When the connection is enabled, your WhatsApp Business Account stays in your own Meta Business Manager and the number stays yours; DialogSignal connects using credentials you grant, stored encrypted, and never takes ownership of either. Today the question is moot, because nothing is connected.
Nothing is charged today, because there is no WhatsApp connection — Meta bills you nothing through DialogSignal. When the integration is enabled, Meta bills your own WhatsApp Business Account directly for template messages at its own published rates. Those fees sit between you and Meta; we do not resell messages and we do not mark them up.
GLOBAL, WITH GCC DEPTH
DialogSignal is global in ambition and Gulf-aware in product thinking. Arabic translation workflows, Saudi PDPL requirements, GDPR principles, and regional-residency options shape the launch, but each claim waits for production proof.
Roadmap work stays labeled as roadmap work. Compliance alignment is not presented as certification.
WHAT WE DO NOT DO
These are the standards the public launch must satisfy before open signup. Final legal wording will match the selected production systems and provider terms.
GDPR or PDPL alignment is described as legal and engineering work, not presented like an ISO or SOC certification.
DialogSignal is a paid intelligence product, not an ad-targeting layer built around customer conversations.
AI-provider and model-training terms must be disclosed clearly before people upload business conversations.
Retention, backups, and deletion timelines must be described with the nuance the production system actually supports.
COMPANY & LEGAL
DialogSignal.ai is a product of Thinkers Engine LLC, a limited liability company registered in the State of Wyoming, United States. The Certificate of Organization was filed with the Wyoming Secretary of State on 22 August 2026 under filing ID 2026-002062754. Registered office: 30 N Gould St #46267, Sheridan, WY 82801, United States.
Wyoming, in the United States, with Registered Agents Inc as the company’s registered agent in Sheridan. The founding team works from Riyadh in Saudi Arabia and Islamabad in Pakistan, which is also where the product’s Gulf and Arabic-language focus comes from.
2 of us, named. Ahsan Naeem Minhas, Founder and CEO, founded DialogSignal and leads it. His field is AI operations: putting agentic AI into real business workflows — deciding what runs locally and what goes to a frontier model, where the data boundaries sit, and where a human has to review before anything ships. He builds and runs his own agent infrastructure, and writes publicly on enterprise AI deployment, data residency and AI governance. 10 years delivering for Saudi and GCC teams, in Arabic and English.
Naeem Ahmed Minhas, Co-Founder and Chief Technical Officer, co-founded DialogSignal and leads its engineering. He spent more than 20 years on enterprise systems for Gulf institutions at Intergraph and Atheeb Intergraph Saudi Company — network asset management for Saudi Telecom, GIS platforms for the Royal Commission in Al Jubail, the emergency-response system for Saudi Aramco, and asset information management for Abu Dhabi Municipality. 23 years of holding other organisations’ operational data to their standards is the discipline this product is built on.
NOW THAT YOU KNOW THE BOUNDARIES
You have read what happens to your data. The next step is small and reversible.