Last updated 5 Sept 2026
Privacy policy
What Sedge collects, why, how long it is kept, and how to have it removed.
Who this covers
Two different groups of people appear in Sedge, and they are treated differently.
- Customers — the people who sign in: an account holder at an organisation that uses Sedge to moderate its WhatsApp groups.
- Group members — the people in those WhatsApp groups. They do not have a Sedge account, and most of them will never see this product. Data about them is held on behalf of the organisation that runs their group, and that organisation decides how long it is kept.
What we collect about customers
- Name, email address and password hash. Passwords are never stored in a readable form.
- Organisation name, billing email and subscription state.
- Session records — the IP address and browser the session was created from, when it was created, and when it was last used — so you can see and revoke your own sessions.
- An audit trail of the actions you take inside the product.
What we collect about group members
Only what moderation needs, and only from the groups an organisation has marked as protected.
- The identifier the provider gives us, the display name, and the phone number where the provider supplies one.
- Counts and timings: how many messages, in which windows, how many links, how many mentions, when the member was last observed.
- Content hashes, so a repeated message can be recognised without keeping the text.
- A bounded excerpt of a message — only when a rule actually fires, and only for as long as the organisation’s retention setting allows.
- Moderation events, strikes, warnings and review cases relating to that member.
What we never collect
- Conversations. Message bodies pass through the analysis queue and are not written to the database.
- Anything from a group that has not been marked as protected.
- Presence, online status or “last seen”. The inactivity engine has no field for it.
- Read receipts.
- Direct messages of any kind.
- Media files. Media is counted and typed; it is never downloaded or stored.
Why we hold it
To provide the service the customer asked for: applying the moderation rules they configured, recording why each action was taken so it can be reviewed, and keeping an audit trail. Where an organisation is subject to data protection law, they are the controller for their group members’ data and Sedge is a processor acting on their instructions.
How long it is kept
Retention is set per organisation and capped by their plan. There are three separate periods, and each can be shortened at any time:
- Evidence — message excerpts and the material attached to a moderation event.
- Activity — the counters and timings behind participation and inactivity.
- Audit — the record of who changed what, and when.
Shortening a period deletes what falls outside it on the next cleanup run. A small set of security-critical audit entries — failed sign-ins, password and two-factor changes, role changes, API key creation, support access, exports and deletions — is always retained, because losing them would defeat the purpose of having an audit trail.
Who can see it
Each organisation’s data is isolated at the database level, not by a filter in the application. Nobody at Sedge can read an organisation’s data by default. Support access is off; enabling it requires a stated reason and an expiry, and every grant and every use of one is written into that organisation’s own audit trail.
Platform staff can always see aggregate counts — numbers of groups, members and failed jobs — because operating the service requires it. Those are counts, never content.
Sub-processors
The hosted service runs on infrastructure operated by our hosting provider, and uses a payment processor for subscriptions. Card details are handled by the payment processor and never reach Sedge. Where an installation is self-hosted, the operator of that installation chooses its own infrastructure and this section does not apply.
Your rights
If you have a Sedge account, you can see and change your own details, see and revoke your own sessions, and export your organisation’s data at any time. An owner can delete the organisation, which schedules the removal of everything belonging to it.
If you are a member of a group moderated by Sedge, the organisation that runs your group is the right place to start — they control the data and can delete an individual member’s records from within the product. If you cannot reach them, write to support@sedge.app and we will pass the request on and tell you that we have.
Cookies
One cookie, for your session. It is http-only, first-party, and set only after you sign in. There is no advertising, no analytics tracking of individuals and no third-party cookie in the product.
Changes
If this policy changes in a way that affects what is collected or how long it is kept, account holders are told in the product before it takes effect.
Contact
Questions about this policy: support@sedge.app. Security reports: security@sedge.app. See also the security page for how isolation and encryption work.