Ctrl Ctrl

Privacy Policy

Last updated: October 2, 2026

1. Who we are

Ctrl ("Ctrl", "we", "us", "our") is a unified messaging inbox for small businesses, built and operated by Lisan Systems. Ctrl lets a business connect its own Instagram, Facebook, and WhatsApp Business accounts and manage customer messages from all of them in one place.

2. What we access, and how

When a business connects a channel, they are sent to that platform's own official login screen (Meta's OAuth consent flow for Instagram and Facebook). Ctrl never asks for, sees, or stores a business's Instagram or Facebook password. Instead, the platform issues Ctrl a limited, revocable access token scoped only to the permissions the business explicitly approved on that screen — typically the ability to read and send messages on the connected Page or account.

For WhatsApp Business, a business enters an access token and phone number ID that they generate themselves from their own Meta Business account; Ctrl stores this the same way, encrypted, and uses it only to send and receive messages on their behalf.

3. What data we store

For each connected business, we store:

  • The encrypted access token(s) issued by the connected platform
  • Messages sent and received through the connected channels, and the customer identifiers (platform-provided user IDs, names) needed to display and reply to a conversation
  • Business account information provided at signup (name, contact email, business settings)
  • Basic usage data needed to operate the product (login timestamps, connection status)

Data belonging to one business is never visible to another business using Ctrl. Every database query is automatically scoped to the business the logged-in user belongs to.

4. How we use data

We use the data above solely to operate Ctrl's core features for the connected business: showing their messages in a unified inbox, sending their replies back to the customer through the originating platform, and — where a business has enabled it — using an AI service to classify the intent of an incoming message (e.g. booking, pricing question) or draft a suggested reply. We do not sell customer or business data, and we do not use it for advertising.

5. Third parties we share data with

Messages and account tokens pass through the platform the business connected (Meta's Graph API for Instagram/Facebook/WhatsApp) in order to send and receive messages — this is how the product functions, and is authorized by the business's own connection. Where a business enables AI-drafted replies or automatic classification, the relevant message text is sent to our AI provider (Anthropic) for that single request only, and is not used by us to train any model.

6. Data retention and deletion

We retain connected account tokens and message history for as long as the business's account remains active. A business can disconnect any channel at any time, which revokes and deletes the stored access token immediately. A business can request full deletion of their account and all associated data by contacting us using the details below.

7. Security

Access tokens are stored encrypted at rest. Access to a business's data within Ctrl is restricted to authenticated users belonging to that business.

8. Changes to this policy

We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date above.

9. Contact us

Questions about this policy or your data can be sent to lisansystems@gmail.com.