Last updated: October 2, 2026
Ctrl ("Ctrl", "we", "us", "our") is a unified messaging inbox for small businesses, built and operated by Lisan Systems. Ctrl lets a business connect its own Instagram, Facebook, and WhatsApp Business accounts and manage customer messages from all of them in one place.
When a business connects a channel, they are sent to that platform's own official login screen (Meta's OAuth consent flow for Instagram and Facebook). Ctrl never asks for, sees, or stores a business's Instagram or Facebook password. Instead, the platform issues Ctrl a limited, revocable access token scoped only to the permissions the business explicitly approved on that screen — typically the ability to read and send messages on the connected Page or account.
For WhatsApp Business, a business enters an access token and phone number ID that they generate themselves from their own Meta Business account; Ctrl stores this the same way, encrypted, and uses it only to send and receive messages on their behalf.
For each connected business, we store:
Data belonging to one business is never visible to another business using Ctrl. Every database query is automatically scoped to the business the logged-in user belongs to.
We use the data above solely to operate Ctrl's core features for the connected business: showing their messages in a unified inbox, sending their replies back to the customer through the originating platform, and — where a business has enabled it — using an AI service to classify the intent of an incoming message (e.g. booking, pricing question) or draft a suggested reply. We do not sell customer or business data, and we do not use it for advertising.
Messages and account tokens pass through the platform the business connected (Meta's Graph API for Instagram/Facebook/WhatsApp) in order to send and receive messages — this is how the product functions, and is authorized by the business's own connection. Where a business enables AI-drafted replies or automatic classification, the relevant message text is sent to our AI provider (Anthropic) for that single request only, and is not used by us to train any model.
We retain connected account tokens and message history for as long as the business's account remains active. A business can disconnect any channel at any time, which revokes and deletes the stored access token immediately. A business can request full deletion of their account and all associated data by contacting us using the details below.
Access tokens are stored encrypted at rest. Access to a business's data within Ctrl is restricted to authenticated users belonging to that business.
We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date above.
Questions about this policy or your data can be sent to lisansystems@gmail.com.