Privacy Policy
Last updated: 3 August 2026
This Privacy Policy explains how Helicon Solutions (“Helicon Solutions”, “we”, “us”, or “our”), the operator of DripRaven, collects, uses, stores, shares and protects personal data when you use the DripRaven service, website, API and the DripRaven MCP connector (together, the “Service”).
If you have any questions about this policy or how we handle your data, contact us at privacy@dripraven.com.
1. Who we are and what DripRaven does
DripRaven is a WhatsApp broadcast and drip-campaign tool designed to be operated by AI agents through the Model Context Protocol (MCP), as well as through a REST API. It lets our customers import contacts, build audience segments and send or schedule approved WhatsApp message templates, and it reports delivery and read statistics.
Helicon Solutions is a limited liability company (LLC) organized in the United States and is the entity responsible for the hosted DripRaven service.
This policy covers the DripRaven service that we host and operate. DripRaven can also be self-hosted; if you run your own instance of DripRaven, you are responsible for the data processed on your infrastructure and this policy does not apply to that deployment.
2. Our role: controller and processor
- We are the data controller for account, authentication, billing and usage data relating to the customers who sign up for and use DripRaven.
- We act as a data processorfor the contact and campaign data that a customer uploads or generates in order to run their own messaging campaigns. The customer is the controller of that data and is responsible for having a lawful basis (such as valid consent) to message their contacts. We process it only to provide the Service and on the customer’s instructions.
3. Data we collect
a. Account and authentication data
- Your name, email address and email-verification status.
- A profile image, if you sign in with Google.
- Authentication credentials: a securely hashed password (if you use email and password), or OAuth tokens (if you sign in with Google).
- Session information, including session tokens, IP address and browser user-agent string, used to keep you signed in and to protect your account.
- Organization and team membership data and invitation email addresses when you invite colleagues.
b. API keys
When you (or an AI agent acting on your behalf) connect to DripRaven programmatically, you use an API key. We store only a salted hashof each key together with a short non-secret prefix — never the key itself. The full key is shown to you only once, at creation.
c. Contact data you upload (processed on your behalf)
- Contact phone numbers (in E.164 format).
- Contact names, tags, source labels and external identifiers.
- Any custom fields you choose to add to a contact record (for example, country, sign-up date, or other attributes you import).
- Opt-out status, so we do not message contacts who have opted out.
d. Campaign and messaging metadata
- Audience segment definitions (the filters you save).
- WhatsApp message templates synchronized from Meta (template name, language, category and approval status).
- Campaign configuration, schedules and per-contact send status.
- Delivery events — whether a message was sent, delivered, read, or failed and the associated provider message identifier and timestamp.
We do not store the content (message bodies) of the messages sent or received. Inbound messages are inspected transiently only to detect opt-out requests (for example, a “STOP” keyword); the message text itself is not persisted. Our activity log records delivery status and metadata only.
e. Technical and usage data
Like most online services, our servers and infrastructure providers automatically log technical information such as IP addresses, request timestamps and error diagnostics for security, debugging and reliability.
f. Data accessed through the DripRaven MCP connector
The DripRaven MCP connector is a thin client that authenticates to the DripRaven API with your API key and exposes tools to add and list contacts, create segments, list templates, send broadcasts and read campaign statistics. It reads and writes only the DripRaven data described above. The connector does not read, collect, or store the content of your conversations with Claude or any other AI assistant. Only the specific instructions and parameters your agent sends to a DripRaven tool (for example, the contact details you ask it to add) reach our Service. Your use of Claude itself is governed by Anthropic’s own privacy policy.
4. How we use data
- To provide, operate and maintain the Service.
- To authenticate you and secure your account and API access.
- To send WhatsApp broadcasts and scheduled messages to the contacts you target, through Meta’s WhatsApp Business platform.
- To deliver transactional emails, such as sign-in (magic-link) and verification emails.
- To generate delivery and engagement statistics for your campaigns.
- To monitor, debug, secure and improve the Service and to prevent abuse.
- To comply with our legal obligations and enforce our terms.
5. Legal bases for processing (GDPR)
Where the GDPR applies, we rely on the following legal bases:
- Performance of a contract— to provide the Service you have signed up for.
- Legitimate interests— to secure, maintain and improve the Service and prevent abuse, balanced against your rights.
- Legal obligation— where we must retain or disclose data to comply with the law.
- Consent— where required. Note that consent to receive marketing messages from a DripRaven customer is obtained and managed by that customer, who is the controller of their contact data.
6. Third parties and sub-processors
We do not sell your personal data. We share it only with the service providers we need to operate DripRaven and only to the extent necessary:
| Provider | Purpose | Data shared |
|---|---|---|
| Meta Platforms (WhatsApp Business) | Sending WhatsApp template messages and receiving delivery status | Contact phone numbers, template name and language; we receive message IDs and delivery/read status back |
| Postmark (Wildbit / ActiveCampaign) | Transactional email delivery (sign-in and verification emails) | Your email address and the email content (for example, a sign-in link) |
| Google (optional) | “Sign in with Google” authentication, only if you choose it | OAuth authentication data; we receive your name, email and profile image |
| Hetzner Online GmbH (Germany) | Hosting the DripRaven servers and database | All data above is stored on infrastructure we control, hosted in Hetzner’s data center in Germany |
We may also disclose data if required by law, to protect our rights or the safety of others, or in connection with a merger, acquisition, or sale of assets (in which case we will notify affected users).
7. Meta / WhatsApp platform data and compliance
DripRaven integrates with the WhatsApp Business Platform provided by Meta Platforms, Inc. When you connect a WhatsApp Business Account to DripRaven, we receive and store a Meta access token and identifiers for your WhatsApp Business Account and phone number, which we use solely to send the messages you configure and to receive delivery status on your behalf.
Our access to, use of and storage of information obtained through Meta’s platform complies with the Meta Platform Terms and Developer Policies. We use data received from Meta only to provide and improve the DripRaven Service. We do not sell it, use it for advertising or ad targeting, transfer it to a data broker, or use it for any purpose that is not disclosed in this policy. Access tokens are encrypted at rest and revoked or deleted when you disconnect your account.
8. Data deletion
You can request deletion of your personal data at any time by emailing privacy@dripraven.com from the address associated with your account, or by deleting your account in the app. To disconnect a WhatsApp Business Account and delete its stored credentials, disconnect it in the app or contact us. We delete the associated data from our production systems within 30 days, except where we are required to retain it to comply with a legal obligation.
9. Where your data is processed and international transfers
DripRaven’s servers and database are hosted in Germany(Hetzner Online GmbH), so the core Service data — your account, contacts and campaign data — is stored and processed in the European Union. Helicon Solutions, which operates DripRaven, is organized in the United States and administers the Service from there, so a limited amount of personal data may be accessed from the United States for support and operations. Some of our sub-processors (for example Postmark and Google) also process data in the United States.
Where personal data is transferred out of the European Economic Area or the United Kingdom — for example when we access it from the United States, or when a US-based sub-processor handles it — we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses (and the UK International Data Transfer Addendum) or another lawful transfer mechanism.
10. Data retention
We retain personal data for as long as your account is active and you use the Service. When you delete your account, or when a customer instructs us to delete data on behalf of a contact, we delete the associated personal data from our production systems within 30 days, except where we are required to retain it longer to comply with a legal obligation, resolve disputes, or enforce our agreements.
When a contact is deleted, delivery-event records are anonymized rather than kept in identifiable form. Hashed API keys are removed when you revoke them. Backups are cycled on a rolling basis and purged in the ordinary course.
11. How we protect data
- All data in transit is encrypted using HTTPS/TLS.
- Passwords are stored only as salted hashes; API keys are stored only as salted hashes.
- Authentication uses OAuth 2.0 and scoped API keys, and the Service is multi-tenant with per-workspace data isolation.
- Access to production systems is restricted to authorized personnel.
No method of transmission or storage is completely secure, but we work to protect your data using industry-standard measures.
12. Your rights
If you are in the European Economic Area or the United Kingdom (GDPR)
You have the right to:
- Access the personal data we hold about you.
- Rectify inaccurate or incomplete data.
- Erase your data (“right to be forgotten”).
- Restrict or object to certain processing.
- Receive your data in a portable format.
- Withdraw consent at any time, where processing is based on consent.
- Lodge a complaint with your local data protection supervisory authority.
If your personal data was uploaded to DripRaven by one of our customers (for example, if you are a contact in someone’s campaign), please direct your request to that customer, who is the controller of your data. We will assist them in responding.
If you are a California resident (CCPA/CPRA)
You have the right to:
- Know what personal information we collect and how we use and disclose it.
- Access and delete your personal information.
- Correct inaccurate personal information.
- Opt out of the “sale” or “sharing” of personal information. We do not sell your personal information and do not share it for cross-context behavioral advertising.
- Not be discriminated against for exercising your rights.
To exercise any of these rights, email privacy@dripraven.com. We will respond within the timeframes required by applicable law.
13. Children’s privacy
DripRaven is a business tool and is not directed to children. We do not knowingly collect personal data from anyone under the age of 16. If you believe a child has provided us with personal data, please contact us and we will delete it.
14. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, notify you. Your continued use of the Service after an update means you accept the revised policy.
15. Contact us
Helicon Solutions LLC — operator of DripRaven (United States)
Email: privacy@dripraven.com
Website: https://dripraven.com