FillNode Privacy Policy
What FillNode accesses in your mailbox, why it needs it, who it is shared with, and how to take it back.
1) About this policy 🧭
This policy covers FillNode, a customer-communication platform operated by Marinode AI Solutions LLP (“Marinode AI”, “we”, “us”), an Indian limited liability partnership. FillNode is available at fillnode.marinode-ai.com.
FillNode is a separate product from the Engine Room Ninja platform, which has its own privacy policy. If you are looking for Engine Room Ninja, this is not the right page.
2) Who this affects 👥
FillNode is sold to businesses (“Customers”). A Customer’s staff use FillNode to handle messages from their own customers (“End Users”). For End User data the Customer is the data controller and Marinode AI acts as a processor on the Customer’s instructions. End Users with a question about their data should contact the business they were dealing with; we will help that business respond.
3) What we access 📥
- Mailbox contents — message bodies, subjects, sender and recipient addresses, attachments and timestamps, so conversations can be shown and replied to.
- Mailbox identity — the name and address of the connected mailbox, to label the inbox.
- WhatsApp Business messages — where a Customer connects a WhatsApp Business number, the messages sent to and from it, the sender’s phone number and profile name, media, and delivery status. See section 4a.
- Agent accounts — name, email, password hash and activity, for sign-in, assignment and audit.
- Usage and error logs — for reliability and troubleshooting.
FillNode accesses only mailboxes a Customer explicitly connects. It does not scan other mailboxes, and it does not request access to your files, calendar or contacts.
4) Mail account permissions 🔑
When you connect a mailbox, FillNode requests the minimum needed to read and reply:
| Provider | Permission | Used for |
|---|---|---|
| Microsoft 365 / Outlook | IMAP.AccessAsUser.All | Read messages from the mailbox |
| Microsoft 365 / Outlook | SMTP.Send | Send replies from the mailbox |
| Microsoft 365 / Outlook | offline_access | Refresh the connection without asking you to sign in again |
| App-specific password | IMAP and SMTP access to the connected mailbox | |
| Other providers | IMAP and SMTP | Standard mailbox access |
These are the only Microsoft permissions FillNode requests. It does not request Mail.Read, Mail.ReadWrite, User.Read.All, directory access, files, calendar or contacts. FillNode reads mail over IMAP and sends over SMTP; it does not call the Microsoft Graph mail APIs.
4a) WhatsApp Business 💬
A Customer may connect a WhatsApp Business account to FillNode using Meta’s Embedded Signup flow. The Customer signs in with their own Meta account and selects the WhatsApp Business Account (WABA) and phone number they want to connect. Marinode AI never sees the Customer’s Meta password.
Once connected, FillNode receives from Meta:
- The WABA ID, phone number ID and display name of the connected number.
- An access token scoped to that WABA, stored encrypted (see section 7).
- Messages sent to and from that number — text, media, sender phone number, and delivery and read status — delivered by Meta webhooks so agents can read and reply in FillNode.
- Message template names, content and approval status, so agents can send templates.
Information FillNode receives from Meta (“Platform Data”) is used only to provide the messaging inbox to the Customer who connected the account. Specifically, Marinode AI does not sell Platform Data, does not use it for advertising or ad targeting, does not use it to build or enrich profiles for any purpose other than serving that Customer, and does not use it to train machine-learning models. Platform Data is not shared with any party other than the sub-processors listed in section 6.
WhatsApp permissions requested: whatsapp_business_management (read and manage the connected WABA and its templates) and whatsapp_business_messaging (send and receive messages on the connected number). A Customer can disconnect at any time — see section 8.
5) Artificial intelligence features 🤖
FillNode includes optional AI features (“Marina”) that summarise conversations, suggest replies and rewrite text. When a Customer’s agent uses one of these features, the relevant conversation text is sent to our AI provider for processing and the result is returned to the agent, who decides whether to use it.
We use a single AI provider: OpenAI, accessed through its paid business API in the United States. Under OpenAI’s API terms, content submitted through that API is not used to train its models. We do not use it to train any model of our own either.
Only the text needed for the requested action is sent — never a Customer’s whole conversation history or contact database. We do not retain the text sent for AI processing beyond returning the result to the agent.
These features run only when an agent triggers them. They are never applied automatically to incoming messages, including WhatsApp messages. A Customer who prefers that no conversation content is sent to an AI provider can ask us to disable these features for their account, and we will confirm in writing once done.
6) Sub-processors 🔗
| Provider | Purpose | Region |
|---|---|---|
| Hostinger International Limited | Application server, database and file storage | Mumbai, India |
| OpenAI | AI text processing, only when an agent triggers it (section 5) | United States |
| Google (Firebase Cloud Messaging) | Push notifications to the FillNode mobile app | United States |
| Apple (APNs) | Push notifications to iOS devices | United States |
| Google / Microsoft / Meta | Message transport for accounts a Customer connects | Global |
This list is current as of the effective date above. We update it here before adding a new sub-processor that handles Customer or End User data.
7) Storage and security 🔒
- Data is held in a PostgreSQL database on servers we control.
- Mailbox passwords and access tokens are encrypted at rest using application-level encryption.
- All connections use TLS — HTTPS for the application, TLS for IMAP and SMTP.
- Access to production systems is restricted to authorised Marinode AI personnel.
8) Retention, deletion and revoking access 🗑️
Conversation data is retained while a Customer’s account is active. On termination we delete or return Customer data within 60 days of a written request, except where law requires otherwise. Backups are overwritten on their normal cycle.
To disconnect a mailbox or account: in FillNode go to Settings → Inboxes and delete the inbox. This removes the stored credentials or tokens for that mailbox immediately.
To revoke access directly with the provider:
- Microsoft — myapps.microsoft.com, or your Microsoft account privacy settings
- Google — revoke the app password at myaccount.google.com/apppasswords
- Meta / WhatsApp — remove Marinode AI under Business Settings → Apps at business.facebook.com/settings, which immediately revokes our access to your WhatsApp Business Account
To request deletion of all your data, follow the instructions on our Data Deletion page, or email privacy@marinode-ai.com with the subject “FillNode data deletion”. We acknowledge within 7 days and complete verified requests within 30 days.
9) What we never do 🚫
- We do not sell personal data.
- We do not use mailbox or message contents for advertising.
- We do not use Customer or End User data to train our own or third-party AI models.
- We do not share data with anyone other than the sub-processors listed above, except where required by law.
10) Your rights ⚖️
Under India’s Digital Personal Data Protection Act, 2023 — and equivalent laws where they apply — you may request access to, correction of, or deletion of your personal data, and may withdraw consent at any time. Use the contact details below.
11) Changes 📝
Any change to this policy is posted on this page with an updated version and date. Material changes affecting how Customer data is processed are notified to Customers in advance.
12) Contact 📬
Entity: Marinode AI Solutions LLP
Name: Hashim C A
Email: privacy@marinode-ai.com
Phone: +91 8281 250 608
Address: Ratnam Arcade, ITI Road, Kazhakkoottam, Thiruvananthapuram 695 005, India
See also the FillNode Terms of Service.
