Legal
Privacy Policy
Sendsar is a headless chat API. This page explains what we collect, why we collect it, and how we handle data when you use our console and APIs.
Last updated 2026-07-21 · Operated by Noeurn Neang
1. Who we are
Sendsar is operated by Noeurn Neang, an individual developer based in Cambodia. There is no separate company entity behind this service today.
Contact for privacy questions: support@sendsar.com.
2. Your role vs our role (important for APIs)
If you integrate Sendsar into your app or website, you decide what end-user content is sent to us (messages, profiles you sync, files, call metadata). You are responsible for your product’s privacy notice, consent, and lawful use of that content.
We process that content to run the messaging, presence, upload, webhook, and call features you enable. We do not use your end users’ chat content to train public AI models or to sell advertising.
3. What we collect
Console / account data (when you sign in with Google or GitHub): name, email, avatar URL, OAuth provider IDs, workspace settings, API keys (hashed/stored for auth), plan and usage metrics, webhook URLs, and support messages you send us.
Service / API data (from your apps via gateway APIs): tenant and app identifiers, your end-user IDs and optional display profiles, rooms/channels, messages, reactions, device tokens for push, upload metadata and files, webhook delivery logs, and call/session metadata when voice or video is enabled (via LiveKit or similar infrastructure).
Technical data: IP addresses, user-agent, request logs, error logs, and approximate usage counters needed to operate, secure, and bill the service.
4. Why we use data
- Provide and improve the Sendsar console, APIs, and real-time features
- Authenticate API keys and protect accounts from abuse
- Meter usage, enforce plan limits, and support billing conversations
- Deliver webhooks and diagnose delivery failures
- Respond to support requests and security incidents
- Comply with law when we are legally required to
5. Where data is stored
Primary application and database hosting currently runs in Singapore (Contabo). File uploads are stored using Cloudflare R2 (S3-compatible object storage).
We also use standard infrastructure providers needed to run the product (for example OAuth sign-in, email/Telegram for support, and call media providers when you enable calls). Those providers process data only as needed to provide their service.
7. Retention
Account and workspace data is kept while your account is active. If you ask us to delete your account, we will delete or anonymize console data within a reasonable time, except records we must keep for security, fraud prevention, or legal reasons.
Chat content and uploads stored for your apps follow your integration and any deletion APIs/tools we provide. You are responsible for deleting end-user data when your users request it under your own policies.
8. Security
We use industry-common practices such as TLS in transit, access controls, hashed API secrets where applicable, and least-privilege access to production systems. No method of transmission or storage is 100% secure; please protect your API keys and rotate them if exposed.
9. Your choices
You can update workspace settings in the console, rotate API keys, and contact us to request access, correction, or deletion of your account data. For end-user requests about content inside your product, handle those in your app first — we can help delete tenant data when you ask.
10. Children
The Sendsar developer console is intended for people 18 or older (or the age of majority where you live). You are responsible for ensuring your own product’s use of Sendsar complies with child-privacy rules that apply to your end users.
11. Changes
We may update this Privacy Policy as the product grows. We will change the “Last updated” date at the top of this page. Continued use of Sendsar after an update means you accept the revised policy.
Questions? support@sendsar.com · Privacy · Terms