Privacy Policy

Last updated Sep 24, 2026

What we collect

Account data: name, email, password hash, language, and workspace details. Connected-account data: the Page, Instagram account, WhatsApp number, or bot you connect, and the access tokens Meta or Telegram issue for it. Conversation data: messages, comments, and contact profiles that reach your workspace through connected channels. Usage data: logs of automated actions, sign-ins, and technical events needed to run and secure the service.

How we use it

To deliver the service you signed up for: receiving and sending messages, running your automations, showing conversations to your team, and enforcing plan limits. To keep the platform secure and reliable. To send transactional emails such as invitations and trial notices. We do not sell personal data and we do not use your customers' conversations to train AI models.

Data from Meta and Telegram

Access tokens are stored encrypted and used only to call the provider APIs on behalf of your workspace. We request the minimum permissions needed: reading the Pages you manage, sending and receiving messages, and reading, replying to, and hiding comments. Disconnecting an account revokes our webhook subscription and deletes the stored token immediately. You can also remove the app from your Facebook Business settings.

AI features

When you enable AI agents, message text and the knowledge you upload are sent to the model provider you selected (for example OpenAI or Anthropic) to generate replies. We send only what is necessary for the request.

Sharing

We share data only with the providers needed to operate the service: hosting, email delivery, payment processing, the messaging platforms you connect, and the AI providers you enable. Each acts under a contract limiting use to our instructions.

Retention and deletion

Workspace data is kept while the workspace is active. Deleting a workspace, or asking us to, removes its data within a reasonable period. To request deletion of data we hold about you, use the contact page; we respond within 30 days.

Security

Data is encrypted in transit and credentials are encrypted at rest. Access inside the platform is limited by role, and every administrative action is logged.

Your rights

You can access, correct, export, or delete your data. Business customers remain responsible for honouring their own customers' rights and for having a lawful basis to message them.

Changes and contact

We will update this page when our practices change. Questions and requests go through the contact page.

Questions about this page? Contact us