Legal Document

Privacy Policy

Last updated: August 3, 2026

Introduction

Overview

Welcome to our platform. This Privacy Policy explains how we collect, use, store, and protect information when you use our AI-powered customer engagement platform ("Service"). The Service enables businesses to deploy AI agents on their websites and social media accounts, handle visitor interactions, provide

By using the Service, you agree to the collection and use of information in accordance with this policy. This policy applies to:

  • Platform Users Businesses and developers who register and use our dashboard to configure and deploy AI agents.

Section 01

Information We Collect

We collect different categories of information depending on your role and how you interact with the Service.

From Platform Users (Businesses):

  • Account Information Name, email address, and profile picture collected via OAuth authentication (Google, Facebook).
  • Project & Configuration Data Chatbot settings, business mode preferences, widget customization, and linked website URLs provided for crawling.
  • Knowledge Base Content Text, documents, and URLs you upload or provide to train your AI agent, stored securely in a vector database.
  • Social Media Integration Data Access tokens and account identifiers for connected Facebook and Instagram Business accounts, used solely to route and respond to messages via approved Meta APIs.
  • Billing Information Subscription tier and payment history processed via Paddle. We do not store raw card details.
  • Usage & Analytics Data Session data, feature interactions, and error logs used to maintain and improve the platform.

Section 02

How We Use Your Information

We use collected information strictly to operate and improve the Service:

  • Authentication To verify your identity and maintain secure access to the platform.
  • AI Agent Operation To power chatbot responses, guided walkthroughs, and autonomous task execution on your website.
  • Social Media Automation To respond to incoming messages on connected Facebook and Instagram Business accounts using AI, on behalf of the platform user.
  • Guided Assistance To deliver text guides, visual (DOM-based) guides, and AI-driven task automation to end visitors.
  • Platform Improvement To analyze usage patterns, fix issues, and develop new features.
  • Billing Management To process payments, manage subscriptions, and handle plan upgrades via Paddle.
  • Communication To send service-related notifications, policy updates, and support responses.

Section 04

DOM Scanning & Website Crawling

To enable the AI-guided assistance features (text guide, visual guide, and AI agent task execution), our SDK performs automated analysis of the website it is integrated into.

How it works:

  • Initial Crawl When a platform user provides their website URL and adds the SDK, we initiate a crawl of the site to index pages and understand structure.
  • DOM Scanning When any visitor opens a page on the website, the SDK scans the page's Document Object Model (DOM) to identify interactive elements — specifically buttons, links, input fields, and other actionable components. Static or decorative elements are not stored.
  • Continuous Scanning DOM scanning is persistently enabled. New or previously unvisited pages are scanned upon first visitor access. Pages already scanned are re-evaluated if changes are detected, ensuring the AI guide remains accurate.
  • Data Stored Only interactive element metadata (element type, position, labels, and identifiers) is stored — not full page HTML, text content, images, or user-generated data on those pages.

DOM scanning is performed to power on-screen guidance features only. The data is not used for advertising, profiling, or any purpose outside of delivering the Service.


Section 05

Social Media Integration

Platform users may connect their Facebook and Instagram Business accounts to our Service. When connected, all incoming messages to those accounts are processed and responded to by the AI agent automatically.

  • Scope of Access We request only the permissions necessary to read incoming messages and send replies via the Meta Business API. We do not access personal timelines, friends lists, or ad accounts.
  • Message Data Messages from followers or customers sent to the connected business account are processed by the AI. Message content is used to generate a relevant reply and may be stored for conversation history and quality review.
  • No Cross-Account Data Use Message data from one business account is never used to train or influence responses for another user's account.
  • Disconnection Users can disconnect their Facebook or Instagram accounts at any time from the platform dashboard. Upon disconnection, we cease processing new messages from those accounts.

Section 07

AI Processing

Our Service uses AI models to generate responses, perform task guidance, and automate interactions. We use third-party AI providers (including Google Gemini) to process queries.

  • Data Sent to AI Providers User queries, conversation context, and knowledge base content may be sent to AI providers for inference. We do not send unnecessary personal data beyond what is needed to generate a relevant response.
  • No Training on Your Data We do not use your proprietary knowledge base data or visitor conversations to train shared AI models.
  • Retention AI inference requests may be temporarily logged for debugging and quality purposes, subject to our standard data retention policy.

Section 08

Payments & Billing

Subscription payments are processed by Paddle, our authorized Merchant of Record. All transactions are denominated in USD.

  • Payment Data Credit card details, billing address, and transaction information are collected and stored by Paddle, not by us. We receive only a tokenized reference and subscription status.
  • Paddle as Data Controller For payment-related data, Paddle acts as an independent data controller. Please review Paddle's Privacy Policy for details.
  • Invoices & Records We retain transaction records (plan, amount, date) for accounting and legal compliance purposes.

Section 09

Data Storage & Security

We implement industry-standard security measures to protect your data at rest and in transit:

  • Encryption All data transmitted between your browser and our servers is encrypted via TLS. Sensitive data at rest is encrypted using AES-256.
  • Vector Database Knowledge base content is stored in Pinecone, a secure vector database optimized for AI retrieval.
  • Access Controls Access to production systems is restricted to authorized personnel only, using role-based access controls and multi-factor authentication.
  • Data Retention Conversation logs and visitor session data are retained for up to 12 months unless the platform user requests earlier deletion. Account data is retained for the duration of the subscription and deleted within 90 days of account termination.
  • Breach Notification In the event of a data breach that affects your personal information, we will notify you as required by applicable law.

Section 10

Sharing of Information

We do not sell, rent, or trade your personal information. Data may be shared only in the following limited circumstances:

  • Service Providers Trusted vendors (cloud hosting, database, analytics) who process data on our behalf under confidentiality agreements.
  • Meta APIs Facebook and Instagram message data is exchanged with Meta's Business APIs solely to enable social media AI agent functionality.
  • AI Providers Query content sent to AI inference providers (e.g., Google Gemini) to generate responses.
  • Paddle Billing and subscription data processed by Paddle as our payment infrastructure provider.
  • Legal Requirements We may disclose data when required by law, court order, or to protect the rights and safety of our users or the public.

Section 11

Your Rights

Depending on your location, you may have the following rights regarding your personal data:

  • Access Request a copy of the personal data we hold about you.
  • Correction Update or correct inaccurate information via your account settings.
  • Deletion Request deletion of your account and associated data by contacting our support team.
  • Portability Request an export of your data in a machine-readable format.
  • Withdrawal of Consent Disconnect social media integrations or revoke permissions at any time from your dashboard.
  • Objection Object to certain processing activities, including analytics, where applicable.

To exercise any of these rights, contact us at support@botversion.com. We will respond within 30 days.


Section 12

Third-Party Services

Our platform integrates with several third-party services. Each has its own privacy policy governing their data practices:

We encourage you to review these policies to understand how each provider handles your data.


Section 13

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will:

  • Update the Date Revise the "Last updated" date at the top of this page.
  • Notify Users Send an email notification to registered platform users for significant changes.
  • In-App Notice Display a prominent notice in the platform dashboard when you next log in.

Continued use of the Service after changes take effect constitutes your acceptance of the revised policy.


Section 14

Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or how your data is handled, please reach out to us:

  • Email support@botversion.com
  • Response Time We aim to respond to all privacy-related inquiries within 5 business days.

For data deletion requests or to exercise your rights under GDPR, CCPA, or other applicable laws, please email us with the subject line: "Privacy Request".