Privacy Policy

Last updated September 9, 2026

Who we are

AIVAS helps businesses manage customer conversations, prepare content, and carry out work using AI assistants and connected services. This policy covers account holders, workspace users, and people whose information a business processes through the service. The data we process depends on the features and connections the business uses.

For customer information processed on a business's behalf, that business determines why the information is used and we process it on its instructions. We are responsible for our own use of account information to administer, support, and protect the service.

What we collect

  • Account data. The name and email address of the people who sign in to AIVAS, and the workspace they belong to.
  • Instagram connection data. Account identifiers and authorization information needed to connect your account. We do not receive your Instagram password.
  • Message content. Messages, replies, timestamps, and attachments processed through a connected account, including photos, videos, and voice notes.
  • Commenter data. Comments and commenter identifiers needed to send private replies when a business enables that feature.
  • Contact profile data. The name, Instagram handle and profile picture of the people who message a connected account, so the business can tell one conversation from another.
  • Workspace and connected-service data. Instructions, uploaded files, AI conversations, content drafts, and feedback you provide. Depending on the connections you enable, we also process email messages and attachments, calendar events and attendee details, form responses, and payment or subscription records needed for the work you request.
  • Usage and diagnostic data. Account and workspace identifiers, feature activity, and technical and delivery records used to understand usage, investigate problems, and prevent abuse. AI diagnostic records can include message content, generated responses, and information used to carry out a task.

How we use it

We use this information to provide the features you enable: manage conversations, generate replies and content, carry out authorized tasks, and show results to the people with access to that work. We also use account, billing, usage, and diagnostic information to administer subscriptions, provide support, investigate errors, and protect the service.

We do not sell personal data, we do not use message content for advertising, and we do not use one business's conversations to serve another business.

Automated messaging and AI processing

AI features send relevant messages, files, instructions, and task context to AI service providers to generate responses, process media, retrieve relevant information, and carry out the work you request. AI output can be inaccurate.

Who we share it with

We share information with the business and users authorized to access the relevant work, with connected services as needed for actions you authorize, and with providers that support the service:

  • Meta Platforms — connecting with Instagram to receive messages and send replies.
  • Hosting and storage providers — operating the service, storing information, and managing sign-in.
  • AI model & processing providers — response generation and audio processing.
  • Transactional communications — operational emails such as invitations and security alerts.
  • Analytics and diagnostics providers — usage measurement and troubleshooting, including AI diagnostic records that may contain message content and task results.
  • Payment and connected-service providers — billing and the email, calendar, forms, and publishing services you choose to connect.

We also disclose data where the law requires it. We do not otherwise share personal data with third parties.

Instagram data specifically

Data we obtain through the Instagram API is used solely to deliver the messaging features described here, in line with Meta's Platform Terms and Developer Policies. We request only the permissions those features need: reading the connected account's basic profile, receiving and sending messages for that account, and receiving comments so the assistant can send a private reply.

Disconnecting Instagram in AIVAS removes the saved connection credentials. Removing access in Instagram revokes the permission there; we remove the saved connection when we process Instagram's notification. Disconnecting does not itself delete conversation history. See the data deletion instructions below.

How long we keep it

We retain workspace information to provide the service and support the business's ongoing work. Retention depends on the type of information, the features used, deletion requests, and legal, accounting, and security requirements.

Stopping an assistant or disconnecting a service does not delete the workspace's records. To request deletion, use the instructions below. Some records may need to be retained to meet legal obligations or resolve disputes; backup copies may remain until they are removed through the applicable backup retention process.

Your rights and deleting your data

You can ask us for a copy of the personal data we hold about you, ask us to correct it, or ask us to delete it. If you messaged a business that uses AIVAS and want your conversation removed, ask that business, or write to us and we will pass the request on and act on it.

To delete Instagram data associated with you, follow the instructions on our data deletion page.

Security

We use access controls and technical safeguards designed to protect personal information and limit access to authorized users, personnel, and service providers. No system can guarantee absolute security.

Children

Workspace accounts are intended for adults aged 18 and older. People who contact a connected business may be younger, and their messages may be processed by the service. Businesses are responsible for using the service appropriately for their audience. Contact us if you believe a child's information has been processed inappropriately.

Changes

If we change this policy materially we will update the date at the top of this page and, where the change affects them, notify workspace administrators by email.

Contact

Questions or privacy requests: privacy@aivas.cloud.