6. Messaging Channels
Businesses may connect their Facebook Page, Instagram professional account, or WhatsApp Business number to the Service. This section describes how data from those channels is handled. As with the chat widget, we act as a data processor for your customers' messages; you are the data controller.
6.1 What we receive and store
When a channel is connected, Meta delivers messages sent to your connected account to us via webhook. For each message we store:
- The message text, the sender's platform identifier and display name, and timestamps
- The channel it arrived on, and which business account it belongs to
- The original webhook payload as received from Meta, kept temporarily for diagnostic purposes
- One small record per conversation: whether automated replies are paused for it, and when the automated-assistant notice was last sent
To connect and operate a channel we also store the connected account's identifiers and an access token issued by Meta. Tokens are encrypted at rest (AES-GCM), decrypted only in our backend to call Meta's APIs, and are never sent to any browser.
6.2 Assisted (automated) replies
Channel messages are shown in your message queue, where your staff read and reply to them. You may optionally enable AI auto-reply. When it is enabled:
- Recent messages from the conversation are sent to the AI provider configured for your account (by default Anthropic, in the US; the business may instead select Google, MiniMax or DeepSeek — see Section 4) in order to draft the reply. This happens only while auto-reply is enabled, and only for the conversation being answered.
- The first automated reply in any conversation carries a visible notice that it is automated.
- Automated replies are drafted only from your business profile and the FAQ answers you have written. They are plain text and cannot take any action.
- If a customer asks for a person, they receive one short acknowledgement and the conversation is handed to your staff. If a customer asks us to stop, nothing further is sent. In both cases automated replies stay paused for that conversation until a member of your staff resumes them.
6.3 Retention and deletion for channel data
- Raw webhook payloads are erased 30 days after the message arrives; the parsed message remains.
- Messages are deleted 12 months after they are received. Both windows are enforced by a scheduled daily job.
- Per-conversation state (the paused flag and the disclosure timestamp) is kept for the life of your account. This is deliberate: it is the record that a person asked not to receive automated replies, and deleting it would cause those replies to resume.
- Disconnecting a channel deletes its stored access token immediately.
- Closing your account deletes all associated messages, conversation records and tokens.
6.4 Meta platform data
Data received from Meta's platforms is used only to provide the messaging features described above, in accordance with the Meta Platform Terms and Meta's Developer Policies. We do not sell it, use it for advertising, or use it to train AI models.