ChatCopilot ChatCopilot Beta
  • Features
  • Demo
  • Blog
  • FAQ
WhatsApp Login Start Free
Features Demo Blog FAQ WhatsApp community Login Start Free

Privacy Policy

Last Updated: 26 July 2026

At ChatCopilot ("ChatCopilot", "we," "our," "us") we treat the privacy and security of personal data as extremely important.

We process personal data in two roles: (1) for our own purposes, such as running our website and managing accounts; and (2) on behalf of our users ("Users", "You", "Your", "Facebook Page Business Owners", "Business Owners", "Business", "Account Holders") who use the ChatCopilot service (the "Service", any product or service we provide) to store their business information and automate customer chats, in line with applicable data protection laws. In the second role we act only on our users' instructions and never use their data for any purpose other than providing the Service. We never sell any data and never share it with third parties for advertising, marketing, or profiling purposes.

This Privacy Policy explains what personal data we process, why, how long we keep it, who we share it with, and how you can control it. It covers:

  • our Users (defined above);
  • the people who message our Users (the "End Customers", "Customers", or "Users' Customers");
  • website visitors.

1. Information We Collect

1.1 From Users

When you sign up and connect your channels, we collect:

DataSourceWhy we collect
Name, email addressManual Input or Facebook OAuth (public_profile, email permissions) or Google OAuthCreate your account, send login/verification emails
Facebook User IDFacebook OAuthIdentify which Facebook account authorized the connection
List of Facebook Pages you managepages_show_list permissionLet you choose which Page to connect to ChatCopilot
Business Manager Pages (if applicable)business_management permissionSupport businesses that manage Pages via Meta Business Manager
Page access tokenIssued after you connect a PageSend/receive messages on your behalf via that Page
Google Calendar OAuth tokenGoogle OAuth (if you connect Google Calendar)Read your availability and create booking events
Business details you provideManual entry during onboardingConfigure your AI knowledge (catalog, hours, services)
Order and catalog dataManual entry / file uploadPower the sales, appointment, and deal closing styles

1.2 From End Customers

When someone messages a business that uses ChatCopilot, we collect:

DataSourceWhy we collect
Facebook Messenger user IDMessaging platformIdentify and reply to the correct conversation
NameMessenger Graph API (name, first_name, last_name fields only)Personalize replies and show the business who they're talking to
Message contentSent directly by the customerUnderstand and respond to the customer's request
Order details (items, delivery address, phone number)Provided by the customer during checkoutFulfill and deliver their order
Appointment details (date, time, address, email, phone number)Provided by the customer during bookingBook their appointment and send confirmations

2. Permissions We Request

2.1 Facebook Integration Permissions

Our app requests exactly these Meta permissions, and no others:

  1. pages_messaging: receive and send messages through your connected Page.
  2. pages_show_list: show you the list of Pages you manage so you can pick one to connect.
  3. pages_manage_metadata: subscribe your Page to message webhooks so we can receive customer messages in real time. This does not grant access to Page content or posting.
  4. business_management: list Pages you manage through Meta Business Manager, for businesses that use that structure.
  5. public_profile: retrieve your basic public profile info during sign-in.
  6. email: retrieve your email address during sign-in, to create and secure your account.

2.2 Google Calendar Integration Permissions

If you connect Google Calendar, our app requests exactly these scopes, and no others:

  1. calendar.calendarlist.readonly: list the calendars in your Google account so you can choose which one to connect.
  2. calendar.events: read your event start/end times and titles to check availability, and create or cancel appointment events on your behalf.
  3. userinfo.email and openid: identify your Google account during sign-in.

3. How We Use Your Information

  • Generate and send replies to customer messages.
  • Take and track orders, and hand off delivery details to your courier partner.
  • Book and manage appointments, including creating Google Calendar events.
  • Communicate with business owners about their account (billing, support, product updates).

Messaging data received via Facebook Messenger is used only to support the messaging functionality above, never used for advertising, never to build profiles of customers beyond what's needed for providing the service, and never combined with data from other apps or advertisers.

4. AI Privacy and Security

We never share your personal or credential data with any AI model. To generate replies, we send our AI provider (via OpenRouter gateway) only what's needed: your business information which you manually uploaded from the ChatCopilot web dashboard and the customer's message content. For integrations like Google Calendar and Pathao, the AI receives only the minimal fields needed to give a personalized reply, not your full records.

For Google Calendar, our AI agent only uses the start time, end time, and title of your calendar events to check availability and avoid double-booking. It does not read or use attendees, descriptions, or location, and never accesses your Google account identity.

We enforce strict AI privacy

As of July 2026, all model calls route through an OpenRouter organization account configured for account level Zero Data Retention and No Data Training (opt-out) privacy setting. These settings are enforced at the routing layer: any model or provider on OpenRouter that does not explicitly comply with these privacy settings and terms is automatically excluded from receiving our traffic. No data is retained by any AI model provider and it is never used to train, fine-tune, or improve any AI/ML model, ours or theirs. Please check the OpenRouter Provider Policies for more information.

Limited Use Compliance Statement

The use of information received from Google Workspace scopes will adhere to the Google User Data Policy, including the Limited Use requirements. We do not use Google Workspace data to develop, improve, or train AI/ML models. Also no Google user data, in any form, is ever transferred to OpenRouter or any AI model provider for training purposes.

5. Data Retention and Deletion

Your data on our servers. We retain your data for as long as your account or connected channel is active.

  • Google Calendar: deleting your calendar integration in the Dashboard immediately removes your Google access tokens and all calendar data from our database. You can also revoke access anytime from your Google Security Settings.
  • Facebook Page and business profile data: email [email protected] with a deletion request; we verify your identity and delete all associated personal data within 30 days, with a confirmation email once complete. Full steps are on our Data Deletion Instructions page.

Your Rights and Data Deletion

You can request access to, correction of, or deletion of your personal data at any time. To do so, contact us at:

  • Email: [email protected]

We will process deletion requests within 30 days and confirm once completed. Deleting your data will disconnect any connected Facebook Page and Google Calendar, and stop the AI agent from responding on your behalf.

6. Third-Party Platform Policies

Our app operates on Facebook Messenger, which is subject to Meta's Platform Policy. Users may also manage their data and app permissions directly through their Facebook App Settings.

Google Calendar access is subject to the Google API Services User Data Policy, including the Limited Use requirements described in Section 4. User can also revoke access anytime from Google Security Settings.

7. Security

We use industry-standard measures: encryption in transit (HTTPS/TLS), encrypted storage of access tokens, and access controls to protect your data from unauthorized access, disclosure, or destruction.

8. Changes to This Policy

We may update this policy from time to time. Material changes will be reflected by updating the "Last Updated" date at the top of this page. We will email you for major changes to our privacy policy.

9. Contact Us

Questions about this policy or our data practices:

  • Email: [email protected]
ChatCopilot ChatCopilot

The AI teammate for Facebook-first businesses. It is your salesman, receptionist or personal secretary. Works 24/7, so you never miss a client or a sale.

Product

  • Features
  • Demo
  • Blog

Company

  • [email protected]
  • WhatsApp community
  • Login

Legal

  • Privacy Policy
  • Data Deletion

© 2026 ChatCopilot.

Built in Bangladesh