Privacy Policy
At ChatCopilot ("ChatCopilot", "we," "our," "us") we treat the privacy and security of personal data as extremely important.
We process personal data in two roles: (1) for our own purposes, such as running our website and managing accounts; and (2) on behalf of our users ("Users", "You", "Your", "Facebook Page Business Owners", "Business Owners", "Business", "Account Holders") who use the ChatCopilot service (the "Service", any product or service we provide) to store their business information and automate customer chats, in line with applicable data protection laws. In the second role we act only on our users' instructions and never use their data for any purpose other than providing the Service. We never sell any data and never share it with third parties for advertising, marketing, or profiling purposes.
This Privacy Policy explains what personal data we process, why, how long we keep it, who we share it with, and how you can control it. It covers:
- our Users (defined above);
- the people who message our Users (the "End Customers", "Customers", or "Users' Customers");
- website visitors.
1. Information We Collect
1.1 From Users
When you sign up and connect your channels, we collect:
| Data | Source | Why we collect |
|---|---|---|
| Name, email address | Manual Input or Facebook OAuth (public_profile, email permissions) or Google OAuth | Create your account, send login/verification emails |
| Facebook User ID | Facebook OAuth | Identify which Facebook account authorized the connection |
| List of Facebook Pages you manage | pages_show_list permission | Let you choose which Page to connect to ChatCopilot |
| Business Manager Pages (if applicable) | business_management permission | Support businesses that manage Pages via Meta Business Manager |
| Page access token | Issued after you connect a Page | Send/receive messages on your behalf via that Page |
| Google Calendar OAuth token | Google OAuth (if you connect Google Calendar) | Read your availability and create booking events |
| Business details you provide | Manual entry during onboarding | Configure your AI knowledge (catalog, hours, services) |
| Order and catalog data | Manual entry / file upload | Power the sales, appointment, and deal closing styles |
1.2 From End Customers
When someone messages a business that uses ChatCopilot, we collect:
| Data | Source | Why we collect |
|---|---|---|
| Facebook Messenger user ID | Messaging platform | Identify and reply to the correct conversation |
| Name | Messenger Graph API (name, first_name, last_name fields only) | Personalize replies and show the business who they're talking to |
| Message content | Sent directly by the customer | Understand and respond to the customer's request |
| Order details (items, delivery address, phone number) | Provided by the customer during checkout | Fulfill and deliver their order |
| Appointment details (date, time, address, email, phone number) | Provided by the customer during booking | Book their appointment and send confirmations |
2. Permissions We Request
2.1 Facebook Integration Permissions
Our app requests exactly these Meta permissions, and no others:
pages_messaging: receive and send messages through your connected Page.pages_show_list: show you the list of Pages you manage so you can pick one to connect.pages_manage_metadata: subscribe your Page to message webhooks so we can receive customer messages in real time. This does not grant access to Page content or posting.business_management: list Pages you manage through Meta Business Manager, for businesses that use that structure.public_profile: retrieve your basic public profile info during sign-in.email: retrieve your email address during sign-in, to create and secure your account.
2.2 Google Calendar Integration Permissions
If you connect Google Calendar, our app requests exactly these scopes, and no others:
calendar.calendarlist.readonly: list the calendars in your Google account so you can choose which one to connect.calendar.events: read your event start/end times and titles to check availability, and create or cancel appointment events on your behalf.userinfo.emailandopenid: identify your Google account during sign-in.
3. How We Use Your Information
- Generate and send replies to customer messages.
- Take and track orders, and hand off delivery details to your courier partner.
- Book and manage appointments, including creating Google Calendar events.
- Communicate with business owners about their account (billing, support, product updates).
Messaging data received via Facebook Messenger is used only to support the messaging functionality above, never used for advertising, never to build profiles of customers beyond what's needed for providing the service, and never combined with data from other apps or advertisers.
4. AI Privacy and Security
We never share your personal or credential data with any AI model. To generate replies, we send our AI provider (via OpenRouter gateway) only what's needed: your business information which you manually uploaded from the ChatCopilot web dashboard and the customer's message content. For integrations like Google Calendar and Pathao, the AI receives only the minimal fields needed to give a personalized reply, not your full records.
For Google Calendar, our AI agent only uses the start time, end time, and title of your calendar events to check availability and avoid double-booking. It does not read or use attendees, descriptions, or location, and never accesses your Google account identity.
We enforce strict AI privacy
As of July 2026, all model calls route through an OpenRouter organization account configured for account level Zero Data Retention and No Data Training (opt-out) privacy setting. These settings are enforced at the routing layer: any model or provider on OpenRouter that does not explicitly comply with these privacy settings and terms is automatically excluded from receiving our traffic. No data is retained by any AI model provider and it is never used to train, fine-tune, or improve any AI/ML model, ours or theirs. Please check the OpenRouter Provider Policies for more information.
Limited Use Compliance Statement
The use of information received from Google Workspace scopes will adhere to the Google User Data Policy, including the Limited Use requirements. We do not use Google Workspace data to develop, improve, or train AI/ML models. Also no Google user data, in any form, is ever transferred to OpenRouter or any AI model provider for training purposes.
5. Data Retention and Deletion
Your data on our servers. We retain your data for as long as your account or connected channel is active.
- Google Calendar: deleting your calendar integration in the Dashboard immediately removes your Google access tokens and all calendar data from our database. You can also revoke access anytime from your Google Security Settings.
- Facebook Page and business profile data: email [email protected] with a deletion request; we verify your identity and delete all associated personal data within 30 days, with a confirmation email once complete. Full steps are on our Data Deletion Instructions page.
Your Rights and Data Deletion
You can request access to, correction of, or deletion of your personal data at any time. To do so, contact us at:
- Email: [email protected]
We will process deletion requests within 30 days and confirm once completed. Deleting your data will disconnect any connected Facebook Page and Google Calendar, and stop the AI agent from responding on your behalf.
6. Third-Party Platform Policies
Our app operates on Facebook Messenger, which is subject to Meta's Platform Policy. Users may also manage their data and app permissions directly through their Facebook App Settings.
Google Calendar access is subject to the Google API Services User Data Policy, including the Limited Use requirements described in Section 4. User can also revoke access anytime from Google Security Settings.
7. Security
We use industry-standard measures: encryption in transit (HTTPS/TLS), encrypted storage of access tokens, and access controls to protect your data from unauthorized access, disclosure, or destruction.
8. Changes to This Policy
We may update this policy from time to time. Material changes will be reflected by updating the "Last Updated" date at the top of this page. We will email you for major changes to our privacy policy.
9. Contact Us
Questions about this policy or our data practices:
- Email: [email protected]