Last updated: July 29, 2026
Privacy Policy
SimpleChat is an AI chatbot platform for businesses. This policy explains what data we collect when you use the platform, how we use it, and what rights you have.
Data we collect
Account data — the email address and organization name you provide at signup. Passwords are handled by Supabase Auth and never reach us in plain text.
Knowledge base — documents you upload to a bot (PDF, DOCX, text) and the vector indexes built from them.
Conversations — chatbot exchanges: questions, bot answers, timestamps, and an anonymous visitor identifier.
Leads — the name, phone number, or email a visitor voluntarily leaves through the widget.
Channel integrations — Telegram and Instagram tokens, stored encrypted in the database with AES-256-GCM.
Instagram and Meta Platform data
When you connect your Instagram account, we receive the following from Meta: your Instagram professional account ID, username, the text of direct messages (DMs) sent to your account, and the text of comments left on your posts.
We use this data for a single purpose — preparing and sending automated replies on your behalf. We do not sell data obtained from Meta, do not use it for advertising, and do not share it with third parties except as described in this policy.
You can disconnect the integration at any time from the dashboard. Once disconnected, the stored token is deleted and we stop receiving new data from your account.
How we use data
To provide the service: generating answers, displaying conversation history, computing analytics.
To track plan limits and handle billing.
For security: detecting abuse and rate-limiting requests.
We do not sell your personal data and do not share it with third parties for advertising.
Third-party services
We rely on the following services to operate the platform: OpenAI (answer generation and text embeddings), Supabase (database and authentication), Vercel (hosting), Upstash (rate limiting), Meta and Telegram (messaging channels).
Conversation text is sent to OpenAI to generate a reply. Data submitted through the OpenAI API is not used to train models.
Data retention
Data is kept for as long as your account is active. After an account deletion request, bots, documents, conversations, and integration tokens are permanently deleted within 30 days.
You can delete an individual document, bot, or channel integration from the dashboard at any time — this takes effect immediately.
Security
All secret tokens are encrypted in the database with AES-256-GCM. Data access is restricted by row-level security (RLS) policies based on organization membership. Traffic is transmitted over HTTPS.
No system is 100% secure. If we detect a breach, we will notify affected users.
Your rights
You have the right to access, correct, export, or request deletion of your data. Write to lutfulloasqarov9@gmail.com — we will address the request within 30 days.
Data deletion
To delete your account and all associated data, send a request to lutfulloasqarov9@gmail.com. You will receive a confirmation once the deletion is complete.
You may separately request deletion of data received through Instagram. We complete such requests within 30 days of receipt.
Cookies
We use only essential cookies: session storage (Supabase Auth) and your language and theme preferences. We do not use advertising or tracking cookies.
Children
The platform is not intended for individuals under 18, and we do not knowingly collect data from children.
Changes to this policy
This policy may be updated from time to time. We will announce material changes by email or in the platform. The date at the top of the page reflects the most recent revision.
Contact
If you have questions about this policy, contact us at lutfulloasqarov9@gmail.com.