Privacy Policy
Last updated: July 18, 2026
Autologic ("we", "our", "us") operates an AI-powered chatbot platform at autologic-chatbot.vercel.app. This Privacy Policy explains how we collect, use, store, and protect data.
1. Information We Collect
From clients (business owners): Email and business name at registration. Facebook, Instagram, and WhatsApp access tokens and account IDs when channels are connected. Google Calendar OAuth tokens (access token and refresh token) when a client connects their Google Calendar — used exclusively to check availability and create meeting events on that client's own calendar. Business logo, product catalogue, and knowledge base documents uploaded by the client.
From end users (customers): Messages sent through connected channels. Sender ID and public profile name as provided by the respective platform. Order or booking information provided during a conversation.
2. Google Calendar Data — Limited Use Disclosure
Autologic's use of data obtained from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
When a client connects Google Calendar, we use that access only to:
- Check the client's calendar availability (free/busy) when a customer requests a meeting.
- Create calendar events with a Google Meet link on the client's behalf when a booking is confirmed.
- Send the Google Meet link to the customer via the connected messaging channel.
We do not read, store, share, or use Google Calendar data for any purpose beyond the above. We do not use it for advertising, profiling, or any secondary purpose. When a client disconnects Google Calendar, all stored OAuth tokens are immediately deleted.
3. How We Use Data
To deliver AI-generated replies to customer messages on behalf of connected businesses. To display conversations and analytics in the client dashboard. To store orders and bookings created during customer conversations. We do not sell personal data. We do not use customer messages or calendar data for advertising.
4. Data Storage and Security
All data is stored in Supabase (PostgreSQL) on AWS ap-southeast-2. Row-Level Security (RLS) policies ensure each client's data is fully isolated. Access tokens and OAuth credentials are stored server-side only and never exposed to browsers or other clients. HTTPS is enforced for all connections.
5. Data Sharing
Customer messages are processed by Google Gemini API to generate AI replies. Meta Graph API (Facebook, Instagram, WhatsApp) is used to send and receive messages. Google Calendar API is used to create events and check availability. Supabase is used for database and file storage. No other third parties receive personal data.
6. Data Retention and Deletion
Clients can delete conversations and files from the dashboard at any time. Disconnecting a channel immediately stops all data processing for that channel. To request full deletion of your account and all associated data, email nahidafzal97@gmail.com. All requests are honored within 30 days.
7. Facebook and Instagram Data Deletion
If you remove our app from Facebook or Instagram settings, we receive an automated deletion callback and delete all associated data automatically within 24 hours.
8. Children's Privacy
Our platform is intended for business use only and is not directed at children under 13. We do not knowingly collect personal data from children.
9. Changes to This Policy
We may update this Privacy Policy from time to time. The date at the top reflects the most recent revision. Continued use after changes constitutes acceptance.
10. Contact
Autologic · Kandirpar, Cumilla, Bangladesh
Email: nahidafzal97@gmail.com