Privacy Policy
Effective date: September 15, 2026 · Applies to the Lovely platform at app.lovely.skodedigital.tech
Lovely ("we", "us", "our") provides AI-powered customer-support bots for Facebook Messenger and WhatsApp. This policy explains what data we collect, why, how long we keep it, and how you can delete it.
1. Who we are
Lovely is a software platform operated from Bangladesh. For any privacy question or request, contact us at hello@skodedigital.tech.
2. What data we collect
- Account data — your name, email address and password (stored securely by Supabase authentication) when you create an account.
- Business configuration — your bot persona, business name, knowledge-base content you add, and connection credentials (page access tokens, app secrets, API keys) you provide to connect Messenger or WhatsApp. Credentials are stored encrypted (AES-256).
- Conversation data — messages your customers send to your connected Messenger/WhatsApp number, the bot's replies, and basic identifiers (Messenger page-scoped ID, WhatsApp phone number) needed to reply.
- Billing data — your plan, payment records and (for manual payments) the transaction ID and sender number you submit. Card payments are processed by Lemon Squeezy; we never see or store your card details.
- Usage data — message counts per workspace, used to enforce plan limits.
3. What we do NOT do
- We do not sell your data to anyone.
- We do not use your customers' conversations for advertising.
- We do not read your knowledge base or conversations except to operate the service, debug an issue you report, or as required by law.
3. Third parties we rely on
- Meta Platforms — Messenger and WhatsApp message delivery (you connect your own page/number).
- Groq / OpenAI — the AI model that drafts replies from your knowledge base. Your knowledge content and customer messages are processed by the AI provider to generate each reply.
- Hugging Face — converts knowledge text into embeddings for search.
- Supabase — hosts our database (your configuration and knowledge base).
- Lemon Squeezy — card payment processing for international customers.
Each of these processes data under its own terms and privacy policy. We only send them what is necessary to run the bot.
4. Your customers' data
When a customer messages a Lovely-powered channel, their message is used (a) to generate the reply and (b) kept as conversation history so the bot remembers the chat. The business owner (our customer) is the controller of that conversation data; Lovely processes it on their behalf.
5. How long we keep data
- Conversation messages: kept while your account is active; deleted when you delete the conversation or your workspace.
- Knowledge base: kept until you delete it or your workspace.
- Account data: kept until you request deletion (see below), then removed within 30 days.
6. Your rights & data deletion
You can delete most data yourself anytime:
- Knowledge base — dashboard → Knowledge → delete individual items or "Delete all".
- Connections — dashboard → Settings → remove credentials / disconnect.
- Entire account — see our data deletion page for the full account-deletion request flow.
If you are an end customer of one of our business users and want your conversation deleted, contact that business — or contact us at hello@skodedigital.tech and we will forward the request to them and assist.
7. Security
- All traffic is encrypted (HTTPS).
- Integration secrets are stored AES-256 encrypted; only our server can decrypt them at the moment of use.
- Each customer's data is isolated at the database level (row-level security) — no other customer, and no unauthorized person, can read it.
- Access by our staff is limited to what is needed to run and support the service.
8. Changes to this policy
If we change this policy materially, we will notify account holders by email or a dashboard notice before the change takes effect.
Questions or deletion requests:
Email hello@skodedigital.tech — we reply within 3 business days.