InbixyAI Sales Reply Assistant

Privacy Policy

Last updated: 28 July 2026

Inbixy connects to a business's Facebook Page and replies to customer messages automatically using AI. This policy explains exactly what data that involves, who it is shared with, and how to delete it.

Who operates Inbixy

Inbixy is operated by Animesh, an individual developer (sole proprietor). There is no registered company entity behind the service at this time.

Contact for any privacy question or request: animesh@classtablet.com

Inbixy is not affiliated with, endorsed by, or sponsored by Meta Platforms, Inc.

Who is responsible for what

When a business connects its Facebook Page, that business decides why and how its customers' messages are processed — it is the data controller for those conversations. Inbixy acts as the processor, handling the data on the business's instructions.

If you messaged a business on Messenger and want your conversation removed, the fastest route is to contact that business directly. You may also email us and we will act on it.

Data we collect

Your Inbixy account. Name, email address, and a hashed password. For each active login session we also store the IP address and browser user agent, which we use to keep sessions secure.

Business information you enter. Business name and description, support hours, payment, delivery and return policies, product listings and their variants, and knowledge snippets. This is the material the AI uses to answer your customers.

Data received from Facebook. When you connect a Page we receive and store:

  • The Page ID and Page name.
  • A Page access token, which lets us send replies on the Page's behalf. It is encrypted at rest using AES-256-GCM.
  • The app-scoped user ID of the Facebook account that authorised the connection.
  • For each customer who messages the Page: their page-scoped ID (PSID), the text of their messages, timestamps, and Meta's message identifiers.
  • Messages Inbixy sends back, so the conversation history stays complete.

We do not collect payment card details, and we do not run advertising or analytics trackers.

How we use it

  • To generate and send automated replies to customers who message your Page.
  • To show you your conversations, connection status, and usage in the dashboard.
  • To enforce fair-use and rate limits so one account cannot degrade the service for others.
  • To debug failures and keep the service running.

We do not sell personal data, and we do not use your conversations to build advertising profiles.

Who we share it with

Inbixy relies on the following third-party services (subprocessors) to function:

  • Google (Gemini API). To generate each reply, the customer's message and your business context are sent to Google's Gemini API. Inbixy does not use your conversations to train any AI model.
  • Meta Platforms, Inc. The Messenger Platform and Graph API, used to receive incoming messages and deliver replies.
  • Upstash (Redis). Optional. Stores only rate-limit counters keyed by workspace identifier — never message content.
  • Our hosting and database providers. They store the data described above on our behalf.

We may also disclose data where legally required, or to protect the rights and safety of our users.

Cookies

Inbixy sets three cookies, all strictly necessary. There are no analytics or advertising cookies.

  • A session cookie that keeps you logged in.
  • A short-lived cookie holding the Facebook OAuth state value, used to prevent request forgery during the connect flow.
  • A short-lived, encrypted cookie holding your pending Page selection while you complete the connect flow. It expires within ten minutes.

How long we keep it

Conversations and Page data are kept until you disconnect the Page, delete your account, or ask us to delete them. Disconnecting a Page in the dashboard permanently deletes the stored Page credentials and all Messenger conversations for that Page.

We action deletion requests within 30 days. See deleting your data for the available routes.

What a Facebook deletion request removes

If you remove Inbixy from your Facebook account, Meta notifies us automatically and we delete all data we obtained from Facebook: the Page access token, Page ID and name, your app-scoped user ID, every customer PSID, and all Messenger message content and metadata for that Page.

We keep your Inbixy account, workspace settings, product listings, and knowledge snippets. That material is first-party content you typed into Inbixy rather than data obtained from Facebook, and deleting a Facebook connection should not destroy your product catalogue. To remove that too, email us and ask for full account deletion.

Customers who message a Page never authorise Inbixy directly, so Meta never sends us a deletion signal on their behalf. Their PSIDs and messages are deleted when the business disconnects the Page or requests deletion.

Your rights

You can request access to, correction of, or deletion of your personal data, and you can withdraw consent by disconnecting your Page or closing your account. Email animesh@classtablet.com and we will respond within 30 days.

Security

Page access tokens are encrypted at rest with AES-256-GCM. Passwords are stored as hashes, never in plain text. Traffic to Inbixy uses HTTPS. No system is perfectly secure, so we cannot guarantee absolute security, but we work to protect your data and will notify affected users of a breach that puts them at risk.

International transfers

Our providers may process and store data outside your country, including in the United States and other regions. By using Inbixy you agree to this transfer.

Children

Inbixy is a business tool and is not directed at people under 18. We do not knowingly collect data from children. If you believe a child's data has reached us, email us and we will delete it.

Changes to this policy

We may update this policy as the service changes. The date at the top reflects the latest revision. Material changes will be communicated to account holders by email.