TwingBot privacy policy

This policy explains what data TwingBot collects, why it is collected, how it is used, how long it is kept, and how users can request deletion or correction. The full policy is on this page; the summary below reproduces its main sections.

Information we collect

How we use information

Meta platform data

When a user connects Meta channels, TwingBot may receive Page, Instagram, message, comment, webhook and profile data permitted by the user's granted permissions. Meta data is used only to provide connected channel functionality such as inbox sync, automation, AI replies, private comment replies, order detection, analytics and page management. If a connected page is removed from TwingBot, we unsubscribe the page from our Meta webhook subscription so new webhook events stop arriving for that page.

AI processing

If AI features are enabled, customer text, image or voice content may be processed to understand intent, answer product questions, detect orders and draft replies. AI replies follow the user's configured persona, language, reply rules, channel settings, automation settings and available product/order data. AI features can be disabled by the user from the AI bot settings.

Third-party services

Data retention

Account deletion and Meta data deletion

Users can request account deletion from the Security settings page. After confirmation, cleanup is processed through a background queue. Deletion cleanup removes connected pages, unsubscribes Meta webhooks, stops automations, removes sessions, inbox data, products, settings and AI data, and anonymizes records that must be retained.

Security

TwingBot uses access controls, authenticated API routes, encrypted/secret field handling where appropriate, masked IP display, session management and worker queues for sensitive background operations. Courier credentials, tokens and connected channel credentials should only be provided by the account owner or an authorized team member. No system can guarantee absolute security, but we work to reduce unnecessary data exposure and keep sensitive workflows server-side.