Last updated 19 August 2026
Privacy Policy
StaffBud is a software service that lets a business connect its Facebook Page so an AI assistant can answer customer messages using knowledge the business itself provides. This policy explains what data the platform processes, why, and how it can be deleted.
Who this policy covers
This policy covers two groups: the business users who create a StaffBud account and connect their Facebook Page, and the customers of those businesses whose Messenger conversations are processed so a reply can be produced. For customer messages, the business that owns the Facebook Page decides what is collected and how it is used; StaffBud processes that data on the business's behalf.
Data we collect
- Account information: name, email address, password credentials held by our authentication provider, workspace name and settings.
- Connected Facebook Page information: Page ID, Page name, Page picture, webhook subscription state and the access tokens needed to receive and send Page messages.
- Messenger customer messages: the message text sent to a connected Page, the sender's Messenger-scoped ID, and the public profile fields Messenger returns for that sender.
- Conversation history: the messages exchanged in a conversation, whether a reply was AI-generated or written by staff, and delivery status.
- Uploaded business files: documents, spreadsheets, images and other files a business uploads as source material.
- Extracted business knowledge: the structured information derived from those files, including text embeddings used for search, and its review status.
- AI-generated responses: prompts assembled from approved knowledge and the replies produced for them.
- Usage and billing information: AI token counts, credit balances and transactions, subscription state and internal cost records.
- Technical logs: request and error logs needed to operate and secure the service.
How data is used
- To create and operate a business's workspace and authenticate its users.
- To receive Messenger messages sent to a connected Page and deliver replies from that Page.
- To generate replies grounded in the business's own approved knowledge.
- To show conversations, customers and analytics to the business that owns them.
- To measure AI usage, apply credit balances and support billing.
- To detect abuse, debug failures and keep the service secure.
We do not sell personal data, and we do not use Messenger message content to train our own models.
Messenger data
When a business connects a Facebook Page, StaffBud subscribes that Page to our Messenger webhook. Messages sent to the Page by its customers are delivered to our servers, stored against that business's workspace, and used to produce a reply. Replies are sent back through the Messenger Platform from the same Page. StaffBud does not initiate conversations with people who have not messaged the Page, and Page access tokens are stored server-side only and never exposed to browsers.
Disconnecting a Page removes our webhook subscription and stops further message processing for that Page.
AI processing
To produce a reply, relevant approved knowledge, the AI employee's configuration and recent conversation context are sent to a third-party large language model provider (OpenAI) which returns generated text. Uploaded file content is also processed by that provider during extraction and to create embeddings for search. AI output is generated automatically, can be incomplete or wrong, and should not be relied on as professional advice.
Uploaded files
Files a business uploads are stored in a private storage bucket that is not publicly readable, and are accessible only to that business's workspace and to the platform operators for support and troubleshooting. Businesses are responsible for the content they upload and should not upload personal data they have no right to process, or sensitive personal data they do not need the assistant to use.
Data retention
- Account, workspace, conversation, knowledge and usage records are retained while the account is active.
- Uploaded files and extracted knowledge are retained until the business deletes them or the account is deleted.
- Webhook event records are retained for a short operational window for delivery, retry and troubleshooting.
- Billing and AI usage records may be retained after deletion where needed for accounting and dispute resolution.
- On account deletion, workspace data is deleted or irreversibly anonymised as described in our data deletion instructions.
Security
Access to workspace data is enforced in the database itself: every table is scoped so a user can only read the records belonging to their own organization. Secrets — the Meta app secret, Page access tokens and AI provider keys — exist only on the server and are never sent to the browser. Incoming Meta webhook requests are rejected unless their signature verifies against our app secret. Data is transmitted over TLS and stored on managed infrastructure. No system can be guaranteed completely secure, and we do not claim any certification we have not obtained.
Third-party processors
StaffBud relies on the following categories of service providers:
- Meta Platforms — Messenger Platform and Graph API, to receive and send Page messages.
- OpenAI — large language model and embedding processing for extraction, search and reply generation.
- Supabase — managed database, authentication and file storage.
- Cloud hosting and content delivery — to run the application and its APIs.
- PayPal — payment processing, once billing is enabled in the product. It is not active today, and no payment data is processed until it is.
Each provider processes data only as needed to deliver its part of the service.
Your rights
Depending on where you live, you may have the right to access, correct, export or delete your personal data, to object to or restrict certain processing, and to complain to a data protection authority. Business users can view and edit most of their data directly in the app. To exercise a right that the app does not expose, contact us at support@messenger-ai-base.lovable.app. If you are a customer of a business using StaffBud, contact that business first — it decides how its Messenger conversations are handled — and we will support it in responding.
Account deletion
You can request deletion of your account, your organization's data, your Facebook Page connection, Messenger conversation data and uploaded business knowledge. Our data deletion instructions explain exactly what is removed and how to make the request, including the automated callback we expose for Facebook-initiated deletion requests.
Changes to this policy
We may update this policy as the product changes. Material changes will be reflected in the "last updated" date above, and continued use of the service after an update means the updated policy applies.
Contact
Questions about this policy or about data handling can be sent to support@messenger-ai-base.lovable.app.