Legal

Privacy Policy

Last updated: June 20, 2026

Novus AI Inbox ("Novus," "we," "us," or "our") is operated by Dataicraft. This Privacy Policy explains how we collect, use, disclose, and protect information when you use our website and services at novusaiinbox.dataicraft.com.

1. Information we collect

Account information. When you register, we collect your name, email address, and password (stored in hashed form). If you are part of a business account, we also associate your user with a tenant organization.

Connected Meta accounts. When you connect Instagram or Facebook through Meta Login or OAuth, we receive access tokens, Page IDs, account usernames, and related metadata needed to receive and send messages on your behalf.

Messaging data. We process direct messages, conversation history, sender identifiers, and message content from connected Instagram and Facebook accounts so our AI agent and your team can respond to customers.

Knowledge base content. Documents and text you upload to train or configure your AI agent are stored and processed to generate responses.

Usage and technical data. We collect log data such as IP address, browser type, pages visited, API usage, and error reports to operate, secure, and improve the service.

2. How we use your information

  • Provide, maintain, and improve Novus AI Inbox
  • Authenticate users and manage tenant accounts
  • Receive, process, and send messages via Meta platforms
  • Generate AI-assisted replies based on your configuration and knowledge base
  • Monitor usage, billing, and platform health
  • Respond to support requests and legal obligations
  • Detect, prevent, and address fraud, abuse, or security issues

3. Meta / Facebook platform data

Novus AI Inbox integrates with Meta products (Facebook Login, Instagram Messaging, and related APIs). Data obtained through these integrations is used only to provide the messaging and automation features you enable — not for unrelated advertising or resale.

You can disconnect linked accounts at any time from your dashboard. If you requested deletion of your Facebook data through Meta, you can check the status of that request on our data deletion status page.

4. How we share information

We do not sell your personal information. We may share data with:

  • Meta Platforms, Inc. — to send and receive messages through Instagram and Facebook APIs you authorize
  • AI and infrastructure providers — to host the service and process messages when generating AI responses
  • Service providers — who assist with hosting, analytics, email, or support under contractual confidentiality obligations
  • Legal requirements — when required by law, court order, or to protect rights, safety, and security

5. Data retention

We retain account and messaging data for as long as your subscription is active or as needed to provide the service. When you disconnect an account or close your tenant, we delete or anonymize associated data within a reasonable period, except where retention is required for legal, security, or backup purposes.

6. Security

We use industry-standard measures including encryption in transit (HTTPS/TLS), hashed passwords, access controls, and secure token storage. No method of transmission or storage is completely secure; we cannot guarantee absolute security.

7. Your rights and choices

Depending on your location, you may have the right to:

  • Access, correct, or delete personal information we hold about you
  • Export your data in a portable format
  • Object to or restrict certain processing
  • Withdraw consent where processing is consent-based

To exercise these rights, email privacy@dataicraft.com. We will respond within the timeframe required by applicable law.

8. Cookies

We use essential cookies and similar technologies for authentication and session management. The Facebook JavaScript SDK may set cookies when you use Facebook Login on our connect page, subject to Meta's policies.

9. International transfers

Your information may be processed in countries other than your own. Where required, we use appropriate safeguards for cross-border data transfers.

10. Children

Novus AI Inbox is a business service and is not directed to children under 13 (or the applicable age in your jurisdiction). We do not knowingly collect personal information from children.

11. Changes to this policy

We may update this Privacy Policy from time to time. We will post the revised version on this page and update the "Last updated" date. Material changes may be communicated by email or in-app notice.

12. Contact us

Questions about this Privacy Policy or our data practices: