Privacy Policy
Draft as of 2026-09-27 — do not publish before legal review
This page describes what data the Once low service (the "service", "we") collects and processes, why, and on what basis. It describes the product as it stands at the time of writing — some points are marked to be confirmed pending unresolved organizational decisions (legal entity and jurisdiction).
Who we are
Service operator: [legal entity name, country of registration]. Contact for data questions: [email].
What data we process
- Business owner account data: email, name, password (stored as a hash, never in plain text).
- Client conversations: messages received through connected channels (Telegram, WhatsApp, Instagram, Facebook Messenger, and Viber), including text, stickers, photos, and voice messages.
- Client data: name, phone number, and anything else the business owner chooses to track on a client's card, including what the agent extracts from the conversation itself.
- Product catalog and organization documentation: what the business owner enters for the AI agent to use.
- Technical data: IP address and request timestamps — for abuse protection (rate limits).
Why we process it
- To show conversations and client cards to the business owner in the dashboard.
- So the AI agent can suggest replies, answer questions about a conversation, and maintain a client's card — this requires sending message text to a third-party model (see below).
- To keep the service secure and limit abuse (per-organization rate limits).
Who we share data with
We do not sell data. The following are involved in running the service:
- Anthropic (Claude API) — processes conversation text to generate reply suggestions and extract client data, under Anthropic's own privacy policy.
- DeepSeek — optionally, if an organization has switched reply-suggestion generation to this provider in settings.
- Telegram, Meta, and Viber — as the messenger operators the conversations run through; their own privacy policies apply independently of ours.
- Hosting provider: [provider and server location — to be confirmed].
Where data is stored
The service's database is hosted in [country/region — to be confirmed once a server is chosen].
How long we keep data
Conversations and client cards are kept for as long as the organization uses the service. When an organization's account is deleted, data is removed [exact process and timelines — to be formalized].
Your rights
A business owner may request an export or deletion of their organization's data by writing to [email]. Self-service export/deletion from the dashboard is in development.
Cookies and local storage
To keep you signed in, we use a session token stored in the browser's local storage (localStorage), not a cookie. It exists only so you don't have to re-enter your password on every page.
Changes to this document
We may update this page as the service evolves. The date of the last update is shown at the top.