Privacy Policy
This policy explains how Rasael AI collects, uses, shares, and stores personal data, including data received through the official APIs of the WhatsApp Business Platform, Instagram, Facebook, TikTok, and Google Calendar. It also describes how to delete your data.
1. Who We Are
- Data Controller: Rasael AI Inc.
- Registered Address: 8 The Green, Ste R, Dover, DE 19901, USA
- UAE Office: 403 Al Noor Building, Damascus Street, Al Qusais, Dubai, UAE
- Site: https://rasael.ai
- Email: support@rasael.ai
- WhatsApp: +971 60 056 1636
2. Scope & Channels Covered
This policy explains how we collect, use, share, and store personal data when you use Rasael AI, including data received from Meta via official APIs for WhatsApp Business Platform, Instagram, and Facebook (Pages/Catalog/Graph/Marketing APIs), and data received from Google via the official Google Calendar API, and data received from TikTok via the official TikTok Business Messaging API.
3. Data We Process
3.1 Facebook & Instagram permissions (only if actually enabled)
| Permission / Feature | Data from Meta | Purpose (why we need it) |
|---|---|---|
catalog_management | Catalog item data (product/item IDs, title, description, price/currency, image URLs, availability, inventory, categories/variants) | Sync/add/update/delete items and product sets in Rasael AI for FB/IG Commerce. No off-app advertising use. |
pages_read_engagement | Page posts, comments, reach/engagement insights | In-app analytics and dashboards. |
pages_manage_posts | Create/edit/schedule Page posts | Enable publishing from Rasael AI. |
pages_manage_metadata | Page settings and connections | Link Page and verify ownership. |
pages_read_user_content (optional) | UGC on your Page | Moderation/support if enabled. |
instagram_basic | Account ID, name, basic media | Display/connect content in-app. |
instagram_manage_comments (optional) | Comments on your media | Moderation and replies. |
instagram_manage_messages (optional) | Instagram Direct for business accounts | Customer service/private replies. |
instagram_manage_insights | Engagement/reach metrics | Performance reporting. |
instagram_content_publish (optional) | Publish Instagram content | Scheduling/publishing from Rasael AI. |
public_profile (optional with social login) | Name, profile photo, user ID | Account creation/verification and in-app display. |
email (optional with social login) | Email address | Verification, security and support communications. |
3.2 WhatsApp (WhatsApp Business Platform)
When you connect a business number, we process (depending on your use):
- Messaging data: customer phone numbers, displayed profile name, conversation/message IDs, message content and media you send/receive via Rasael AI, delivery/read statuses, conversation categories (service/marketing/authentication per Meta), message templates and approval status, webhook notifications.
- Account/settings data: WABA ID and Phone Number ID, messaging tier/quality rating, opt-in/opt-out status.
- Purpose: to enable customer support, notifications and transactions, manage templates, reporting and compliance.
- Restrictions: We do not use WhatsApp message content or channel data to build advertising profiles or for off-app targeting, and we do not onward-transfer Meta Platform Data to third parties other than our processors without your consent or a clear legal basis.
3.3 Google Calendar (Google Calendar API)
When you choose to connect your Google Calendar to Rasael AI, we request the following Google OAuth scopes and process the corresponding data. We access your Google user data only after you explicitly grant permission, and only to provide this feature.
| Scope | Data from Google | Purpose (why we need it) |
|---|---|---|
calendar.calendars | Your calendar list and calendar properties (calendar names and settings — not event content) | Identify and select the calendar connected to your Rasael AI workspace so appointments are always booked on the correct calendar. |
calendar.events | Your calendar events (event titles, times, attendees, availability/free-busy information) | Read your availability and create, update, or cancel booking/appointment events on your calendar when your customers schedule appointments with your business through Rasael AI chat channels. |
- OAuth tokens: the access and refresh tokens Google issues for your connection are stored encrypted at rest and are used solely to call the Google Calendar API on your behalf.
- Change notifications: we receive Google Calendar push notifications so your availability stays in sync; these notifications contain no event content, only a signal that something changed.
- What we do NOT do: we do not use Google Calendar data for advertising, we do not sell it, and we do not transfer it to third parties except as necessary to provide the feature (our hosting processors) or as required by law. Humans do not read your calendar data except with your explicit permission (e.g., a support request), for security/abuse investigation, or where required by law.
Rasael AI’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, data obtained from Google APIs is:
- Used only to provide and improve the Appointment Scheduling feature you requested.
- Not transferred or sold to third parties for advertising, marketing, or other unrelated purposes.
- Not used to serve advertisements.
- Not used to train generalized or non-personalized AI/ML models. Google user data is never used to train our AI models.
- Accessed by humans only in the limited cases permitted by Google — with your explicit consent, for security or legal compliance, or when the data has been aggregated and anonymized.
3.4 Other data we may collect
- In-app usage logs (diagnostics), limited to what is necessary.
- Device/browser info (device type, OS, public IP).
- Content you provide (e.g., product data, media, captions) when using publishing tools, catalog management, or messaging features.
3.5 TikTok (Business Messaging API)
When a business connects its TikTok Business Account, we process (depending on your use):
- Messaging data: TikTok user identifiers (open ID) as provided by TikTok, display name and avatar where supplied, conversation and message IDs, message content and media sent or received through Rasael AI, delivery and read statuses, and webhook notifications.
- Account/settings data: TikTok Business Account ID, connection status, and automated-reply configuration set by the business.
- Purpose: to deliver inbound direct messages into the authorizing business’s shared inbox, enable human and configured automated replies, and provide conversation reporting to that business.
- Authorization: access is granted only through the standard TikTok OAuth flow by the Business Account owner, and is revoked immediately upon disconnection.
- Restrictions: We do not use TikTok message content or channel data to build advertising profiles or for off-platform targeting. We do not use TikTok data to train generalized AI models. We do not onward-transfer TikTok data to third parties other than our processors without your consent or a clear legal basis.
- Messaging limits: Messages are sent only in response to conversations initiated by the TikTok user, and strictly within TikTok’s 48-hour messaging window. Rasael AI does not provide broadcast, bulk, or business-initiated messaging on TikTok.
4. How We Use Data
- Provide the service: enable channels (WhatsApp/Instagram/Facebook/TikTok/Google Calendar) and the features you choose (e.g., catalog sync, messaging, publishing, appointment scheduling).
- Analytics & performance: understand feature usage and improve experience (typically aggregated/de-identified).
- Security & fraud prevention: protect accounts, investigate abuse.
- Service communications: important changes or incidents. We do not use Meta, TikTok, or Google data for marketing without your explicit consent.
- AI features (if enabled): some functions may use AI models hosted by us or our processors. We do not use your customer content to train general-purpose models without your consent, and we never use Google Calendar data to train AI models.
5. Sharing & Disclosure
- Service providers (hosting, databases, analytics, media caching, customer-support tooling) under data-protection agreements.
- Legal compliance where required.
- Corporate transactions (merger/acquisition) with continued protections.
We do not sell personal data, we do not share Meta Platform Data, TikTok data, or Google user data for off-app ad targeting, and we do not combine Meta, TikTok, or Google data with external sources to build marketing profiles without explicit consent.
6. Legal Bases
Processing is based on: (a) contract performance, (b) legitimate interests (security/performance), and (c) consent where required (for optional features).
7. Retention
- Catalog-related sync and diagnostic logs: up to 90 days.
- Working copies needed to operate your commerce integration (e.g., mappings between your product IDs and Meta Item IDs): retained while your account/integration is active, then deleted within 30 days of disconnect or deletion request.
- Message content/attachments processed via WhatsApp or Instagram messaging features: retained only as needed to operate the feature (e.g., deliver, display, or troubleshoot), then deleted per your workspace settings; if no setting applies, up to 30 days.
- Message content and attachments processed via the TikTok Business Messaging API: retained only as needed to operate the feature (e.g., deliver, display, or troubleshoot), then deleted per your workspace settings; if no setting applies, up to 30 days. TikTok OAuth tokens and connection records are retained while the connection is active, then deleted within 30 days of disconnection, revocation, or deletion request.
- Google Calendar OAuth tokens and connection records: retained while your Google Calendar connection is active, then deleted within 30 days of disconnection, revocation, or deletion request. Booking events we created remain on your Google Calendar under your control.
8. International Transfers
Your data may be processed on servers outside your country. We use appropriate safeguards (e.g., Standard Contractual Clauses where applicable) to ensure an equivalent level of protection.
9. Security
We apply technical and organizational measures (TLS in transit, encryption at rest for access tokens and credentials, restricted access controls, environment isolation, encrypted backups) and conduct periodic reviews of permissions and logs.
10. Your Rights & Choices
You may request access, correction, deletion, portability, and restriction/objection, and withdraw consent where applicable. You can:
- Disconnect channels (e.g., WhatsApp/FB/IG/TikTok/Google Calendar) from Rasael AI at any time.
- Revoke Rasael AI’s access to your Google account at any time from your Google Account security settings.
- Stop WhatsApp marketing by replying STOP or via channel settings.
- Submit a deletion request using the section below.
Contact support@rasael.ai to exercise your rights.
11. Children
Rasael AI is not directed to children under 13, and we do not knowingly process their data.
12. Changes
We will post any changes on this page and update the “Last updated” date.
13. Contact
Rasael AI Inc.
8 The Green, Ste R, Dover, DE 19901, USA
WhatsApp: +971 60 056 1636
Data Deletion Instructions
Applies to Meta (Facebook/Instagram), WhatsApp Business Platform, TikTok, and Google Calendar integrations.
A) Self-service: disconnect integrations
- Rasael AI → Settings → Channels: disconnect the WhatsApp number, Facebook Page, Instagram account, TikTok Business Account, or Google Calendar.
- Facebook/Instagram: you may also remove Rasael AI in Facebook Business Integrations and revoke the Instagram connection.
- TikTok: you may also revoke Rasael AI’s access from your TikTok Business Account settings. Revoking invalidates our stored tokens immediately.
- Google Calendar: you may also revoke Rasael AI’s access from your Google Account → Security → Third-party access. Revoking invalidates our stored tokens immediately.
B) Request deletion from us
Use our form: https://rasael.ai/data-deletion
Include:
- Your account email and company name.
- IDs relevant to the integration you want deleted (any that apply): Page ID, Instagram Business/Professional Account ID, WABA ID and/or Phone Number ID, TikTok Business Account ID, or the Google account email connected for Google Calendar.
- What to delete: account data, channel connections/tokens, catalog sync data, message content/attachments, logs.
What we delete
- Account profile, channel connections and access tokens (including Google OAuth access and refresh tokens).
- Catalog mappings and sync artifacts (e.g., product-ID ↔ Meta item-ID tables).
- Message content and media stored by us for WhatsApp/Instagram messaging features.
- TikTok connection records, access and refresh tokens, and message content and media stored by us for the TikTok messaging feature.
- Google Calendar connection records and sync state stored by us. (Events on your Google Calendar itself remain under your control in Google Calendar.)
- Diagnostic/sync logs (subject to the timeline below).
What we may retain
- Minimal audit logs, security records, and billing/invoices as required by law and for fraud prevention. These are kept separately and not used for marketing.
Timeline
- We acknowledge your request within 7 days and complete deletion within 30 days (unless a longer period is legally required).
- Backups are overwritten on a rolling cycle (up to 35 days). Once expired, deleted data becomes unrecoverable.
- Deleting data in Rasael AI does not delete your content from Meta, TikTok, or Google themselves (e.g., items in your Meta Catalog, your TikTok messages, or events on your Google Calendar); manage those in Facebook/Instagram/TikTok/Google Calendar directly or ask support for help.
Automated callbacks
If you remove our app from Facebook/Instagram, disconnect a WhatsApp number, disconnect your TikTok Business Account, or revoke Rasael AI’s Google access, our Data Deletion Callback runs to delete associated tokens/mappings per the rules above.
Contact
If you cannot access the form, email support@rasael.ai with the subject “Data Deletion Request – Rasael AI” and include the details listed above.