Who this covers
Two different groups of people appear in this policy, and they are treated differently.
Operators are the business owner, the client-admins and the teammates who sign in to AiPraktor. We hold their account data directly and we are responsible for it.
Customers are the people who message a business on Facebook, Instagram, WhatsApp or its website. Their messages, names and contact details belong to that business. AiPraktor stores and processes them on that business’s instructions, as a service provider — in European terms, the business is the controller and we are the processor. The business decides what is collected, how long it is kept, and who on their team can see it.
If you are the customer of a business that uses AiPraktor and you want your data corrected or removed, ask that business first — they will pass the request on to us. You can also write to privacy@aipraktor.com and we will make sure it happens.
The AiPraktor Assistant Chrome extension
This is the section a Chrome Web Store reviewer usually wants, so it is the most detailed one on this page.
The extension is a work tool. It is installed by a business’s own staff and used on that business’s own Meta Business Suite or Messenger inbox. It runs on exactly three sites — business.facebook.com, www.facebook.com and www.messenger.com — and on no other page you visit.
Signing in
You sign in through the extension’s popup with your AiPraktor email and password, or with an AiPraktor access key. The credentials are sent once, over HTTPS, to our login endpoint. The extension never stores your password. It stores the API key the login returns, together with your email and role, in chrome.storage.local on that computer. Signing out deletes them.
Reading the conversation you have open
When you click the assistant button on a conversation, the extension reads the visible text of that one open thread — the messages in the message pane, the customer name Meta displays, and the URL of the avatar image Meta renders — and sends it to the automation engine your workspace has configured for that page. The engine compares those messages against the conversations the business has already recorded and answers with which recorded customer this thread belongs to.
That identification is the only reason the text is sent. It is necessary because Meta’s Business Suite does not put a usable conversation id in the URL, so there is no other way to know which customer is on screen. The answer is cached locally against that thread, so a thread is identified once and not again.
Doing the work
Once the customer is identified, the extension reads and writes only that business’s own records, through the AiPraktor API: whether the conversation is handled by the AI or by a human, the customer’s lead (stage, follow-up date, phone, email, note, value, priority) and — when you ask for it — a summary of their history, a suggested reply, or an answer to a question you type.
Notifications
While Chrome is open, the extension asks our events endpoint roughly every 30 seconds whether anything happened on the pages you are allowed to see: a chat handed to a human, a new lead, or an alert raised by the AI agent. It shows a desktop notification for the types you have left switched on, and you can turn each one off in the popup. The response contains only events for your own pages; the server decides that, not the extension.
What stays on your computer
chrome.storage.local holds your API key, your user record and role, the list of pages you can access, the cached thread-to-customer mapping, your notification preferences, the event cursor and the ids of recently shown notifications, and — if you set one — a custom AiPraktor server address. Nothing else. Signing out clears all of it.
What the extension does not do
- It does not read or collect your browsing history.
- It does not track you across websites, and injects nothing into sites other than the three listed above.
- It contains no analytics SDK, no advertising SDK and no third-party trackers.
- It does not sell, rent or share data with anyone for advertising.
- It does not send data anywhere except the AiPraktor service and the automation engine your own workspace is configured to use.
- It reads no payment details. Beyond access to the three sites named above, the only Chrome permissions it requests are storage, alarms and notifications.
Chrome Web Store Limited Use disclosure
AiPraktor Assistant’s use of information received from Google APIs, and of any user data it handles, adheres to the Chrome Web Store User Data Policy, including its Limited Use requirements. Specifically:
- We use the data only to provide and improve the features visible to the user in the extension.
- We do not transfer the data to third parties, except to the AiPraktor service and the automation engine the user’s own workspace is configured to use — both acting on the user’s instructions — or where required by law, or in connection with a merger or acquisition after notice to users.
- We do not use or transfer the data for advertising, ad targeting or personalisation.
- We do not sell the data.
- No human reads the data except the user’s own colleagues inside their workspace’s permissions, and an AiPraktor engineer with the user’s explicit permission or where necessary for security or to comply with the law.
What the dashboard and API store
- Operator accounts
- Email, display name, role, workspace, assigned pages, an API key, and — for client logins — a hashed password. Never a plain-text password.
- Pages and channels
- The page’s name and channel, its auto-revert window, response-time target, handoff webhook, and its connection credentials (see Security, below).
- Conversations
- One record per conversation: the customer’s platform id, display name and profile image URL, whether the AI or a human is handling it, when a temporary handover expires, who claimed it, and the timestamps used for response-time reporting.
- Conversation content
- For businesses using the interaction ledger, the messages exchanged between the customer and the page, stored in AiPraktor’s database, kept apart from every other business’s data, so the AI can answer from history.
- Leads
- Name, phone, email, stage, value, intent, notes, follow-up dates, source and channel — plus a timeline recording every change and who made it.
- Operational records
- An activity log of every switch between AI and human, alerts raised by the AI agent, and web push subscriptions for the browsers that opted in.
- How long we keep it
- While a business uses AiPraktor, and afterwards for as long as its account exists in view-only mode, until the business asks us to delete it. A person’s own data is deleted when they ask. Data from a marketplace that sets its own limits is deleted within that marketplace’s limit.
- Website enquiries
- If you use the live chat on our own site, the name, mobile number, optional email and message you type are stored as a lead in AiPraktor’s own workspace so we can reply. Your IP address is used only to rate-limit that form — it is held in memory for the length of a one-minute window and is never written to the database or attached to the enquiry.
We do not ask for, and the product has no field for, payment card numbers, government identity numbers or health information.
How the data is protected
- Everything travels over HTTPS.
- Passwords are stored as scrypt hashes with a per-user random salt, never in plain text, and are compared in constant time.
- Each business’s channel and model credentials are encrypted with AES-256-GCM before they are written to the database, and decrypted only on the server at the moment the automation engine needs them. They are never sent to a browser — the settings screen shows only whether a field is filled in. If the encryption key is missing, the product refuses to store a secret rather than storing it in the clear.
- The database is reachable only through the server’s privileged role. Row-level security is on and the public key reads nothing.
- Every dashboard and extension request carries the signed-in key, and the server — never the browser — decides which pages that key may touch. A client cannot widen its own access by editing a request.
- Login and the public enquiry form are rate-limited.
No system is perfectly secure. If a breach affects your data we will tell you, and the relevant authority, without undue delay.
Who on a team can see what
- Owner
- Everything, across every workspace. This is the AiPraktor operator.
- Client-admin
- One workspace only — its pages, conversations, leads, activity, analytics and team. Never another business’s data.
- Teammate
- Only the pages assigned to them, and by default only the leads assigned to them plus the unassigned ones. An admin can widen this for an individual teammate.
These boundaries are enforced on the server for every request, including every request the Chrome extension makes.
How long things are kept
Conversation records, leads and activity are a business’s working records, kept as set out under “How long we keep it” in section 4. A business can delete an individual lead from the dashboard at any moment.
Database backups are overwritten on a rolling basis, so deleted data disappears from backups within that cycle. Web push endpoints are deleted as soon as they stop working. Notification history in the Chrome extension lives only on your own computer.
Your rights
Depending on where you live you may have the right to ask for a copy of your data, to have it corrected or deleted, to object to or restrict how it is used, to receive it in a portable form, and to complain to your data protection authority. Where we act on a business’s behalf (see section 1) we pass the request to that business and help them answer it.
To exercise any of these, or to ask us to delete your data, email privacy@aipraktor.com. We reply within 30 days. We will ask you to confirm your identity first, so that a request cannot be used to obtain somebody else’s data.
Where the processing happens
AiPraktor is operated from Bangladesh, and the servers it runs on are located in the European Union and the United States. Your data will therefore be transferred to and stored in countries other than your own. Where the law requires a transfer safeguard, we rely on the standard contractual clauses offered by the providers listed in section 5.
Children
AiPraktor is a business tool and is not directed at children. We do not knowingly collect data from anyone under 18. If you believe a child’s data has reached us through a business’s inbox, tell us at privacy@aipraktor.com and we will remove it.
Changes to this policy
If we change this policy we update the date at the top of this page, and for anything material we tell signed-in operators in the dashboard before it takes effect. The previous version is available on request.
Contact
Write to privacy@aipraktor.com with any question about this policy, about what we hold, or to make a request under section 10. Questions in Bangla are welcome, and a Bangla copy of this policy is available on request.
Our terms of service are at aipraktor.com/terms.
Privacy Policy · last updated 16 September 2026 · AiPraktor