AiPraktor
← Back to home
Legal

Privacy Policy

Last updated: 16 September 2026·Applies to the AiPraktor dashboard, its API, and the AiPraktor Assistant Chrome extension
Existing accounts: the changes published on 11 September 2026 take effect on 25 September 2026.

AiPraktor is a customer-conversation tool for small businesses. This page says, in plain English, exactly what the dashboard and the Chrome extension read, where that data goes, and what we never do with it.

The short version: we set no cookies, run no analytics or advertising, sell nothing to anybody, and the extension only ever looks at the one conversation you have open on your own inbox. The detail is below — and if anything here is unclear, email privacy@aipraktor.com and we will answer it.

Contents
  1. 1Who this covers
  2. 2The AiPraktor Assistant Chrome extension
  3. 3Chrome Web Store Limited Use disclosure
  4. 4What the dashboard and API store
  5. 5Who else touches the data
  6. 6How the data is protected
  7. 7Who on a team can see what
  8. 8Cookies, browser storage and notifications
  9. 9How long things are kept
  10. 10Your rights
  11. 11Where the processing happens
  12. 12Children
  13. 13Changes to this policy
  14. 14Contact

1Who this covers

Two different groups of people appear in this policy, and they are treated differently.

Operators are the business owner, the client-admins and the teammates who sign in to AiPraktor. We hold their account data directly and we are responsible for it.

Customers are the people who message a business on Facebook, Instagram, WhatsApp or its website. Their messages, names and contact details belong to that business. AiPraktor stores and processes them on that business’s instructions, as a service provider — in European terms, the business is the controller and we are the processor. The business decides what is collected, how long it is kept, and who on their team can see it.

If you are the customer of a business that uses AiPraktor and you want your data corrected or removed, ask that business first — they will pass the request on to us. You can also write to privacy@aipraktor.com and we will make sure it happens.

2The AiPraktor Assistant Chrome extension

This is the section a Chrome Web Store reviewer usually wants, so it is the most detailed one on this page.

The extension is a work tool. It is installed by a business’s own staff and used on that business’s own Meta Business Suite or Messenger inbox. It runs on exactly three sites — business.facebook.com, www.facebook.com and www.messenger.com — and on no other page you visit.

Signing in

You sign in through the extension’s popup with your AiPraktor email and password, or with an AiPraktor access key. The credentials are sent once, over HTTPS, to our login endpoint. The extension never stores your password. It stores the API key the login returns, together with your email and role, in chrome.storage.local on that computer. Signing out deletes them.

Reading the conversation you have open

When you click the assistant button on a conversation, the extension reads the visible text of that one open thread — the messages in the message pane, the customer name Meta displays, and the URL of the avatar image Meta renders — and sends it to the automation engine your workspace has configured for that page. The engine compares those messages against the conversations the business has already recorded and answers with which recorded customer this thread belongs to.

That identification is the only reason the text is sent. It is necessary because Meta’s Business Suite does not put a usable conversation id in the URL, so there is no other way to know which customer is on screen. The answer is cached locally against that thread, so a thread is identified once and not again.

Doing the work

Once the customer is identified, the extension reads and writes only that business’s own records, through the AiPraktor API: whether the conversation is handled by the AI or by a human, the customer’s lead (stage, follow-up date, phone, email, note, value, priority) and — when you ask for it — a summary of their history, a suggested reply, or an answer to a question you type.

Notifications

While Chrome is open, the extension asks our events endpoint roughly every 30 seconds whether anything happened on the pages you are allowed to see: a chat handed to a human, a new lead, or an alert raised by the AI agent. It shows a desktop notification for the types you have left switched on, and you can turn each one off in the popup. The response contains only events for your own pages; the server decides that, not the extension.

What stays on your computer

chrome.storage.local holds your API key, your user record and role, the list of pages you can access, the cached thread-to-customer mapping, your notification preferences, the event cursor and the ids of recently shown notifications, and — if you set one — a custom AiPraktor server address. Nothing else. Signing out clears all of it.

What the extension does not do

  • It does not read or collect your browsing history.
  • It does not track you across websites, and injects nothing into sites other than the three listed above.
  • It contains no analytics SDK, no advertising SDK and no third-party trackers.
  • It does not sell, rent or share data with anyone for advertising.
  • It does not send data anywhere except the AiPraktor service and the automation engine your own workspace is configured to use.
  • It reads no payment details. Beyond access to the three sites named above, the only Chrome permissions it requests are storage, alarms and notifications.

3Chrome Web Store Limited Use disclosure

AiPraktor Assistant’s use of information received from Google APIs, and of any user data it handles, adheres to the Chrome Web Store User Data Policy, including its Limited Use requirements. Specifically:

  • We use the data only to provide and improve the features visible to the user in the extension.
  • We do not transfer the data to third parties, except to the AiPraktor service and the automation engine the user’s own workspace is configured to use — both acting on the user’s instructions — or where required by law, or in connection with a merger or acquisition after notice to users.
  • We do not use or transfer the data for advertising, ad targeting or personalisation.
  • We do not sell the data.
  • No human reads the data except the user’s own colleagues inside their workspace’s permissions, and an AiPraktor engineer with the user’s explicit permission or where necessary for security or to comply with the law.

4What the dashboard and API store

Operator accounts
Email, display name, role, workspace, assigned pages, an API key, and — for client logins — a hashed password. Never a plain-text password.
Pages and channels
The page’s name and channel, its auto-revert window, response-time target, handoff webhook, and its connection credentials (see Security, below).
Conversations
One record per conversation: the customer’s platform id, display name and profile image URL, whether the AI or a human is handling it, when a temporary handover expires, who claimed it, and the timestamps used for response-time reporting.
Conversation content
For businesses using the interaction ledger, the messages exchanged between the customer and the page, stored in AiPraktor’s database, kept apart from every other business’s data, so the AI can answer from history.
Leads
Name, phone, email, stage, value, intent, notes, follow-up dates, source and channel — plus a timeline recording every change and who made it.
Operational records
An activity log of every switch between AI and human, alerts raised by the AI agent, and web push subscriptions for the browsers that opted in.
How long we keep it
While a business uses AiPraktor, and afterwards for as long as its account exists in view-only mode, until the business asks us to delete it. A person’s own data is deleted when they ask. Data from a marketplace that sets its own limits is deleted within that marketplace’s limit.
Website enquiries
If you use the live chat on our own site, the name, mobile number, optional email and message you type are stored as a lead in AiPraktor’s own workspace so we can reply. Your IP address is used only to rate-limit that form — it is held in memory for the length of a one-minute window and is never written to the database or attached to the enquiry.

We do not ask for, and the product has no field for, payment card numbers, government identity numbers or health information.

5Who else touches the data

We do not sell data and we have no advertising partners. The data is handled by these parties and no others:

Hostinger
Hosts the web app and the API on a virtual server we operate.
Our database server
A PostgreSQL / Supabase instance self-hosted by AiPraktor, which holds everything listed above.
The automation engine
Runs each business’s AI workflow and the assistant actions the extension calls. Self-hosted by AiPraktor, or by the business itself where it prefers to run its own.
Meta
Facebook, Instagram and WhatsApp are where the messages come from and go back to. Meta’s own terms and privacy policy govern their side of it.
The AI model provider the business chooses
Each business supplies its own key — for example OpenRouter or OpenAI. Message content needed to draft a reply, a summary or an answer is sent to that provider under that provider’s terms. A business that supplies no key gets no AI drafting, and nothing is sent.
Your browser vendor’s push service
Google, Apple or Mozilla deliver web push notifications to the browsers that opted in. They receive the notification text, not your account.

We will also disclose data where the law genuinely requires it, and we will tell the affected business unless we are forbidden from doing so.

6How the data is protected

  • Everything travels over HTTPS.
  • Passwords are stored as scrypt hashes with a per-user random salt, never in plain text, and are compared in constant time.
  • Each business’s channel and model credentials are encrypted with AES-256-GCM before they are written to the database, and decrypted only on the server at the moment the automation engine needs them. They are never sent to a browser — the settings screen shows only whether a field is filled in. If the encryption key is missing, the product refuses to store a secret rather than storing it in the clear.
  • The database is reachable only through the server’s privileged role. Row-level security is on and the public key reads nothing.
  • Every dashboard and extension request carries the signed-in key, and the server — never the browser — decides which pages that key may touch. A client cannot widen its own access by editing a request.
  • Login and the public enquiry form are rate-limited.

No system is perfectly secure. If a breach affects your data we will tell you, and the relevant authority, without undue delay.

7Who on a team can see what

Owner
Everything, across every workspace. This is the AiPraktor operator.
Client-admin
One workspace only — its pages, conversations, leads, activity, analytics and team. Never another business’s data.
Teammate
Only the pages assigned to them, and by default only the leads assigned to them plus the unassigned ones. An admin can widen this for an individual teammate.

These boundaries are enforced on the server for every request, including every request the Chrome extension makes.

8Cookies, browser storage and notifications

AiPraktor sets no cookies, and runs no analytics, advertising or tracking scripts. There is no Google Analytics, no Meta pixel, no session cookie and no third-party script on this site — which is why you were not shown a cookie banner. Even the fonts are self-hosted and served from our own domain, so opening a page here sends nothing to a font provider.

The dashboard keeps a few values in your browser’s own local storage so the app can work and remember your view: your signed-in user and access key, your language choice, your selected workspace, and small preferences such as which list view you last used. They never leave your browser except as the access key on requests to our own API. Signing out or clearing site data removes them.

Web push notifications are opt-in. When you allow them, your browser hands us an endpoint that we store so we can alert you about your own pages. You can revoke it in your browser at any time, and we delete endpoints that stop being deliverable.

9How long things are kept

Conversation records, leads and activity are a business’s working records, kept as set out under “How long we keep it” in section 4. A business can delete an individual lead from the dashboard at any moment.

Database backups are overwritten on a rolling basis, so deleted data disappears from backups within that cycle. Web push endpoints are deleted as soon as they stop working. Notification history in the Chrome extension lives only on your own computer.

10Your rights

Depending on where you live you may have the right to ask for a copy of your data, to have it corrected or deleted, to object to or restrict how it is used, to receive it in a portable form, and to complain to your data protection authority. Where we act on a business’s behalf (see section 1) we pass the request to that business and help them answer it.

To exercise any of these, or to ask us to delete your data, email privacy@aipraktor.com. We reply within 30 days. We will ask you to confirm your identity first, so that a request cannot be used to obtain somebody else’s data.

11Where the processing happens

AiPraktor is operated from Bangladesh, and the servers it runs on are located in the European Union and the United States. Your data will therefore be transferred to and stored in countries other than your own. Where the law requires a transfer safeguard, we rely on the standard contractual clauses offered by the providers listed in section 5.

12Children

AiPraktor is a business tool and is not directed at children. We do not knowingly collect data from anyone under 18. If you believe a child’s data has reached us through a business’s inbox, tell us at privacy@aipraktor.com and we will remove it.

13Changes to this policy

If we change this policy we update the date at the top of this page, and for anything material we tell signed-in operators in the dashboard before it takes effect. The previous version is available on request.

14Contact

Write to privacy@aipraktor.com with any question about this policy, about what we hold, or to make a request under section 10. Questions in Bangla are welcome, and a Bangla copy of this policy is available on request.

Our terms of service are at aipraktor.com/terms.

Privacy Policy · last updated 16 September 2026 · AiPraktor

© 2026 AiPraktor. All rights reserved.
HomePrivacyTermsDelete your dataprivacy@aipraktor.com