Privacy Policy

Last updated: 2026-09-14 · Eva AI · Oyu Intelligence LLC

Энэ бодлогыг монголоор унших

1. Information we collect

With your permission: the name and ID of your Facebook Page and Instagram Business account; the content of messages and comments sent to that page; the sender's Facebook/Instagram ID, public name and profile picture link.

If a staff member connects Telegram: their Telegram user ID and chat ID; requests sent to Eva and messages exchanged with connected partner organisations. We do not read private chats, groups, or contact lists.

If a voice message arrives: the audio is transcribed to text and only the TEXT is stored. We do not keep the audio file on our own servers.

When an order is captured: the customer's name, PHONE NUMBER, DELIVERY ADDRESS, ordered product, quantity and price — as typed by the customer in the chat.

From your use of the service: your account email, organisation name, and the knowledge base content you provide.

If you connect a separate mailbox: its address, sender name, IMAP/SMTP server settings, and encrypted App Password. When you open the inbox, Eva processes the sender, recipients, subject, date, plain-text message body, and whether attachments exist through IMAP. Eva does not download or store attachment files.

If you request product updates on our public page: the email address you enter, the signup time, and the privacy-policy version you accepted.

Page access tokens are stored encrypted using AES-256-GCM.

2. How we use it

To generate automated replies to customer messages and comments on your behalf, show incoming messages from a connected mailbox to an operator, send the operator's reply, send email campaigns that you initiate, let staff interact with Eva, and exchange messages with connected partner organisations.

We use an email address voluntarily submitted for updates only to send Eva AI product and service news.

We do NOT sell your data and do not use it for advertising.

3. Third-party processing

We use the following sub-processors to operate the service:

• DeepSeek (api.deepseek.com, China) — receives the TEXT of the comment or message and your knowledge base content in order to generate a reply. Facebook access tokens are never sent.

• Fal.AI (fal.ai, USA) — transcribes voice messages to text (Whisper model) and generates images you request. Audio is not retained by them after processing.

• Supabase — database infrastructure with row-level access control.

• Fly.io (Tokyo, Japan) — the main application servers. This is where your data is processed.

• Vercel — hosting for the public marketing pages and the front-end proxy.

• Telegram (api.telegram.org; Telegram Web — web.telegram.org — for browser-based connection) — when a staff member connects Telegram, receiving and sending Eva requests and messages with connected partner organisations.

• QPay (merchant.qpay.mn, Mongolia) — creating payment invoices and confirming payment.

• Brave Search (api.search.brave.com, only if web search is enabled) — receives only the SEARCH TERMS, never the conversation history.

• OpenAI (api.openai.com, USA) — a FALLBACK provider for AI replies and for voice transcription. DeepSeek and Fal.AI are the defaults, so this is used only when explicitly configured. It exists as an option for organisations that do not want data transferred to China.

• Resend — sending account, invitation, notification, and user-initiated email. The connected email provider's IMAP/SMTP servers — listing incoming mail for an operator, reading the selected message text, and sending the operator's reply or other user-initiated email.

• Google (only if you connect a Google account) — capability-specific Calendar, app-selected Drive files, and send-only Gmail access on your behalf.

• Google Fonts (fonts.googleapis.com, fonts.gstatic.com) — the PUBLIC marketing pages (/ and /en) load their typefaces from Google. Viewing those pages sends your browser's IP address and User-Agent to Google. This applies to the public pages only: the signed-in console does not use Google Fonts, and no organisation data is ever sent here.

• Services you connect yourself (only if you connect them) — Zapier, Make, n8n or your own system: when a staff member runs one of their actions through Eva, Eva sends only the information that action needs. Addresses for outgoing notifications: when an event you chose happens (a conversation starts, is handed to a person, or an order is submitted through the order flow), Eva sends a signed notice containing only identifiers, the time, a status and, for orders, the amount — never names, phone numbers or message text. You choose these yourself and can disconnect them at any time.

Each processes data under its own privacy policy. Apart from those listed above and services you connect yourself, we do not share your data with anyone else.

4. Google user data

If you connect a Google account, we access only the capability you select: events on calendars you own; Drive, Sheets, or Docs files created by Eva; and send-only Gmail access. We do not request permission to read your Gmail inbox.

This is used ONLY to carry out work you or your assistant performs — scheduling meetings, recording entries in selected spreadsheets, drafting documents, and sending approved email.

Eva AI's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

We do not use Google user data for advertising, do not sell it, and do not allow humans to read it — except for security purposes, to comply with applicable law, or with your explicit consent.

We do not use Google user data to train AI or machine learning models.

Access and refresh tokens are stored encrypted with AES-256-GCM. When you disconnect, Eva deletes its local tokens and asks Google to revoke the OAuth grant. If Google revocation cannot be confirmed, Eva reports that outcome and links you to Google Account Connections so you can remove the app manually.

5. Retention

Message and comment history is retained while the connection is active. It is permanently deleted within 30 days of disconnection or a deletion request.

Local Meta Page access tokens are deleted immediately when a connection is removed. Eva attempts to unsubscribe the webhook, but the Facebook Login/Business Integration grant is separate and must also be removed in Meta settings.

Mailbox listings and selected message text are fetched from the provider for each request and are not stored in Eva's database. Mailbox settings and the encrypted App Password are retained until you disconnect the mailbox or delete the organisation; after disconnecting, you must also revoke the App Password in the provider account.

Minimised evidence for paid, expired, or cancelled payments is retained in a separate append-only ledger without tenant or customer PII for at least 10 years for accounting purposes. An unresolved payment operation temporarily pauses deletion until it is reconciled.

After a Meta person-data deletion completes, raw app-scoped and Page-scoped IDs are removed. Only one-way identity hashes are retained to prevent delayed or replayed webhooks from recreating deleted data.

Update-list subscriptions are retained until you opt out or request deletion; you can make that request through the contact email below.

6. Security

Data is stored in a database with row-level security. Access tokens and App Passwords are encrypted with AES-256-GCM. Every webhook request is verified with an HMAC SHA-256 signature.

7. Your rights

You may request access to, correction of, or deletion of your data, opt out of product updates, and object to processing. Send requests to the address below; we respond within 30 days.

See /data-deletion for detailed deletion instructions.

8. Contact

Oyu Intelligence LLC — a limited liability company, state registration number 7074801.

Khan-Uul district, 3rd khoroo, Ulaanbaatar, Mongolia.

Email: info@oyu.ml · Phone: +976 8697-0213