Privacy Policy
Last updated: November 20, 2025
1. Introduction
Welcome to RENSHO AI ("we," "our," or "us"). We are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our multi-tenant SaaS platform for Retrieval-Augmented Generation (RAG) chatbots integrated with Facebook Messenger.
By using our service, you agree to the collection and use of information in accordance with this policy.
2. Information We Collect
2.1 Personal Information
- Account information: email address, name, and password
- Profile information: business details, preferences, and settings
- Payment information (if applicable for premium features)
2.2 Facebook Data
- Facebook Page connections and access tokens (encrypted)
- Messenger conversation data between your customers and our AI
- Page admin information for notification purposes
2.3 Usage Data
- Knowledge bases, documents, and AI persona configurations
- Conversation logs and interaction history
- API usage statistics and performance metrics
2.4 Technical Data
- IP address, browser type, and device information
- Cookies and similar tracking technologies
- Server logs and error reports
3. How We Use Your Information
We use the collected information for the following purposes:
- To provide and maintain our AI chatbot service
- To process and respond to customer messages via Facebook Messenger
- To generate AI responses using Retrieval-Augmented Generation (RAG)
- To manage your account and provide customer support
- To analyze usage patterns and improve our service
- To comply with legal obligations and enforce our terms
- To send administrative notifications and updates
4. Information Sharing and Disclosure
We do not sell, trade, or otherwise transfer your personal information to third parties except in the following circumstances:
- Facebook: We share necessary data with Facebook to facilitate Messenger integration and webhook functionality
- AI Service Providers: We use OpenRouter API and similar services to process AI requests. Data is transmitted securely and used only for generating responses
- Service Providers: We may share data with trusted third-party service providers who assist in operating our platform (e.g., Supabase for data storage)
- Legal Requirements: We may disclose information if required by law, court order, or to protect our rights and safety
- Business Transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred
5. Data Security
We implement appropriate technical and organizational security measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. These measures include:
- Encryption of sensitive data in transit and at rest
- Access controls and authentication mechanisms
- Regular security audits and updates
- Secure storage using Supabase with Row Level Security (RLS)
- Encrypted storage of API keys and access tokens
6. Data Retention
We retain your personal information for as long as necessary to provide our services and fulfill the purposes outlined in this policy, unless a longer retention period is required by law. Specifically:
- Account data is retained while your account is active
- Conversation logs may be retained for service improvement and legal compliance
- Deleted data is permanently removed from our systems within 30 days
7. Your Rights and Choices
Depending on your location, you may have the following rights regarding your personal information:
- Access: Request a copy of the personal information we hold about you
- Correction: Request correction of inaccurate or incomplete information
- Deletion: Request deletion of your personal information and account
- Portability: Request transfer of your data in a structured format
- Opt-out: Opt-out of certain data processing activities
To exercise these rights, please contact us using the information provided below. For account deletion requests, you can also use the "Delete Account" option in your account settings, which will permanently remove all your data from our systems. We will process deletion requests within 30 days and notify you once completed.
8. Cookies and Tracking Technologies
We use cookies and similar technologies to enhance your experience, analyze usage, and provide personalized services. You can control cookie preferences through your browser settings.
9. Children's Privacy
Our service is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If we become aware that we have collected such information, we will take steps to delete it.
10. International Data Transfers
Your information may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place to protect your data during such transfers.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new policy on this page and updating the "Last updated" date.
12. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us:
- Email: privacy@rensholab.com
- Address: [Your Business Address]