Introduction
At Resolo, we take your privacy seriously. This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our platform and services.
By using Resolo, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies and practices, please do not use our services.
Information We Collect
We collect several types of information to provide and improve our services:
Personal Information
Name, email address, and contact details
Account credentials and authentication data
Profile information and preferences
Billing and payment information
Usage Data
Device information (IP address, browser type, operating system)
Usage patterns and interaction with our platform
Log data and analytics information
Cookies and similar tracking technologies
Content Data
Files, documents, and media you upload
Messages, emails, and communications
Generated content and AI outputs
Calendar events and task information
How We Use Your Information
We use the collected information for various purposes:
To provide, maintain, and improve our services
To process your transactions and manage your account
To send you updates, notifications, and marketing communications
To personalize your experience and content recommendations
To train and improve our AI models and algorithms
To detect, prevent, and address technical issues or fraud
To comply with legal obligations and enforce our policies
To analyze usage patterns and optimize platform performance
Data Sharing & Disclosure
We may share your information in the following circumstances:
We Share With
Service providers and business partners
Payment processors and financial institutions
Analytics and monitoring services
Cloud infrastructure providers
We Never Share
Your data with advertisers for marketing
Personal information to third parties for profit
Your content publicly without permission
Sensitive data without encryption
Legal Disclosure: We may disclose your information if required by law, court order, or government request, or to protect our rights and safety.
Data Security
We implement robust security measures to protect your data at every level:
Encryption at Rest & In Transit
AES-256-GCM encryption for all sensitive credentials and tokens
Per-user encryption keys derived from master keys using HMAC-SHA256
OAuth tokens, API keys, and platform credentials encrypted before storage
TLS 1.3 encryption for all data transmitted between your device and our servers
Platform Integration Security
Instagram, WhatsApp, Gmail, and Telegram credentials stored with AES-GCM encryption
Webhook signatures verified using HMAC-SHA256 to prevent tampering
OAuth 2.0 flows with secure state parameters for CSRF protection
Automatic token refresh with encrypted storage of refresh tokens
Infrastructure & Access Control
Deployed on Cloudflare Workers with edge-level security
Environment secrets managed through secure secret storage
Role-based access controls and authentication for all API endpoints
Regular security audits and penetration testing
Real-time monitoring for suspicious activities and anomalies
Key Rotation: We support encryption key rotation to re-encrypt all stored data when security keys are updated, ensuring continuous protection even if keys are compromised.
Important: While we implement bank-level encryption and security practices, no method of transmission over the internet is 100% secure. We continuously improve our security measures to protect your data.
Your Privacy Rights
You have the following rights regarding your personal data:
Access & Portability
Request a copy of your personal data in a structured, machine-readable format
Correction
Update or correct inaccurate or incomplete information
Deletion
Request deletion of your personal data (right to be forgotten)
Opt-Out
Unsubscribe from marketing communications at any time
Data Processing
Object to or restrict certain types of data processing
Withdraw Consent
Revoke previously given consent for data processing
To exercise any of these rights, please contact us at [email protected]
Data Retention
We retain your data for different periods depending on the type:
Account data: Retained while your account is active
Content data: Stored as long as you use our services
Usage logs: Typically retained for 90 days
Billing records: Kept for 7 years for tax compliance
Marketing data: Until you unsubscribe or request deletion
Backup data: Maintained for 30 days after deletion
Children's Privacy
Our services are not intended for children under 13 years of age. We do not knowingly collect personal information from children. If you are a parent or guardian and believe your child has provided us with personal data, please contact us immediately, and we will take steps to remove such information.
International Data Transfers
Your information may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place:
Standard Contractual Clauses (SCCs) approved by the EU Commission
Adequacy decisions for countries with equivalent data protection
Privacy Shield certification for US-based processors
Binding Corporate Rules for intra-group transfers
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by:
Sending an email to your registered email address
Posting a prominent notice on our platform
Updating the "Last updated" date at the top of this policy
Your continued use of our services after changes are posted constitutes acceptance of the updated policy.
Privacy Questions?
If you have questions about our privacy practices or want to exercise your rights, our privacy team is here to help.
Resolo Privacy Team
123 AI Street
Tech City, TC 12345
Social Media & Messaging Integrations
Resolo connects with messaging platforms to enable automated responses on your behalf. This section explains the technical process, the data involved, and your control over these integrations.
OAuth Authentication Process
When you connect Instagram or Facebook, the following occurs:
You are redirected to Meta (Facebook) login where you authenticate directly with Meta
You explicitly grant permission to connect your Instagram Business or Professional Account
Meta issues an access token which Resolo stores in encrypted form
The token permits Resolo to receive incoming messages and send responses on your behalf
At no point does Resolo receive or store your Facebook or Instagram password
Data Access & Limitations
Resolo requests only the permissions necessary to operate. We access:
What We Access
Instagram Business Account identifier
Incoming direct messages to your account
Ability to send message responses
Connected Facebook Page information
What We Cannot Access
Your personal Facebook profile or friends
Private Instagram account content or followers
Ability to post, comment, or like on your behalf
Access to any accounts you do not authorize
Message Processing & Privacy
When a message arrives, the following process occurs:
Incoming messages are received via secure webhook and passed directly to the AI agent for processing
The AI agent generates a contextual response and sends it back through the platform API
Message content is processed in real-time and is not stored on Resolo servers by default
Resolo personnel do not have access to read, review, or monitor your message content
Conversation context may be temporarily held in memory to maintain continuity, then discarded
AI & Language Model Privacy
Message content processed by the AI is not used to train or improve third-party language models
We utilize enterprise-grade AI services with data processing agreements that prohibit training on user data
No message content is shared with third parties except as necessary to generate responses
You may request complete deletion of any stored data at any time
Disconnection & Token Revocation
You may disconnect any integration from your Resolo dashboard at any time
Upon disconnection, access tokens are immediately invalidated and permanently deleted
You may also revoke access directly through Instagram or Facebook settings
Disconnection stops all automated responses and webhook processing immediately
Platform Compliance: Resolo operates in compliance with Meta Platform Terms, Instagram Platform Policy, and applicable data protection regulations. Access tokens and credentials are encrypted using AES-256-GCM and stored on infrastructure that meets SOC 2 standards.