01.

Introduction

At Resolo, we take your privacy seriously. This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our platform and services.

By using Resolo, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies and practices, please do not use our services.

02.

Information We Collect

We collect several types of information to provide and improve our services:

Personal Information

Name, email address, and contact details

Account credentials and authentication data

Profile information and preferences

Billing and payment information

Usage Data

Device information (IP address, browser type, operating system)

Usage patterns and interaction with our platform

Log data and analytics information

Cookies and similar tracking technologies

Content Data

Files, documents, and media you upload

Messages, emails, and communications

Generated content and AI outputs

Calendar events and task information

03.

How We Use Your Information

We use the collected information for various purposes:

1

To provide, maintain, and improve our services

2

To process your transactions and manage your account

3

To send you updates, notifications, and marketing communications

4

To personalize your experience and content recommendations

5

To train and improve our AI models and algorithms

6

To detect, prevent, and address technical issues or fraud

7

To comply with legal obligations and enforce our policies

8

To analyze usage patterns and optimize platform performance

04.

Social Media & Messaging Integrations

Resolo connects with messaging platforms to enable automated responses on your behalf. This section explains the technical process, the data involved, and your control over these integrations.

OAuth Authentication Process

When you connect Instagram or Facebook, the following occurs:

1

You are redirected to Meta (Facebook) login where you authenticate directly with Meta

2

You explicitly grant permission to connect your Instagram Business or Professional Account

3

Meta issues an access token which Resolo stores in encrypted form

4

The token permits Resolo to receive incoming messages and send responses on your behalf

5

At no point does Resolo receive or store your Facebook or Instagram password

Data Access & Limitations

Resolo requests only the permissions necessary to operate. We access:

What We Access

Instagram Business Account identifier

Incoming direct messages to your account

Ability to send message responses

Connected Facebook Page information

What We Cannot Access

Your personal Facebook profile or friends

Private Instagram account content or followers

Ability to post, comment, or like on your behalf

Access to any accounts you do not authorize

Message Processing & Privacy

When a message arrives, the following process occurs:

Incoming messages are received via secure webhook and passed directly to the AI agent for processing

The AI agent generates a contextual response and sends it back through the platform API

Message content is processed in real-time and is not stored on Resolo servers by default

Resolo personnel do not have access to read, review, or monitor your message content

Conversation context may be temporarily held in memory to maintain continuity, then discarded

AI & Language Model Privacy

Message content processed by the AI is not used to train or improve third-party language models

We utilize enterprise-grade AI services with data processing agreements that prohibit training on user data

No message content is shared with third parties except as necessary to generate responses

You may request complete deletion of any stored data at any time

Disconnection & Token Revocation

You may disconnect any integration from your Resolo dashboard at any time

Upon disconnection, access tokens are immediately invalidated and permanently deleted

You may also revoke access directly through Instagram or Facebook settings

Disconnection stops all automated responses and webhook processing immediately

Platform Compliance: Resolo operates in compliance with Meta Platform Terms, Instagram Platform Policy, and applicable data protection regulations. Access tokens and credentials are encrypted using AES-256-GCM and stored on infrastructure that meets SOC 2 standards.

05.

Data Sharing & Disclosure

We may share your information in the following circumstances:

We Share With

Service providers and business partners

Payment processors and financial institutions

Analytics and monitoring services

Cloud infrastructure providers

We Never Share

Your data with advertisers for marketing

Personal information to third parties for profit

Your content publicly without permission

Sensitive data without encryption

Legal Disclosure: We may disclose your information if required by law, court order, or government request, or to protect our rights and safety.

06.

Data Security

We implement robust security measures to protect your data at every level:

Encryption at Rest & In Transit

AES-256-GCM encryption for all sensitive credentials and tokens

Per-user encryption keys derived from master keys using HMAC-SHA256

OAuth tokens, API keys, and platform credentials encrypted before storage

TLS 1.3 encryption for all data transmitted between your device and our servers

Platform Integration Security

Instagram, WhatsApp, Gmail, and Telegram credentials stored with AES-GCM encryption

Webhook signatures verified using HMAC-SHA256 to prevent tampering

OAuth 2.0 flows with secure state parameters for CSRF protection

Automatic token refresh with encrypted storage of refresh tokens

Infrastructure & Access Control

Deployed on Cloudflare Workers with edge-level security

Environment secrets managed through secure secret storage

Role-based access controls and authentication for all API endpoints

Regular security audits and penetration testing

Real-time monitoring for suspicious activities and anomalies

Key Rotation: We support encryption key rotation to re-encrypt all stored data when security keys are updated, ensuring continuous protection even if keys are compromised.

Important: While we implement bank-level encryption and security practices, no method of transmission over the internet is 100% secure. We continuously improve our security measures to protect your data.

07.

Your Privacy Rights

You have the following rights regarding your personal data:

01

Access & Portability

Request a copy of your personal data in a structured, machine-readable format

02

Correction

Update or correct inaccurate or incomplete information

03

Deletion

Request deletion of your personal data (right to be forgotten)

04

Opt-Out

Unsubscribe from marketing communications at any time

05

Data Processing

Object to or restrict certain types of data processing

06

Withdraw Consent

Revoke previously given consent for data processing

To exercise any of these rights, please contact us at [email protected]

08.

Cookies & Tracking

We use cookies and similar technologies to enhance your experience:

Essential Cookies

Always active

Required for the platform to function properly (authentication, security)

Performance Cookies

Optional

Help us understand how you interact with our platform

Functional Cookies

Optional

Remember your preferences and settings

Analytics Cookies

Optional

Track usage patterns and improve our services

You can manage cookie preferences in your browser settings or through our cookie consent banner.

09.

Data Retention

We retain your data for different periods depending on the type:

Account data: Retained while your account is active

Content data: Stored as long as you use our services

Usage logs: Typically retained for 90 days

Billing records: Kept for 7 years for tax compliance

Marketing data: Until you unsubscribe or request deletion

Backup data: Maintained for 30 days after deletion

10.

Children's Privacy

Our services are not intended for children under 13 years of age. We do not knowingly collect personal information from children. If you are a parent or guardian and believe your child has provided us with personal data, please contact us immediately, and we will take steps to remove such information.

11.

International Data Transfers

Your information may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place:

Standard Contractual Clauses (SCCs) approved by the EU Commission

Adequacy decisions for countries with equivalent data protection

Privacy Shield certification for US-based processors

Binding Corporate Rules for intra-group transfers

12.

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by:

Sending an email to your registered email address

Posting a prominent notice on our platform

Updating the "Last updated" date at the top of this policy

Your continued use of our services after changes are posted constitutes acceptance of the updated policy.

Privacy Questions?

If you have questions about our privacy practices or want to exercise your rights, our privacy team is here to help.

Address

Resolo Privacy Team
123 AI Street
Tech City, TC 12345