Privacy Policy
Ai Xodim (ai-xodim.uz, the “Service”) helps businesses automate Instagram — keyword auto-replies to comments and Direct messages, account analytics — and lets them connect their own AI assistant (Claude, ChatGPT, Gemini and others) to their Instagram through the Model Context Protocol (MCP). The Service is operated by the sole proprietor Yakka tartibdagi tadbirkor JABBOROV SANJAR RADJABOVICH, Republic of Uzbekistan (“we”, “us”). This policy explains what data we process, why, and what control you have over it.
1. Roles
- For the account data of our customers (“Merchants”) we are the controller.
- For data about people who interact with a Merchant’s Instagram account (commenters and people who write in Direct) the Merchant is the controller and we process that data on the Merchant’s behalf, only to provide the Service.
2. Data we process
Merchant account
- Name, login, and optionally email and company name; password stored only as a one-way hash.
- If you sign in with Google or Apple: the name, email address and profile photo that the provider shares with your consent, and an identifier of that sign-in. Apple may give us a private relay address instead of your real email. Sign-in goes through Google Firebase Authentication, which keeps its own record of the sign-in; it is deleted together with your account.
- Connected AI applications: the application name, when access was granted, and OAuth tokens (revocable at any time on the “AI connector” page).
- Mobile app push-notification tokens, if you use our iOS or Android app.
- If you subscribe to Ai Xodim Pro in the app: the purchase record from the App Store or Google Play — product, transaction or order identifiers, status, trial and renewal dates — and a random account identifier we attach to the purchase so it can be matched to your account. Payment itself is handled by Apple or Google; we never receive your card details.
Connected Instagram account
Obtained through the official Instagram login with the account owner’s explicit consent. We never see or store Instagram passwords.
- Instagram account ID, username and the access token issued by Meta (encrypted at rest), with its expiry date.
- Profile counters (followers, following, posts), recorded once a day to show growth over time.
- Posts, reels, comments and insights (reach, views, interactions, audience demographics) — read from Instagram when you open analytics or your AI assistant asks for them, and cached for a few minutes.
- Your automation settings: keyword rules, reply texts, default reply.
People who interact with a Merchant’s Instagram account
- Instagram-scoped user ID, username and display name.
- Text of incoming Direct messages and of comments that matched an auto-reply rule, with timestamps.
- The automatic replies sent, and how the person reached the account (a comment under a post, a story reply, an ad or a link).
- Whether the person opted out of automated messages (by writing “stop”).
Technical data
- IP address, browser user agent and request errors — for security and troubleshooting.
3. Why we use it
- To send the auto-replies the Merchant configured — in Direct and under comments.
- To show the Merchant analytics and a log of what the automation did.
- To let the Merchant’s connected AI assistant read and act on the Merchant’s Instagram when the Merchant asks it to.
- To keep the Service secure, prevent abuse, and provide support.
We do not sell personal data, and we do not use it for advertising.
4. Who receives data
- Meta (Instagram) — replies and actions are sent through the official Instagram API.
- AI applications the Merchant connects — when a Merchant connects an AI assistant (for example Claude by Anthropic, ChatGPT by OpenAI or Gemini by Google) and asks it a question, the data needed to answer — analytics, posts, comments, Direct messages of that Merchant’s account — is sent to that application and processed under its provider’s terms and privacy policy. The Merchant chooses and authorizes these applications and can revoke access at any time.
- Our AI provider — for the optional “content analysis” feature, captions of the Merchant’s posts are sent to our language-model provider (Google Gemini or OpenAI) to group them by topic. Where AI reply features are enabled for an account, message text is processed the same way.
- Infrastructure providers — hosting (Akamai/Linode, United States), Firebase Cloud Messaging for mobile push notifications and Firebase Authentication for signing in with Google or Apple.
- Apple and Google — subscriptions are bought through the App Store or Google Play; we check the purchase with the store and receive its status updates.
5. Storage and security
- Data is stored on servers in the United States. By using the Service you acknowledge this transfer.
- Passwords are hashed; Instagram access tokens are encrypted; all traffic uses HTTPS.
- Instagram webhooks are verified with Meta’s signature; AI connections use OAuth 2.1 and can be revoked by the Merchant.
6. How long we keep it
- Logs of incoming Direct messages and matched comments — 90 days, then deleted automatically.
- If a person unsends a Direct message, we delete our copy of its text.
- Contacts, rules and daily snapshots — until the Merchant disconnects the Instagram account (which deletes them immediately) or deletes their account.
- Technical logs — up to 30 days.
- When a Merchant account is deleted, all related data is deleted within 30 days.
7. Your rights
Depending on where you live (for example under the GDPR in the EEA/UK), you may have the right to access, correct, export or delete your data, and to object to or restrict its processing. Merchants can disconnect Instagram, revoke AI applications and delete their whole account themselves — in the dashboard (Profile → Delete account) or in the mobile app. For anything else, email brandbox.uz@mail.ru. If you wrote to or commented on a business that uses Ai Xodim, see Data deletion — we will also forward your request to that business, who controls your data.
8. Children
The Service is intended for businesses and is not directed to children under 16.
9. Cookies
Only functional cookies: the sign-in session, security token and interface language. No advertising or third-party analytics cookies.
10. Changes
We will publish any changes on this page and update the date above; material changes will be announced to Merchants by email or in the dashboard.
11. Contact
Yakka tartibdagi tadbirkor JABBOROV SANJAR RADJABOVICH, Republic of Uzbekistan · brandbox.uz@mail.ru
Политика конфиденциальности
Ai Xodim (ai-xodim.uz, далее — «Сервис») помогает бизнесу автоматизировать Instagram — автоответы по ключевым словам на комментарии и сообщения в Direct, аналитика аккаунта — и позволяет подключить к своему Instagram собственного ИИ-ассистента (Claude, ChatGPT, Gemini и другие) по протоколу Model Context Protocol (MCP). Оператор Сервиса — индивидуальный предприниматель Yakka tartibdagi tadbirkor JABBOROV SANJAR RADJABOVICH, Республика Узбекистан («мы»). Здесь описано, какие данные мы обрабатываем, зачем и как вы можете ими управлять.
1. Роли
- По данным учётных записей наших клиентов («Мерчантов») мы — оператор (контролёр).
- По данным людей, которые взаимодействуют с Instagram-аккаунтом Мерчанта (комментируют и пишут в Direct), контролёр — Мерчант, а мы обрабатываем эти данные по его поручению и только для работы Сервиса.
2. Какие данные мы обрабатываем
Учётная запись Мерчанта
- Имя, логин и по желанию email и название компании; пароль — только в виде необратимого хэша.
- Если вы входите через Google или Apple: имя, email и фото профиля, которые провайдер передаёт с вашего согласия, и идентификатор этого входа. Apple может передать нам служебный адрес-пересылку вместо вашего настоящего email. Вход проходит через Google Firebase Authentication, где остаётся запись о входе; она удаляется вместе с аккаунтом.
- Подключённые ИИ-приложения: название, время выдачи доступа и OAuth-токены (доступ отзывается в любой момент на странице «AI-коннектор»).
- Токены push-уведомлений, если вы пользуетесь нашим приложением для iOS или Android.
- Если вы оформляете подписку Ai Xodim Pro в приложении: запись о покупке из App Store или Google Play — продукт, идентификаторы транзакции или заказа, статус, даты пробного периода и продления — и случайный идентификатор, который мы прикрепляем к покупке, чтобы связать её с вашей учётной записью. Оплату проводят Apple или Google; данные карты мы не получаем.
Подключённый Instagram-аккаунт
Получаем через официальный вход Instagram с явного согласия владельца аккаунта. Пароли Instagram мы не видим и не храним.
- ID и имя пользователя Instagram-аккаунта, токен доступа, выданный Meta (хранится зашифрованным), и срок его действия.
- Счётчики профиля (подписчики, подписки, публикации) — фиксируются раз в сутки, чтобы показывать рост.
- Публикации, Reels, комментарии и статистика (охват, просмотры, взаимодействия, демография аудитории) — запрашиваются у Instagram, когда вы открываете аналитику или о них спрашивает ваш ИИ-ассистент, и кешируются на несколько минут.
- Ваши настройки автоответов: правила, тексты ответов, ответ по умолчанию.
Люди, которые взаимодействуют с Instagram-аккаунтом Мерчанта
- Идентификатор пользователя в Instagram (scoped ID), имя пользователя и отображаемое имя.
- Текст входящих сообщений в Direct и комментариев, сработавших на правило автоответа, с отметками времени.
- Отправленные автоответы и то, откуда человек пришёл (комментарий под публикацией, ответ на сторис, реклама или ссылка).
- Отметка об отказе от автоматических сообщений (если человек написал «стоп»).
Технические данные
- IP-адрес, данные браузера и ошибки запросов — для безопасности и диагностики.
3. Зачем мы используем данные
- Чтобы отправлять автоответы, настроенные Мерчантом, — в Direct и под комментариями.
- Чтобы показывать Мерчанту аналитику и журнал работы автоответов.
- Чтобы подключённый Мерчантом ИИ-ассистент мог по его запросу читать данные его Instagram и выполнять действия.
- Чтобы обеспечивать безопасность, предотвращать злоупотребления и оказывать поддержку.
Мы не продаём персональные данные и не используем их для рекламы.
4. Кому передаются данные
- Meta (Instagram) — ответы и действия отправляются через официальный Instagram API.
- ИИ-приложения, которые подключает Мерчант — когда Мерчант подключает ИИ-ассистента (например, Claude от Anthropic, ChatGPT от OpenAI или Gemini от Google) и задаёт ему вопрос, нужные для ответа данные — аналитика, публикации, комментарии, сообщения Direct аккаунта этого Мерчанта — передаются этому приложению и обрабатываются по условиям и политике конфиденциальности его провайдера. Мерчант сам выбирает и авторизует такие приложения и может отозвать доступ в любой момент.
- Наш ИИ-провайдер — для необязательной функции «разбор контента» подписи к публикациям Мерчанта отправляются нашему провайдеру языковой модели (Google Gemini или OpenAI), чтобы сгруппировать их по темам. Если для аккаунта включены ИИ-ответы, так же обрабатывается текст сообщений.
- Инфраструктурные провайдеры — хостинг (Akamai/Linode, США), Firebase Cloud Messaging для push-уведомлений в мобильных приложениях и Firebase Authentication для входа через Google или Apple.
- Apple и Google — подписка покупается через App Store или Google Play; мы проверяем покупку у магазина и получаем уведомления о её статусе.
5. Хранение и защита
- Данные хранятся на серверах в США. Пользуясь Сервисом, вы соглашаетесь с этой передачей.
- Пароли хэшируются, токены Instagram шифруются, весь трафик идёт по HTTPS.
- Вебхуки Instagram проверяются по подписи Meta; ИИ-подключения работают по OAuth 2.1 и отзываются Мерчантом.
6. Сроки хранения
- Журналы входящих сообщений Direct и сработавших комментариев — 90 дней, затем удаляются автоматически.
- Если человек удалил отправленное сообщение, мы удаляем его текст у себя.
- Контакты, правила и ежедневные снимки — пока Мерчант не отключит Instagram-аккаунт (тогда удаляются сразу) или не удалит учётную запись.
- Технические логи — до 30 дней.
- При удалении учётной записи Мерчанта все связанные данные удаляются в течение 30 дней.
7. Ваши права
В зависимости от страны проживания (например, по GDPR в ЕЭЗ и Великобритании) вы вправе получить доступ к своим данным, исправить, выгрузить или удалить их, а также возразить против обработки или ограничить её. Мерчант может сам отключить Instagram, отозвать доступ ИИ-приложений и удалить весь аккаунт — в кабинете («Профиль» → «Удалить аккаунт») или в мобильном приложении. По остальным вопросам пишите на brandbox.uz@mail.ru. Если вы писали или оставляли комментарий бизнесу, который пользуется Ai Xodim, см. Удаление данных — мы также передадим ваш запрос этому бизнесу как контролёру ваших данных.
8. Дети
Сервис предназначен для бизнеса и не рассчитан на детей младше 16 лет.
9. Cookies
Только функциональные cookies: сессия входа, защитный токен и язык интерфейса. Рекламных и сторонних аналитических cookies нет.
10. Изменения
Изменения публикуются на этой странице с новой датой; о существенных изменениях сообщаем Мерчантам по email или в кабинете.
11. Контакты
Yakka tartibdagi tadbirkor JABBOROV SANJAR RADJABOVICH, Республика Узбекистан · brandbox.uz@mail.ru