Data Policy
Last updated June 23, 2026
1. Purpose of this Data Policy
This Data Policy explains specifically how Socavi accesses, processes, stores, and deletes data obtained through third-party platform APIs, including Meta platforms (Instagram and Facebook), and other connected channels such as WhatsApp, Telegram, TikTok, YouTube, LinkedIn, Discord, and website chat. It supplements our Privacy Policy and is intended to meet the data-handling disclosure requirements of the platforms we integrate with.
2. Platform data we access
When a user connects a social or messaging account to Socavi, we access only the data needed to deliver the service the user has explicitly enabled. For Meta platforms this may include: the connected account profile, messages and comments directed at the connected account, and the platform-scoped user identifiers required to maintain a conversation thread.
We only access messages and comments that are initiated by an end user toward our customer's connected account. Socavi never sends unsolicited outbound messages to users who have not first engaged with our customer.
3. How we use platform data
Platform data is used solely to: route incoming messages and comments into a unified inbox, run the automated qualification funnels our customer has configured, score lead intent, and push qualified lead records to the customer's chosen CRM. We do not use platform data for advertising, we do not sell platform data, and we do not use it to build cross-customer profiles.
4. Data storage and retention
Platform data is stored on secure infrastructure provided by our hosting and database providers. Conversation and lead data is retained while the customer maintains an active account and is deleted within 30 days of account closure; conversation transcripts are retained for up to 12 months unless deletion is requested earlier. Access tokens are stored encrypted and are used only to perform actions the customer has authorized.
5. Data sharing
We share platform data only with: the customer who owns the connected account, the CRM or destination the customer has explicitly connected (for example Google Sheets, HubSpot, Klaviyo, Salesforce, or Pipedrive), and infrastructure subprocessors strictly necessary to operate the service (currently Supabase for database, authentication, and file storage; Render for application and API hosting; Groq for the AI inference behind agent replies; Google Workspace for transactional email; Stripe for payments; and Sentry for error monitoring where enabled). All are located in the United States. We do not share platform data with any other third party.
6. Compliance with platform policies
Socavi operates in accordance with the platform terms and developer policies of each service we integrate with, including the Meta Platform Terms and Developer Policies. Where a platform restricts a use of data, that restriction takes precedence over any conflicting configuration. We honor message-window rules, permitted-use limits, and rate limits set by each platform.
7. Data deletion
End users and customers may request deletion of their data at any time. See our Data Deletion Instructions page for the exact process. Upon a valid request we delete the associated conversation, message, and lead records, and revoke stored access tokens.
8. Use of AI in messaging
Socavi includes an optional AI agent that can generate reply messages on behalf of our customer (the business that owns the connected account). When a customer enables this feature, AI-generated replies are sent from the business account within the messaging window permitted by the platform, in response to messages a person has initiated. The AI assists the business in responding; it does not impersonate the person messaging, and it does not initiate unsolicited contact.
The AI uses only the information needed to reply in context: the current conversation history, the business profile and FAQ content the customer has configured, and the lead's stated intent. Message content is sent to Groq, our AI inference provider, solely to generate the reply. It is not used to train any model, and it is not retained by us for training. The customer remains responsible for the messages sent from their account and can disable the AI agent or take over any conversation at any time.
9. Contact
For any question about how Socavi handles platform data, contact us at hello@socavi.co.