Privacy Policy
Who we are
Jimmaa is an AI-assisted messaging tool operated by HIU, a small apparel studio in Kathmandu, Nepal. Jimmaa connects to a business’s own Instagram, Messenger and WhatsApp accounts to help that business reply to customer messages and comments. This policy explains what data Jimmaa processes and how.
What we process
When you message or comment on a business that uses Jimmaa, we receive, through Meta’s official APIs:
- The content of your messages and comments.
- Basic profile information the platform provides — your username, display name and profile picture.
- Message metadata — timestamps and which platform the message came from.
On behalf of the connected business, Jimmaa also stores secure access tokens that let it send approved replies. Tokens are encrypted at rest.
How we use it
- To generate suggested reply drafts using AI (see “AI processing” below).
- To let the business’s team review, edit, approve and send replies.
- To organize conversations — labels, notes and customer records — so the business can respond well.
We do not use your messages to build advertising profiles, and we do not sell personal data.
AI processing
To draft suggested replies, the text of incoming messages and relevant business information (for example product and policy details) is sent to OpenAI’s API, which returns a draft. Per OpenAI’s API terms, this content is not used to train their models. A person at the business reviews every draft before anything is sent.
Who we share it with
We share data only with the service providers that operate Jimmaa:
- OpenAI — AI draft generation (processor).
- Meta Platforms — Instagram, Messenger and WhatsApp APIs, to receive and send messages.
- Vercel, Railway and Neon — hosting and database, which store data on our behalf.
We do not sell your data or share it for advertising.
Retention
We keep conversation data for as long as the connected business uses Jimmaa to manage that relationship. You can request deletion at any time — see our Data Deletion page.
Security
Access tokens are encrypted at rest, all connections use TLS, and access to a workspace is restricted to that business’s authorized team members.
Your rights
You may request access to, correction of, or deletion of your data. To do so, or for any privacy question, email sg28r8@gmail.com.
Changes
We may update this policy; material changes will be reflected by the “Last updated” date above.