Apexed (https://apexed.online) is a business automation platform that helps merchants train an AI assistant and connect it to channels such as Facebook Messenger. This Privacy Policy explains how we handle information when you use our website, application, and related services (collectively, the "Service").
1. Who this applies to
- Merchants — business owners who create an Apexed account, train their AI, and optionally connect a Facebook Page.
- End customers — people who message a merchant's connected Facebook Page via Messenger. We process those messages on the merchant's behalf to generate replies.
2. Information we collect
Account and authentication
- Email address and account identifiers when you register or sign in.
- If you use social login (Google, Apple, or Facebook), we receive profile information allowed by that provider (such as name and email) according to your settings with them.
- Session and security tokens needed to keep you signed in.
Business and AI training data
- Business profile information you provide during onboarding or in the dashboard (business name, type, hours, pricing, FAQs, policies, product descriptions, uploaded documents, and similar training content).
- Derived knowledge used by the AI (structured profile fields, text chunks, and embeddings stored to power accurate replies).
Facebook / Meta integration
When a merchant connects a Facebook Page, we receive data from Meta in accordance with Meta Platform Terms and the permissions the merchant grants:
- Facebook Page ID and Page name.
- Page access tokens (stored in encrypted form) to receive webhooks and send Messenger replies.
- Messenger messages sent to the connected Page, including message text and sender identifiers needed to reply in the conversation thread.
We do not use Meta data to build unrelated advertising profiles. We use it only to operate the Service for the merchant who connected the Page.
Technical and usage data
- Server logs (IP address, timestamps, request metadata) for security and debugging.
- Product usage events related to onboarding, training, and channel connectivity.
3. How we use information
- Provide, maintain, and improve the Service.
- Train and run the merchant's AI assistant using their business knowledge.
- Receive customer Messenger messages and send automated replies on behalf of the merchant.
- Authenticate users and protect against abuse or unauthorized access.
- Comply with law and enforce our Terms of Service.
We send message content to third-party AI providers only to generate replies for the merchant. We do not sell personal information.
4. Service providers
We use trusted infrastructure and subprocessors, including:
- Supabase — authentication and PostgreSQL database hosting.
- Render — application hosting for our AI engine and APIs.
- Qdrant Cloud — vector search for retrieval-augmented AI replies.
- AI model providers — such as DeepSeek and Google Gemini (and optionally others configured for your deployment) to process prompts and generate text responses.
- Meta / Facebook — when you connect a Page or use Messenger features, subject to Meta's policies.
These providers process data under our instructions and their own terms, only as needed to operate the Service.
5. Retention
We retain account and business data while your account is active and as needed to provide the Service. Messenger conversation data is retained to support ongoing customer threads and merchant history unless you request deletion or disconnect integrations. We may retain limited records where required for security, legal, or accounting purposes.
6. Security
We use industry-standard measures including HTTPS in transit, access controls, and encryption for sensitive tokens (such as Facebook Page access tokens). No method of transmission or storage is 100% secure; we work to protect data and review our practices regularly.
7. Your choices and rights
- Disconnect Facebook Page — in Apexed under Channels / Meta, which stops new Messenger processing for that Page.
- Delete data — see our Data Deletion Instructions.
- Access or correction — contact us to request access or updates to account information we hold.
Merchants are responsible for informing their customers about automated messaging, as required by applicable law and Meta policies.
8. Children
The Service is intended for businesses and is not directed to children under 13. We do not knowingly collect personal information from children.
9. International users
Our infrastructure and providers may process data in various countries. By using the Service, you understand that data may be transferred to jurisdictions with different data protection laws than your own.
10. Changes
We may update this Privacy Policy from time to time. We will post the revised version on this page and update the "Last updated" date. Continued use of the Service after changes constitutes acceptance of the updated policy.
11. Contact
Questions about this Privacy Policy or our data practices:
abril090853@gmail.com