Legal
Privacy Policy
Last updated 30 September 2026
Jawab, operated by JawabAI, is an AI assistant that replies to customer messages on Instagram and Facebook using a merchant's own product catalog and knowledge base. This policy explains what we collect from your Shopify store and connected messaging accounts, what we do with it, who else processes it, and how to have it deleted.
What we collect
We collect only what the service needs to answer your customers' questions. We do not collect payment card numbers — those are handled by our payment processor and never reach our servers.
- Account information
- The name, email address and password hash you create when you sign up for Jawab, plus your brand and workspace settings.
- Shopify store data
- Your store domain, currency, and your product catalog: titles, descriptions, images, variants, SKUs, prices and inventory levels. We request read-only access and never modify your store.
- Messaging data
- Messages sent to and from your connected Instagram and Facebook accounts, along with the sender's platform ID and display name, so conversations can be threaded and answered.
- Knowledge base content
- Documents, FAQs, policies and other material you upload or write so the assistant can answer from your own information.
- Access tokens
- Encrypted tokens issued by Shopify and Meta that let Jawab read your catalog and send replies on your behalf.
- Technical logs
- Request logs, error traces and timestamps used to keep the service secure, diagnose faults and prevent abuse.
How we use it
- To answer customer questions using your catalog, so replies quote your real products, prices and stock levels.
- To route a conversation to your team when the assistant is not confident enough to answer.
- To keep your synced catalog current when products or inventory change in your store.
- To show you conversation history, analytics and quota usage in your dashboard.
- To operate, secure, troubleshoot and improve the service.
- To bill you for your subscription and provide support.
We do not use your data, your catalog or your customers' messages to train our own machine learning models, and we do not sell personal data to anyone.
AI processing
Generating a reply means sending content to a third-party AI provider. We think you should know exactly what leaves our systems.
When a customer messages you, the message text, relevant excerpts from your knowledge base, and matching products from your catalog are sent to our AI provider to compose a reply. Your knowledge base is also converted into numerical embeddings by an embeddings provider so the assistant can find the right passage to answer from.
These providers act as processors on our behalf under contract. They do not use your content to train their models. Voice notes are transcribed on our own infrastructure and are not sent to a third-party transcription service.
Retention and deletion
We keep data only as long as it is needed to provide the service to you.
- Message content is deleted automatically 30 days after a conversation's last activity. Conversations still waiting for the merchant's team to step in are kept until the team has handled them. Counts used for analytics (such as the number of conversations and orders) are kept without the message text.
- Uninstalling the app from your Shopify store removes the connection and deletes the product catalog we synced from it, along with the stored access tokens for that store.
- Closing your Jawab account deletes your brand, conversations, knowledge base and settings.
- If a merchant asks us to erase a specific customer's data, we delete that customer's messages and any related records within 30 days.
- If a merchant asks us to erase all data for a store, we delete it within 48 hours of the request.
- Technical logs are retained for a limited period for security and diagnostics, then deleted.
We may retain a minimal record of billing transactions where we are required to for tax and accounting purposes.
How we protect it
- Access tokens for Shopify and Meta are encrypted at rest using AES-256-GCM.
- All traffic between your browser, our services and third-party APIs is encrypted in transit over TLS.
- Every record is scoped to a single brand, and database row-level security keeps one merchant's data inaccessible to another.
- Incoming webhooks are verified by cryptographic signature so we only accept data genuinely sent by Shopify or Meta.
- Access to production systems is limited to staff who need it to operate the service.
No system is perfectly secure. If a breach ever affects your data, we will notify you and the relevant authorities as required by law.
Your rights
Depending on where you live, you may have the right to access, correct, export or delete your personal data, to object to or restrict how we process it, and to withdraw consent.
Merchants can export or delete most data from the Jawab dashboard. For anything else, email us at Support@jawabai.app and we will respond within 30 days.
If you are a customer who messaged a brand using Jawab, the brand controls that conversation. Contact the brand directly, or write to us and we will pass your request on.
Children's data
Jawab is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child's data has reached us, contact us and we will delete it.
Changes to this policy
We may update this policy as the service changes. The date at the top always reflects the current version, and we will notify merchants by email before any change that materially affects how we handle their data.
Contact us
For privacy questions, data requests or anything else about this policy: