Privacy Policy
Butterchat · Last updated: 22 August 2026 · Effective: 22 August 2026
This Privacy Policy explains how Butterchat ("Butterchat", "we", "us", or "our") collects, uses, shares, retains, and protects information when you use our customer-engagement and social-inbox platform available at https://app.studiobutterfly.io and related services, APIs, chat widgets, and integrations (collectively, the "Service").
Butterchat helps businesses ("Customers") manage conversations across messaging channels including Facebook Messenger, Instagram, and WhatsApp (provided by Meta Platforms, Inc., "Meta"), as well as a website chat widget. We answer and route incoming messages using AI and human agents. This policy describes our practices and our compliance with the Meta Platform Terms, Meta Developer Policies, and the WhatsApp Business Messaging Policy.
1. Information We Collect
1.1 Business / Customer account data
- Account and profile details: name, work email, company name, role, password (stored hashed), and team/department membership.
- Configuration you create: AI agent settings, knowledge-base documents you upload, saved replies, posts, comment rules, and conversation settings.
- Billing and subscription metadata where applicable.
1.2 Data received from Meta (Facebook, Instagram, Messenger)
When a business connects a Facebook Page or linked Instagram Business account via Facebook Login, we receive and process:
- The connecting user's basic profile (name, Facebook user ID) and email, as authorized through
public_profileandemail. - The list of Facebook Pages the user manages, Page IDs, Page names, and Page access tokens.
- Page and linked Instagram content: posts, drafts, comments, reactions, and engagement metrics.
- Messenger and Instagram conversations: message content, attachments, timestamps, and Page-Scoped IDs (PSIDs) of the people messaging the Page.
- The set of permissions actually granted during consent ("granted scopes").
1.3 Data received from WhatsApp Business
- WhatsApp Business Account (WABA) ID, phone number ID, and display phone number.
- Customer phone numbers and profile names provided by WhatsApp.
- Message content, media, message templates, status events (delivered/read), and timestamps necessary to send and receive messages.
1.4 End-customer conversation data (web widget & all channels)
- Messages, attachments, and metadata exchanged between an end customer and a business.
- Customer identifiers (channel-specific ID, name, phone or email if provided), conversation tags, summaries, and assignment/escalation history.
1.5 Technical & usage data
- IP address, device/browser information, log data, and cookies or similar technologies used to keep you signed in and to operate the chat widget.
1.6 Data from connected commerce, payment & delivery services
If a business enables commerce, checkout, or order-fulfilment features, we exchange data with the third-party services the business connects, only as needed to provide those features:
- Ecommerce platforms (such as Shopify and WooCommerce): product catalogs, inventory, orders, order status, and associated customer details (name, contact information, shipping/billing address, order items) so the business and its AI agent can look up, place, cancel, or modify orders.
- Payment gateways (such as bKash and SSLCommerz): payment initiation and status information. Sensitive payment credentials (for example, full card or wallet numbers and PINs) are entered on and handled by the gateway, not stored by Butterchat; we receive transaction identifiers and status.
- Courier & delivery services (such as Steadfast and Pathao): the recipient details required to create and track a shipment, including customer name, phone number, and delivery address.
2. How We Use Meta & WhatsApp Permissions
We request only the permissions needed to deliver features a business has enabled, and we use data obtained through Meta APIs only to provide and improve the Service for that business — never to build independent profiles, and never for unauthorized advertising. The specific Meta permissions we request and why:
| Permission (scope) | Why we use it |
|---|---|
pages_show_list | Let the business select which of their Facebook Pages to connect. |
pages_read_engagement | Read Page posts, comments, and engagement to display and manage them in the inbox. |
pages_manage_posts | Create, schedule, edit, and delete posts on the business's own Page. |
pages_manage_engagement | Reply to and moderate comments and reactions on the business's content. |
pages_messaging | Send and receive Messenger and Instagram messages through the connected Page inbox. |
pages_manage_metadata | Subscribe the Page to webhooks so new messages and events reach the inbox in real time. |
ads_management | Read the business's promotable/unpublished (draft) posts so they can be listed and managed in the planner. |
public_profile, email | Identify the connecting user and contact them about the connection. |
Instagram is accessed through the connected Facebook Page's linked Instagram Business account using the Page permissions above; we do not request separate Instagram login credentials.
3. How We Use Information
- Operate the inbox: deliver, display, route, and reply to messages across connected channels.
- Generate AI-assisted replies grounded in the business's own knowledge base (Retrieval-Augmented Generation), and decide when to escalate a conversation to a human agent.
- Create conversation summaries and tags to help agents respond.
- Publish and schedule social posts and automate comment handling that the business configures.
- Authenticate users, secure the Service, prevent abuse, and provide support.
- Comply with legal obligations and enforce our terms.
We do not sell personal information, and we do not use message content for advertising or to train third-party foundation models for unrelated purposes.
4. AI Processing & Sub-processors
To provide AI features we share the minimum necessary content (such as a customer's question and relevant knowledge-base context) with our AI sub-processor(s), including OpenAI, to generate embeddings and responses. These providers act under contractual confidentiality and data-protection terms and are not permitted to use the data to train their general models where such terms apply. Other infrastructure sub-processors include our cloud hosting, database, vector-search, and queue providers. Where a business enables commerce, payment, or delivery features, the connected providers named in Section 5 also act as sub-processors or independent controllers for the data exchanged with them. A current list of sub-processors is available on request via hello@studiobutterfly.io.
5. How We Share Information
- With the business you contacted: end-customer messages are made available to the business operating the connected channel and its authorized agents.
- With Meta and WhatsApp: to send and receive messages and content via their APIs, subject to their terms.
- With sub-processors: service providers that host, process, or secure data on our behalf (Section 4).
- For legal reasons: to comply with law, lawful requests, or to protect rights, safety, and the integrity of the Service.
- Business transfers: in connection with a merger, acquisition, or asset sale, subject to this policy.
Connected commerce, payment & delivery providers. When a business enables these features, data is shared with the specific providers it connects, each of which handles that data under its own privacy policy:
| Provider | Purpose | Privacy policy |
|---|---|---|
| Shopify | Ecommerce store, products, orders | shopify.com/legal/privacy |
| WooCommerce | Ecommerce store, products, orders | automattic.com/privacy |
| bKash | Payment processing | bkash.com/en/page/privacy-notice |
| SSLCommerz | Payment processing | sslcommerz.com/privacy-policy |
| Steadfast | Courier / delivery | steadfast.com.bd/privacy |
| Pathao | Courier / delivery | pathao.com/privacy |
We share only the data needed for the feature the business has enabled, and a provider appears here only when the business connects it. This list may change as we add or remove integrations.
6. Data Retention
We retain personal data only as long as necessary to provide the Service, comply with legal obligations, resolve disputes, and enforce agreements. Conversation and message data is retained for the duration of the business's account and deleted or anonymized upon account termination or upon a valid deletion request, subject to limited retention required by law or for security. Page and WhatsApp access tokens are stored securely and revoked when a connection is removed.
7. Data Deletion & Your Choices
You can disconnect any Facebook, Instagram, or WhatsApp connection at any time from within the app, which revokes the associated tokens and stops further data processing for that channel. You may also remove Butterchat's access from your Meta Business Integrations settings.
To request deletion of data associated with your account or a connected Meta/WhatsApp identity, use our data deletion instructions at https://studiobutterfly.io/data-deletion or email hello@studiobutterfly.io. We will process verified requests promptly and confirm completion.
8. Your Rights
Depending on your location (including under the GDPR and CCPA/CPRA), you may have rights to access, correct, delete, port, or restrict processing of your personal data, and to object to certain processing. Because Butterchat often acts as a processor for a business, requests about end-customer data may be directed to that business; we will assist them in responding. To exercise your rights, contact hello@studiobutterfly.io.
9. International Data Transfers
We may process and store information in countries other than where you reside. Where required, we use appropriate safeguards (such as Standard Contractual Clauses) for cross-border transfers.
10. Security
We use technical and organizational measures to protect data, including encryption in transit, access controls, multi-tenant isolation so one business cannot access another's data, and secure storage of credentials and access tokens. No method of transmission or storage is completely secure, but we work to protect your information and to notify affected parties of incidents as required by law.
11. Cookies
We use strictly necessary cookies and similar technologies to authenticate users and operate the chat widget. You can control cookies through your browser settings; disabling some cookies may affect the Service.
12. Children's Privacy
The Service is intended for businesses and is not directed to children under 16 (or the minimum age in your jurisdiction). We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.
13. Compliance with Meta & WhatsApp Policies
- We process Platform Data in accordance with the Meta Platform Terms and Developer Policies and only for the permitted purposes described above.
- We use WhatsApp in accordance with the WhatsApp Business Messaging Policy and Meta's WhatsApp Business Terms, including obtaining required opt-in before messaging and respecting messaging windows and template rules.
- We do not sell or transfer Platform Data to data brokers, ad networks, or monetization partners.
- We retain Platform Data only as long as needed and delete it when no longer required or upon request.
14. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the "Last updated" date above and, where appropriate, by additional notice. Continued use of the Service after changes take effect constitutes acceptance.
15. Contact Us
Butterchat is a product of Studio Butterfly (Lomba Limited), Dhaka, Bangladesh.
Email: hello@studiobutterfly.io
App: https://app.studiobutterfly.io
Website: https://studiobutterfly.io