Legal

Privacy Policy

Last updated: 18 August 2026

What BMAI accesses

BMAI connects to your Meta Business Portfolio using credentials you or your authorized administrator provide (a Meta System User access token or OAuth-issued token). BMAI reads and, where explicitly authorized, writes to Meta's Graph API and Marketing API on your behalf — Business Manager, ad account, Page, WhatsApp Business Account (asset status only, never message content), Instagram account, and product catalog data.

What BMAI does not access

BMAI does not read, store, or process customer-facing message content on WhatsApp or Messenger. This is a fixed boundary, not a configurable setting.

How credentials are stored

Meta access tokens are encrypted at rest and are never included in logs, error messages, or reports. Each connected business is isolated from every other connected business.

How data is used

Data read from Meta is used to power monitoring, case detection, audit reports, and the Founder Dashboard for the business that authorized the connection. It is not shared with, or used on behalf of, any other customer.

Data retention

Audit logs, case history, and monitoring results are retained to provide historical reporting and trend analysis. Access can be revoked, and the underlying Meta credential invalidated, at any time by the authorizing administrator.

Requesting deletion

To request removal of a connection's Meta access, see the Data Deletion page for the exact process, what is actually removed, and what is retained for security and audit reasons.

Third parties

BMAI's only external data connection is Meta's own official APIs. BMAI does not sell or share portfolio data with unrelated third parties.

Contact

Questions about this policy can be sent to hello@bodhari.com.