Privacy Policy

Effective Date: September 27, 2026 | Last Updated: September 27, 2026

Entity: Astomverse Innovations Private Limited

1. Introduction

OpenKiti is an autonomous AI agent platform that connects to API specifications, knowledge bases, and third-party software integrations. OpenKiti is a product of Astomverse Innovations Private Limited.

This Privacy Policy describes how Astomverse Innovations Private Limited collects, uses, processes, stores, and protects information when you visit our website, connect external services (such as Google Workspace or Meta/Instagram accounts), embed our copilot widget, or interact with OpenKiti services.

By accessing or using OpenKiti, you acknowledge that you have read and understood the data practices described in this policy.

2. Information We Collect

We collect information necessary to operate our platform, execute configured AI workflows, bill for credit consumption, maintain account security, and provide customer support:

  • Account & Identity Information: Full name, email address, password hashes (hashed using argon2), organization name, workspace configurations, and account credentials submitted during registration.
  • Workspace & Integration Inputs: OpenAPI and Postman API specifications, knowledge base documents, agent configurations, prompt instructions, workflow triggers, and custom API connection endpoints.
  • Connected Integration Data: Data retrieved from authorized third-party integrations (such as Google Workspace and Instagram/Meta Graph APIs), including profile details, messages, emails, calendar events, spreadsheet ranges, posts, and comments required to complete user-initiated agent tasks.
  • AI Execution & Query Logs: Natural language prompts, agent execution step logs, task mapping records, completion responses, model latency, error traces, and token usage metadata.
  • Billing & Subscription Records: Subscription plan tier, monthly credit allocation balances, transaction history, and credit usage events. Payment card processing is performed directly by third-party payment gateways; OpenKiti does not store raw payment card numbers.

3. How We Use Information

  • To provide, maintain, and execute OpenKiti's autonomous AI agent operations and API workflows.
  • To authenticate user identity, manage workspace permissions, and issue platform API keys.
  • To process user prompts through connected language model providers and return generated responses.
  • To synchronize authorized external tools (such as Gmail, Google Calendar, Google Sheets, Google Meet, and Instagram) according to workspace rules.
  • To calculate token consumption, manage monthly workspace credit balances, and process subscription billing.
  • To monitor service availability, detect platform abuse or unauthorized access, and perform technical debugging.
  • To communicate regarding platform updates, account security notifications, or technical support requests.

OpenKiti does not use customer content, API data, or connected account data to train public foundation AI models.

4. Google API Data

OpenKiti allows users to connect their Google Workspace accounts to enable AI agents to perform automated operations across Google services.

Google Scopes Requested & Purpose

  • Identity: openid, userinfo.email, userinfo.profile to authenticate the user and display connected Google account details.
  • Gmail APIs: gmail.send, gmail.compose, gmail.labels, gmail.readonly, gmail.modify, gmail.metadata to allow authorized agents to read email metadata, search messages, manage labels, compose draft responses, or send automated emails.
  • Google Calendar APIs: calendar.freebusy, calendar.events.readonly, calendar.events, calendar.events.owned, calendar.calendarlist, calendar.calendars, calendar.settings.readonly, calendar to retrieve event schedules, check free/busy availability, create meeting invites, and manage calendar entries.
  • Google Sheets APIs: spreadsheets.readonly, spreadsheets to read spreadsheet cell ranges, query rows, and update spreadsheet data as directed by workflows.
  • Google Meet APIs: meetings.space.settings, meetings.space.created, meetings.space.readonly to create meeting spaces, retrieve conference records, and access meeting session details.

Storage & Protection of Google Credentials

Google OAuth access tokens and refresh tokens are encrypted at rest in our database using key-managed encryption (tokenEncryptionKeyId).

Google API Limited Use Disclosure

OpenKiti's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is not used for serving advertisements and human personnel do not read Google user data.

Disconnecting Google Accounts

Users can disconnect their Google account at any time through the OpenKiti integration settings. Disconnection invokes Google's OAuth revocation endpoint to invalidate tokens, revokes stored credentials, and marks the integration status as disconnected. To permanently purge historical metadata, users may submit a verified data deletion request.

5. Instagram / Meta Data

OpenKiti provides native integration with Meta and Instagram Graph APIs for connected Instagram Professional Accounts (Business or Creator accounts). We operate strictly in compliance with the Meta Platform Terms and Meta Developer Policies.

Platform Non-Affiliation & Trademark Notice:

OpenKiti is an independent software platform developed and operated by Astomverse Innovations Private Limited. OpenKiti is not affiliated with, sponsored by, or endorsed by Meta Platforms, Inc., Instagram, Facebook, WhatsApp, Google LLC, or Google Workspace. Instagram, Facebook, and WhatsApp are trademarks of Meta Platforms, Inc. Google and Google Workspace are trademarks of Google LLC. OpenKiti integrates with these platforms through their official, publicly documented APIs and developer interfaces, in accordance with their applicable platform terms, policies, and requirements.

Meta API Scopes Requested & Functional Purpose

OpenKiti requests only the minimum necessary Meta Graph API permissions required to deliver customer support and messaging automation features explicitly activated by the workspace owner:

  • public_profile: To securely authenticate the user via Meta/Facebook Login and display their name and profile identity in their OpenKiti account.
  • email: To retrieve the primary email address associated with the user's Meta account for workspace account verification and critical service communications.
  • instagram_basic: To retrieve basic account identity (account ID, username, profile name, and profile picture) to verify account ownership and display connected Instagram account status within the workspace dashboard.
  • instagram_manage_messages: To receive inbound customer Direct Messages (DMs) via real-time webhooks, allow assigned AI agents to parse customer intent against verified business knowledge, and send automated, context-aware responses or transfer the conversation to human team members.
  • instagram_manage_comments: To listen for customer comments on published Instagram posts and reels in real time, analyze inquiries, and automatically post helpful replies or filter spam.
  • pages_manage_metadata: To subscribe the connected Facebook Page to webhook subscriptions required to receive real-time notifications for incoming Instagram messages and comments.
  • pages_show_list: To display the list of Facebook Pages managed by the user so they can select and link the relevant Page connected to their Instagram Professional Account.

Categories of Data Collected

When a business connects an Instagram Professional Account via Meta OAuth authentication, OpenKiti collects and processes:

  • Account & Profile Information: Connected Instagram Professional Account ID, linked Facebook Page ID, handle/username, profile details, and account identifiers.
  • Instagram Posts & Media: Published media details including post ID, caption, media type, permalink, and publication timestamp for content viewing and comment tracking.
  • Instagram Comments: Customer comments and replies posted on published Instagram media (including comment text, commenter handles/usernames, and comment timestamps), retrieved to display in the OpenKiti workspace and enable AI agents to generate and post replies.
  • Instagram Direct Messages & Message Content: Inbound and outbound customer Direct Messages (including message content/text, sender handles/usernames, conversation threads, and delivery timestamps), retrieved to display conversation threads and enable assigned AI agents to process messages and send responses.
  • Access Credentials: Meta/Instagram OAuth access tokens authorizing OpenKiti to interact with authorized Meta APIs.
  • Webhook Event Subscriptions: Real-time interaction events and delivery notifications required to receive incoming Instagram comments and Direct Messages.

How Instagram Data Is Used

Instagram data is processed strictly to provide the Instagram integration and customer support AI functionality. Specifically, data is used to identify connected accounts, synchronize and display published media, organize comments and message threads, and power configured AI agents to send automated replies to customer comments and Direct Messages.

Technical Service Provider & Multi-Tenant Data Isolation (Meta Section 5)

OpenKiti acts strictly as a Technical Service Provider (data processor) to our business customers who connect their Instagram accounts. In strict accordance with Section 5 of the Meta Platform Terms:

  • Multi-Tenant Logical Isolation: Each customer workspace operates in a strictly isolated logical tenant environment. Instagram Direct Messages, comment threads, customer interaction history, and leads belonging to one business client are strictly segregated and can never be accessed, queried, or commingled with any other client's workspace.
  • Processing Solely on Behalf of Client: OpenKiti processes Meta Platform Data solely on behalf of and according to the instructions and configurations of the connected business client. We never use client Platform Data for our own independent commercial purposes, marketing, or cross-tenant analytics.

Data Retention & Deletion Schedule (Meta Section 3.d)

We maintain strict data lifecycle rules to ensure Meta Platform Data is retained only for as long as strictly necessary:

  • Active Integration Support: Conversation threads and Customer 360 memory are retained only while the business maintains an active connection to OpenKiti to provide uninterrupted customer support.
  • Transient Webhook Payloads & Diagnostic Logs: Ephemeral webhook payloads, raw request logs, and temporary caching entries are automatically purged within thirty (30) days.
  • Immediate Revocation Upon Disconnection: Disconnecting the Instagram integration in the dashboard immediately invalidates and revokes stored OAuth access tokens and ceases background synchronization. To permanently purge all historical records and interaction history, workspace owners can submit a verified data deletion request.

Meta Platform Terms Compliance & Restrictions (Data Use)

In strict adherence to the Meta Platform Terms (Section 3: Data Use) and Developer Policies, OpenKiti strictly enforces the following data protections:

  • No AI/ML Foundation Model Training: OpenKiti will not use Meta/Instagram Platform Data (including customer Direct Messages, comments, captions, media metadata, or profile information) to build, train, retrain, or fine-tune machine learning or artificial intelligence models without Meta's prior written permission.
  • No Selling, Licensing, or Transferring: OpenKiti will never sell, rent, lease, license, or transfer Meta Platform Data to any third-party data brokers, advertising networks, or unauthorized entities.
  • No Surveillance, Profiling, or Eligibility Determinations: Meta Platform Data is never processed to conduct surveillance, track users across third-party services, assess creditworthiness, determine eligibility for housing, employment, or insurance, or build unauthorized independent user profiles.
  • Limited to App Functionality: OpenKiti requests and uses only the minimum restricted Platform Data necessary to operate the authorized customer support and workflow automation features explicitly enabled by the user.
  • User Data Deletion Guarantee: Users can disconnect the integration or submit a data deletion request at any time via our Data Deletion Request Page or by emailing [email protected].

6. AI and Third-Party Services

OpenKiti integrates with third-party artificial intelligence model providers (Google Gemini, DeepSeek, and self-hosted Ollama instances) to process prompts and execute complex agent logic. Third-party providers process data in accordance with their commercial API terms.

7. Usage and Billing Information

We record request timestamps, model selection, prompt token counts, completion token counts, latency metrics, and credit cost calculations per workspace (LlmUsage and CreditUsageEvent records) to track plan limits, manage credit allocations, prevent service abuse, and generate workspace usage reports.

8. Data Sharing

Astomverse Innovations Private Limited does not sell personal information, customer data, or Meta Platform Data to third-party data brokers or advertising networks. We share information only with third-party service providers acting on our behalf strictly as necessary to provide and operate the service, including cloud hosting, database infrastructure, configured AI model providers, payment gateways, and email services (such as EmailJS).

9. Data Storage and Retention

Data is stored in secure PostgreSQL database infrastructure. We retain account credentials, workspace settings, API specifications, and transaction logs for as long as your account remains active or as required by operational, accounting, and legal requirements.

10. Security & Incident Notification

We implement comprehensive technical and organizational security safeguards to protect personal data and connected platform data against unauthorized access, destruction, loss, alteration, or disclosure:

  • Encryption at Rest: All OAuth tokens (Google tokens and Meta/Instagram long-lived page tokens) and sensitive credentials are encrypted at rest using industry-standard AES-256 / key-managed encryption (tokenEncryptionKeyId). Password hashes are securely stored using Argon2.
  • Encryption in Transit: All data transmissions between clients, servers, and external third-party APIs (including Meta and Google endpoints) are enforced over HTTPS with TLS 1.3 encryption.
  • Multi-Tenant Access Isolation: Role-based access controls (RBAC) and tenant scoping guarantee that database queries and cached payloads are isolated strictly to the authorized workspace.
  • 24-Hour Security Incident Notification (Meta Section 6 Compliance): In accordance with Section 6 of the Meta Platform Terms, in the event of any confirmed security breach, unauthorized access, or security incident involving Meta Platform Data, OpenKiti commits to notifying Meta and affected users in writing within twenty-four (24) hours of becoming aware of the incident.
  • Vulnerability Reporting: If you identify a potential security issue or vulnerability, please notify our security team immediately at [email protected] with the subject line "Security Disclosure". We investigate all valid submissions promptly.

11. Account and Integration Disconnection

Users may disconnect connected integrations (such as Instagram or other channels) at any time through the Channels > Settings section in their OpenKiti dashboard to immediately revoke access authorization and invalidate credentials.

12. Data Deletion

You have the right to request deletion of your account, workspace data, uploaded specifications, or contact submission records.

To submit a data deletion request, email [email protected] with your registered account details, or follow our step-by-step instructions on our dedicated Data Deletion Instructions page. Upon receipt of a verified request, we will delete or permanently anonymize applicable data as soon as reasonably possible, targeting completion within thirty (30) days, unless retention is mandated by law.

13. User Rights and Choices

Depending on your location, you may have rights regarding your personal data, including the right to access, update, correct, export, or request restriction of data processing.

14. Children's Privacy

OpenKiti is a commercial SaaS application designed for business and developer use. We do not knowingly collect personal information from individuals under 18 years of age.

15. Changes to This Policy

We may update this Privacy Policy periodically to reflect changes in our service or legal requirements. Updated versions will be published on this page with a revised "Last updated" date.

16. Contact Us

Astomverse Innovations Private Limited

Product: OpenKiti

Email: [email protected]

Phone: +91 62066 59034

Address: Room No 1, 3rd Floor, Incubation Centre, NIT, Mahendru, Sampatchak, Patna- 800006, Bihar, India