# Privacy Policy — OpenKiti

**Effective Date:** September 27, 2026  
**Last Updated:** September 27, 2026  
**Entity:** Astomverse Innovations Private Limited  
**Website:** https://www.openkiti.in/  
**Contact:** naveen.astomverse@gmail.com  

---

## 1. Introduction
OpenKiti is an autonomous AI agent platform that connects to API specifications, knowledge bases, and third-party software integrations. OpenKiti is a product of **Astomverse Innovations Private Limited**.

This Privacy Policy describes how Astomverse Innovations Private Limited collects, uses, processes, stores, and protects information when you visit our website, connect external services (such as Google Workspace or Meta/Instagram accounts), embed our copilot widget, or interact with OpenKiti services.

By accessing or using OpenKiti, you acknowledge that you have read and understood the data practices described in this policy.

---

## 2. Information We Collect
We collect information necessary to operate our platform, execute configured AI workflows, bill for credit consumption, maintain account security, and provide customer support:

- **Account & Identity Information:** Full name, email address, password hashes (hashed using argon2), organization name, workspace configurations, and account credentials submitted during registration.
- **Workspace & Integration Inputs:** OpenAPI and Postman API specifications, knowledge base documents, agent configurations, prompt instructions, workflow triggers, and custom API connection endpoints.
- **Connected Integration Data:** Data retrieved from authorized third-party integrations (such as Google Workspace and Instagram/Meta Graph APIs), including profile details, messages, emails, calendar events, spreadsheet ranges, posts, and comments required to complete user-initiated agent tasks.
- **AI Execution & Query Logs:** Natural language prompts, agent execution step logs, task mapping records, completion responses, model latency, error traces, and token usage metadata.
- **Billing & Subscription Records:** Subscription plan tier, monthly credit allocation balances, transaction history, and credit usage events. Payment card processing is performed directly by third-party payment gateways; OpenKiti does not store raw payment card numbers.

---

## 3. How We Use Information
We use the collected information for the following specific purposes:
- To provide, maintain, and execute OpenKiti's autonomous AI agent operations and API workflows.
- To authenticate user identity, manage workspace permissions, and issue platform API keys.
- To process user prompts through connected language model providers and return generated responses.
- To synchronize authorized external tools (such as Gmail, Google Calendar, Google Sheets, Google Meet, and Instagram) according to workspace rules.
- To calculate token consumption, manage monthly workspace credit balances, and process subscription billing.
- To monitor service availability, detect platform abuse or unauthorized access, and perform technical debugging.
- To communicate regarding platform updates, account security notifications, or technical support requests.

*OpenKiti does not use customer content, API data, or connected account data to train public foundation AI models.*

---

## 4. Google API Data
OpenKiti allows users to connect their Google Workspace accounts to enable AI agents to perform automated operations across Google services.

### Google Scopes Requested & Purpose
Depending on the features enabled by the user, OpenKiti requests access to the following specific Google OAuth scopes:
- **Identity (`openid`, `userinfo.email`, `userinfo.profile`):** To authenticate the user and display connected Google account details (email address and profile name).
- **Gmail APIs (`gmail.send`, `gmail.compose`, `gmail.labels`, `gmail.readonly`, `gmail.modify`, `gmail.metadata`):** To allow authorized agents to read email metadata, search messages, manage labels, compose draft responses, or send automated email communications on behalf of the user.
- **Google Calendar APIs (`calendar.freebusy`, `calendar.events.readonly`, `calendar.events`, `calendar.events.owned`, `calendar.calendarlist`, `calendar.calendars`, `calendar.settings.readonly`, `calendar`):** To retrieve event schedules, check free/busy availability, create meeting invites, and manage calendar entries according to user instructions.
- **Google Sheets APIs (`spreadsheets.readonly`, `spreadsheets`):** To read spreadsheet cell ranges, query rows, and update spreadsheet data as directed by AI agent workflows.
- **Google Meet APIs (`meetings.space.settings`, `meetings.space.created`, `meetings.space.readonly`):** To create meeting spaces, retrieve conference records, and access meeting session details for workflow automation.

### Storage & Protection of Google Credentials
Google OAuth access tokens and refresh tokens are encrypted at rest in our database using key-managed encryption (`tokenEncryptionKeyId`). Synced metadata is stored in restricted database models solely to maintain workspace state and power search operations.

### Google API Limited Use Disclosure
OpenKiti's use and transfer to any other app of information received from Google APIs will adhere to the [Google API Services User Data Policy](https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements:
- Google user data is used solely to provide or improve user-facing features prominent in OpenKiti's user interface.
- Google user data is not transferred to third parties except as necessary to provide or improve these features, comply with applicable law, or as part of a merger/acquisition.
- Google user data is not used for serving advertisements.
- Human personnel do not read Google user data unless authorized by the user for support troubleshooting, required by law, or aggregated for internal system performance analysis.

### Disconnecting Google Accounts
Users can disconnect their Google account at any time through the OpenKiti integration settings. Disconnection invokes Google's OAuth revocation endpoint to invalidate tokens, revokes stored credentials, and marks the integration status as disconnected. To permanently purge historical metadata, users may submit a verified data deletion request.

---

## 5. Instagram / Meta Data
OpenKiti provides native integration with Meta and Instagram Graph APIs for connected Instagram Professional Accounts (Business or Creator accounts). We operate strictly in compliance with the [Meta Platform Terms](https://developers.facebook.com/terms/#datause) and Meta Developer Policies.

> **Platform Non-Affiliation & Trademark Notice:** OpenKiti is an independent software platform developed and operated by Astomverse Innovations Private Limited. OpenKiti is not affiliated with, sponsored by, or endorsed by Meta Platforms, Inc., Instagram, Facebook, WhatsApp, Google LLC, or Google Workspace. Instagram, Facebook, and WhatsApp are trademarks of Meta Platforms, Inc. Google and Google Workspace are trademarks of Google LLC. OpenKiti integrates with these platforms through their official, publicly documented APIs and developer interfaces, in accordance with their applicable platform terms, policies, and requirements.

### Meta API Scopes Requested & Functional Purpose
OpenKiti requests only the minimum necessary Meta Graph API permissions required to deliver customer support and messaging automation features explicitly activated by the workspace owner:
- **`public_profile`**: To securely authenticate the user via Meta/Facebook Login and display their name and profile identity in their OpenKiti account.
- **`email`**: To retrieve the primary email address associated with the user's Meta account for workspace account verification and critical service communications.
- **`instagram_basic`**: To retrieve basic account identity (account ID, username, profile name, and profile picture) to verify account ownership and display connected Instagram account status within the workspace dashboard.
- **`instagram_manage_messages`**: To receive inbound customer Direct Messages (DMs) via real-time webhooks, allow assigned AI agents to parse customer intent against verified business knowledge, and send automated, context-aware responses or transfer the conversation to human team members.
- **`instagram_manage_comments`**: To listen for customer comments on published Instagram posts and reels in real time, analyze inquiries, and automatically post helpful replies or filter spam.
- **`pages_manage_metadata`**: To subscribe the connected Facebook Page to webhook subscriptions required to receive real-time notifications for incoming Instagram messages and comments.
- **`pages_show_list`**: To display the list of Facebook Pages managed by the user so they can select and link the relevant Page connected to their Instagram Professional Account.

### Categories of Data Collected
- **Account & Profile Information:** Connected Instagram Professional Account ID, linked Facebook Page ID, username, profile details, and account identifiers.
- **Instagram Posts & Media:** Published media details including post ID, caption, media type, permalink, and publication timestamp for content viewing and comment tracking.
- **Instagram Comments:** Customer comments and replies posted on published Instagram media (including comment text, commenter handles/usernames, and comment timestamps), retrieved to display in the OpenKiti workspace and enable AI agents to generate and post replies.
- **Instagram Direct Messages & Message Content:** Inbound and outbound customer Direct Messages (including message content/text, sender handles/usernames, conversation threads, and delivery timestamps), retrieved to display conversation threads and enable assigned AI agents to process messages and send responses.
- **Access Credentials:** Meta/Instagram OAuth access tokens authorizing OpenKiti to interact with authorized Meta APIs.
- **Webhook Event Subscriptions:** Interaction events and notifications required to receive real-time Instagram comments and Direct Messages.

### How Instagram Data Is Used
Instagram data is processed strictly to provide the Instagram integration and customer support AI functionality. Specifically, data is used to identify connected accounts, synchronize and display published media, organize comments and message threads, and power configured AI agents to send automated replies to customer comments and Direct Messages.

### Storage & Credential Security
Meta/Instagram OAuth access tokens are stored in encrypted format. All credentials are encrypted at rest using key-managed encryption.

### Disconnecting Instagram Accounts
Users can disconnect the Instagram integration at any time via OpenKiti workspace settings. Upon disconnection, OpenKiti revokes stored OAuth access tokens, ceases background synchronization, and marks the integration status as disconnected. To permanently purge all historical records and interaction history, workspace owners can submit a verified data deletion request.

### Technical Service Provider & Multi-Tenant Data Isolation (Meta Section 5)
OpenKiti acts strictly as a Technical Service Provider (data processor) to our business customers who connect their Instagram accounts. In strict accordance with Section 5 of the Meta Platform Terms:
- **Multi-Tenant Logical Isolation:** Each customer workspace operates in a strictly isolated logical tenant environment. Instagram Direct Messages, comment threads, customer interaction history, and leads belonging to one business client are strictly segregated and can never be accessed, queried, or commingled with any other client's workspace.
- **Processing Solely on Behalf of Client:** OpenKiti processes Meta Platform Data solely on behalf of and according to the instructions and configurations of the connected business client. We never use client Platform Data for our own independent commercial purposes, marketing, or cross-tenant analytics.

### Data Retention & Deletion Schedule (Meta Section 3.d)
We maintain strict data lifecycle rules to ensure Meta Platform Data is retained only for as long as strictly necessary:
- **Active Integration Support:** Conversation threads and Customer 360 memory are retained only while the business maintains an active connection to OpenKiti to provide uninterrupted customer support.
- **Transient Webhook Payloads & Diagnostic Logs:** Ephemeral webhook payloads, raw request logs, and temporary caching entries are automatically purged within thirty (30) days.
- **Immediate Revocation Upon Disconnection:** Disconnecting the Instagram integration in the dashboard immediately invalidates and revokes stored OAuth access tokens and ceases background synchronization. To permanently purge all historical records and interaction history, workspace owners can submit a verified data deletion request.

### Meta Platform Terms Compliance & Restrictions (Section 3: Data Use)
In strict adherence to the [Meta Platform Terms (Section 3: Data Use)](https://developers.facebook.com/terms/#datause) and Meta Developer Policies, OpenKiti enforces the following data protections:
- **No AI/ML Model Training:** OpenKiti will not use Meta/Instagram Platform Data (including customer Direct Messages, comments, captions, media metadata, or profile information) to build, train, retrain, or fine-tune machine learning or artificial intelligence models without Meta's prior written permission.
- **No Selling, Licensing, or Transferring:** OpenKiti will never sell, rent, lease, license, or transfer Meta Platform Data to any third-party data brokers, advertising networks, or unauthorized entities.
- **No Surveillance or Profiling:** Meta Platform Data is never processed to conduct surveillance, track users across third-party services, assess creditworthiness, or build independent user profiles without express consent.
- **Limited to App Functionality:** OpenKiti requests and uses only the minimum restricted Platform Data necessary to operate the authorized customer support and workflow automation features explicitly enabled by the user.
- **User Data Deletion Guarantee:** Users can disconnect the integration or submit a data deletion request at any time via our [Data Deletion Request Page](https://www.openkiti.in/data-deletion) or by emailing `naveen.astomverse@gmail.com`.

---

## 6. AI and Third-Party Services
OpenKiti integrates with third-party artificial intelligence model providers to process prompts and execute complex agent logic. Depending on workspace configuration, requests may be routed to Google Gemini, DeepSeek, or self-hosted Ollama instances. Third-party providers process data in accordance with their commercial API terms.

---

## 7. Usage and Billing Information
We record request timestamps, model selection, prompt token counts, completion token counts, latency metrics, and credit cost calculations per workspace (`LlmUsage` and `CreditUsageEvent` records) to track plan limits, manage credit allocations, prevent service abuse, and generate workspace usage reports.

---

## 8. Data Sharing
Astomverse Innovations Private Limited does not sell personal information, customer data, or Meta Platform Data to third-party data brokers or advertising networks. We share information only with third-party service providers acting on our behalf strictly as necessary to provide and operate the service, including cloud hosting, database infrastructure, configured AI model providers, payment gateways, and email services (such as EmailJS).

---

## 9. Data Storage and Retention
Data is stored in secure PostgreSQL database infrastructure. We retain account credentials, workspace settings, API specifications, and transaction logs for as long as your account remains active or as required by law.

---

## 10. Security & Incident Notification
We implement technical and organizational security measures to safeguard data against unauthorized access, destruction, loss, alteration, or disclosure:
- **Encryption at Rest:** All OAuth tokens (Google tokens and Meta/Instagram long-lived page tokens) and sensitive credentials are encrypted at rest using industry-standard AES-256-GCM / key-managed encryption (`tokenEncryptionKeyId`). Password hashes are securely stored using Argon2.
- **Encryption in Transit:** All data transmissions between clients, servers, and external third-party APIs (including Meta and Google endpoints) are enforced over HTTPS with TLS 1.3 encryption.
- **Multi-Tenant Access Isolation:** Role-based access controls (RBAC) and tenant scoping guarantee that database queries and cached payloads are isolated strictly to the authorized workspace.
- **24-Hour Security Incident Notification (Meta Section 6 Compliance):** In accordance with Section 6 of the Meta Platform Terms, in the event of any confirmed security breach, unauthorized access, or security incident involving Meta Platform Data, OpenKiti commits to notifying Meta and affected users in writing within twenty-four (24) hours of becoming aware of the incident.
- **Vulnerability Reporting:** If you identify a potential security issue or vulnerability, please notify our security team immediately at `naveen.astomverse@gmail.com` with the subject line *"Security Disclosure"*.

---

## 11. Account and Integration Disconnection
Users may disconnect connected integrations (such as Google Workspace or Instagram) at any time through their OpenKiti dashboard, immediately revoking access authorization and invalidating credentials.

---

## 12. Data Deletion
You have the right to request deletion of your account, workspace data, uploaded specifications, or contact submission records. To submit a data deletion request, email `naveen.astomverse@gmail.com` with your registered account details, or follow our step-by-step instructions on our dedicated [Data Deletion Request Page](https://www.openkiti.in/data-deletion). Upon receipt of a verified request, we will delete or permanently anonymize applicable data as soon as reasonably possible, targeting completion within thirty (30) days, unless retention is mandated by law.

---

## 13. User Rights and Choices
Depending on your location, you may have rights regarding your personal data, including the right to access, update, correct, export, or request restriction of data processing.

---

## 14. Children's Privacy
OpenKiti is a commercial SaaS application designed for business and developer use. We do not knowingly collect personal information from individuals under 18 years of age.

---

## 15. Changes to This Policy
We may update this Privacy Policy periodically. Updated versions will be published on this page with a revised "Last updated" date.

---

## 16. Contact Us
**Astomverse Innovations Private Limited**  
Product: OpenKiti  
Email: naveen.astomverse@gmail.com  
Phone: +91 62066 59034  
Address: Room No 1, 3rd Floor, Incubation Centre, NIT, Mahendru, Sampatchak, Patna - 800006, Bihar, India
