Privacy policy

Latest update:

May 12, 2026

Introduction

Alfred ("we", "our", "us") provides an AI-powered messaging assistant that helps businesses reply to customer messages on WhatsApp, Facebook Messenger, Instagram Direct, and a web chat widget. Alfred can also connect to Google Calendar so businesses can check availability and sync bookings. This page explains what data we collect, how we use it, and how to delete it.

Who Controls This App

Alfred is operated by 01 Digital. Contact [email protected].

What We Collect

Business owner account info: when an administrator connects a Facebook Page or Instagram Business account, we store the access token, account name, account ID (Page ID or Instagram user ID), and the linked admin's App-Scoped ID. We do not store personal Facebook or Instagram passwords.

Customer messages: messages sent to a connected Page or Instagram account are received via Meta's webhooks, including the sender's platform-scoped ID (PSID/IGSID), the message text, and timestamps. We use this to generate the AI reply and to display the conversation in the business owner's admin dashboard.

Google Calendar connection data: when an administrator connects Google Calendar, we store the connected Google account email, selected calendar ID, OAuth access and refresh tokens, token expiry, free/busy availability responses, and booking event IDs created, updated, or deleted by Alfred. We do not store Google account passwords.

Generated replies: AI-generated responses are stored alongside the incoming message so the business can review them.

Usage logs: standard server logs (timestamp, status code, IP) for security and debugging. Retained for 30 days.

What We Do Not Collect

We do not collect customer phone numbers from Facebook or Instagram conversations unless the customer voluntarily shares them in the chat.

We do not access any Facebook or Instagram data outside of the explicit permissions the connecting admin grants (page messaging, IG business messaging).

We do not read Google Calendar data beyond what is needed to check availability and sync booking events.

We do not use Google Calendar data for advertising, sell it, or use it to train AI models.

We do not sell or share data with advertisers or third parties for marketing.

How We Use the Data

Generate AI replies to inbound customer messages.

Show conversation history to the connected business owner in their admin dashboard.

Send the AI's reply (or a human operator's reply) back through Meta's Send APIs.

Check Google Calendar availability for booking times requested by the business or its customers.

Create, update, or remove Google Calendar events that correspond to bookings managed in Alfred.

Operational analytics (number of conversations, response time) for the business owner only.

Where Data Is Stored

All data is stored on servers operated by 01 Digital. Access tokens are stored at rest. We do not transfer data outside of the operating region except as needed for the AI inference provider used to generate replies (currently OpenAI). Alfred's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Retention

Conversation data is retained for as long as the business owner's connection is active, plus 90 days after disconnect for support and audit. Access tokens are deleted immediately on disconnect. Google Calendar tokens are retained only while the calendar connection is active and are deleted when the business disconnects Google Calendar. Booking event IDs are retained with the related booking records until the business deletes them or the retention period ends.

Deleting Your Data

If you are a customer who messaged a business that uses Alfred and want your messages removed, contact the business directly or email [email protected] with the platform (Facebook/Instagram) and the business name. We will remove your messages within 30 days.

If you are a business owner, click "Disconnect" on the Facebook Messenger, Instagram, or Google Calendar integration card in the admin dashboard. This revokes the access token and deactivates webhooks or calendar sync. To permanently delete all associated conversation history or booking sync records, email us with your tenant ID. You may also revoke Google access from your Google Account permissions page.

Meta's automated data deletion callback is wired to our endpoint; when a user removes our app from their Facebook or Instagram settings, we automatically disable that connection and clear stored access tokens.

Security

Webhooks are verified via Meta's X-Hub-Signature-256 HMAC. Admin sessions use short-lived JWT access tokens with refresh rotation. Access tokens, including Google OAuth tokens, are read only by server-side workers; never exposed to the browser.

Changes

If we make material changes to this policy we will post the updated version here and update the "Last updated" date above. See also our Terms of Service.

Contact

Questions about this Privacy Policy or how we handle your data? Email us at: [email protected]

Let Alfred learn about your business

© 2026 Alfred · Built for SingaporeSite made by 0123 Digital Pte. Ltd.