Privacy Policy

Last updated: July 27, 2026

This document is provided in English.

This Privacy Policy explains how Responses collects, uses, stores, shares and protects personal data when businesses use Responses to manage messages from official social, messaging and email channels, including Instagram, Facebook Messenger, WhatsApp Business, Telegram Business, Booking.com, Airbnb, Gmail and Outlook. It also explains the choices available to workspace owners, team members and the customers whose messages are processed through the service.

References to "Responses", "we", "us" and "our" mean the operator of the Responses service. References to "Customer" mean the business or organization that creates a Responses workspace. References to "End User" mean a person who sends messages to a Customer through a connected channel.

1. Our Role

For workspace account data, billing data and product usage data, Responses acts as a data controller or business. For message content, connected channel credentials and End User data processed on behalf of a Customer, Responses acts as a service provider or processor. The Customer controls which channels are connected, which team members have access, whether AI is enabled, whether replies are sent manually or automatically, and how long business records are retained within the service. Our Data Processing Addendum applies when Responses processes personal data on a Customer's behalf.

2. Data We Collect

We collect the following categories of data:

3. Sources of Data

We receive data from:

4. How We Use Data

We use data to:

5. AI Processing

Responses uses AI to draft replies and assist support workflows. AI output may be inaccurate, incomplete or inappropriate, so Customers remain responsible for reviewing configuration, approving replies where required and monitoring automated behavior. By default, AI starts in draft mode unless the Customer enables auto-send.

6. Telegram Business, Channex and Connected Platforms

When a Customer connects Telegram Business, the Customer enables Secretary Mode for the Responses bot in Telegram. Telegram then sends business connection and business message updates to Responses. Responses uses the business connection identifier to receive customer messages and send replies on behalf of the connected Telegram Business account, according to the permissions granted in Telegram.

When a Customer connects Booking.com or Airbnb through Channex, the Customer supplies a Channex API key and property identifier. Responses validates the property, stores the API key encrypted, and registers an authenticated Channex webhook. Channex relays guest messages, message-thread metadata and attachment references from the selected OTA and carries replies back to that thread. Airbnb inquiries can create a thread without a booking. Disconnecting deletes the stored API key and asks Channex to remove the webhook; conversation records already stored in Responses remain subject to the Customer's Responses retention settings.

Customers are responsible for their relationship with each connected platform, including platform terms, messaging policies, consent/opt-in requirements, customer notices and any restrictions on automated replies.

7. Email Channels: Google Gmail and Microsoft Outlook

When a Customer connects a Gmail mailbox, they authorize Responses through Google OAuth to read incoming messages and send replies on their behalf. Responses requests only the narrowest scopes needed to operate a shared inbox: gmail.readonly to read the incoming customer emails a reply is generated for, and gmail.send to send the reply into the same email thread. Responses registers a Gmail watch so Google notifies the service of new inbox messages; the notification itself contains no message content, and Responses then fetches the referenced messages using the authorized scope. When a Customer connects an Outlook mailbox, the equivalent Microsoft Graph delegated permissions (Mail.Read, Mail.Send, User.Read, offline_access) are used the same way.

Responses uses Gmail and Outlook data solely to provide the user-facing inbox and AI-assisted reply features described in this policy. It does not use this data for advertising, does not sell it, does not transfer it to others except the subprocessors required to run the features (see Section 10), and does not allow humans to read it except where you or your team explicitly view a conversation, where required for security or to comply with law, or on data that has been aggregated or de-identified. Disconnecting a mailbox revokes the tokens, stops the Gmail watch or Graph subscription, and deletes the stored credentials.

8. Google API Services User Data Policy (Limited Use)

Responses' use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Specifically, Google user data obtained through Gmail scopes is used only to provide and improve the user-facing features that are prominent in the Responses interface (the shared email inbox and AI-assisted replies); it is not used for serving advertising; it is not sold; it is not transferred to others except as necessary to provide or improve those features, to comply with applicable law, or as part of a merger, acquisition or asset sale with user notice; and humans do not read it except with the user's or workspace's explicit consent for viewing their own conversations, for security purposes such as investigating abuse, to comply with applicable law, or on aggregated/anonymized data. Responses does not use Google user data to train generalized AI/ML models.

9. Cookies and Similar Technologies

Responses uses cookies and similar local storage technologies for authentication, session continuity, security, preferences and product functionality. We do not use message content for behavioral advertising. Browser controls may allow users to delete or block cookies, but doing so may prevent login or workspace functionality from working correctly.

10. Sharing and Subprocessors

We share data only as needed to provide, secure and support the service:

We do not sell personal data or message content.

11. Retention

We retain data for as long as needed to provide the service, comply with legal obligations, resolve disputes, enforce agreements and maintain security. Workspace conversation retention may be controlled by product settings. Connected channel tokens are deleted when an account is disconnected. Deletion requests remove workspace conversations, messages, connected accounts, platform credentials and related business records except where limited retention is required by law, security, backups or billing records. AI provider handling of request data is described separately in Section 5.

12. Security

Responses uses technical and organizational measures designed to protect data, including encrypted transport, role-based workspace access, encrypted storage of platform credentials, secret-token webhook verification, audit/security events and restricted operational logging. No system is perfectly secure. Customers must protect their credentials, restrict team access, rotate exposed platform tokens and notify us promptly about suspected compromise.

13. International Processing

Responses, its infrastructure providers and subprocessors may process data in countries other than where the Customer or End User is located. Where required, Customers and Responses will rely on appropriate transfer mechanisms, contractual commitments and subprocessors that support lawful international processing.

14. Privacy Rights

Depending on location, individuals may have rights to access, correct, delete, export, restrict or object to processing of personal data, and to appeal or lodge a complaint with a privacy authority. Team members can use in-product controls where available. End Users should first contact the business they messaged, because that Customer controls the conversation. If an End User contacts Responses directly, we may route the request to the relevant Customer unless law requires us to respond directly.

15. Meta User Data Deletion

Responses supports Meta's user data deletion callback. If a person removes the Responses app or requests deletion through Meta's app settings, Meta can call our deletion endpoint at https://responses.me/api/v1/meta/data-deletion. The callback verifies Meta's signed request, deletes Facebook/Instagram data associated with the app-scoped Meta user ID, and returns a confirmation code with a status URL.

Step-by-step deletion instructions and a status checker are available at responses.me/data-deletion. People can also request deletion by contacting privacy@responses.me. Users can delete a workspace or their entire account (including cancellation of active subscriptions) from the in-product Security & Privacy page.

16. Children

Responses is a business service and is not intended for children. Customers must not use Responses to knowingly collect personal data from children unless they have all required permissions and legal authority to do so.

17. Changes

We may update this Privacy Policy from time to time. If changes are material, we will provide notice through the service, email or another reasonable method. Continued use after the effective date means the updated policy applies.

18. Contact

Privacy requests, security notices and data deletion requests can be sent to privacy@responses.me. General questions and support: support@responses.me. Workspace owners can also use the in-product Security & Privacy controls to export or delete workspace data.

Privacy Policy - Responses · Responses