project4am

Privacy Policy

Last updated: May 20, 2026

Overview

project4am is a self-hosted, multi-tenant AI customer-service assistant used by small businesses (each a "Business") to handle inbound customer messages on their own channels (web widget, Facebook Messenger, Instagram Direct, WhatsApp Business). This policy describes what data we process on behalf of those Businesses, how it is stored, and what rights end users (customers messaging the Business) have.

project4am is operated as a back-office tool by each Business. We do not display advertising, sell data, or use customer messages to train any public AI model.

Data we collect

When a customer interacts with a Business through project4am, we process:

We do not request, store, or process:

How we use Meta platform data

When a Business connects a Facebook Page, Instagram Business account, or WhatsApp Business number, project4am uses the Meta-granted permissions strictly to:

We never use Meta-platform data for advertising, profiling, resale, or cross-app tracking. Meta-platform data is only made available to the specific Business that owns the connected page and to staff users that Business has invited.

Third-party processors

To generate replies, project4am sends the relevant portion of a conversation (most recent messages plus retrieved knowledge snippets) to language-model providers. The Business configures which providers are used; the default deployment uses:

These providers process data only as needed to fulfill the request and under their respective privacy policies. Data is not retained for model training.

Storage, retention, and security

Data is stored in a PostgreSQL database operated by the Business or its designated operator. Each Business's data is isolated at the row level using PostgreSQL row-level security keyed on tenant ID; staff users can only access conversations belonging to the Business they are members of. Passwords are stored as salted hashes via Better Auth. Transport is encrypted with TLS.

Conversation history is retained for as long as the Business needs it to provide service continuity. Businesses can delete individual conversations or messages at any time from the admin dashboard. Account-level deletion requests result in removal of the requester's account, membership, and personally identifiable information.

Your rights

End users (customers messaging a Business) and staff users have the following rights regarding their data:

To exercise any of these rights, contact the Business directly or email erik.kubica@gmail.com. We will respond within 30 days.

Data deletion request

To request deletion of your data, send an email to erik.kubica@gmail.com with the subject "Data Deletion Request" and include the Business page, Instagram handle, or phone number you used to message the Business. We will confirm deletion within 30 days.

For Meta-platform users: you can also revoke project4am's access at any time from your Facebook or Instagram account settings under "Apps and Websites".

Children

project4am is not directed to children under 13 (or the higher minimum age in your jurisdiction). We do not knowingly collect data from children. If you believe we have, contact us and we will delete it.

International transfers

project4am may be operated on servers located outside your country of residence. By using a Business that runs project4am, you consent to your data being transferred to and processed in the countries where those servers operate.

Changes to this policy

We may update this policy from time to time. The "Last updated" date at the top of this page reflects the most recent change. Material changes will be communicated to staff users via email; end users will be informed via the Business they message.

Contact

Questions about this policy or about how project4am handles your data: erik.kubica@gmail.com.