Legal

Privacy Policy

Last updated: 16 June 2026

This Privacy Policy explains how Keiyora, trading as Sasha Tufnell, collects, uses, stores, shares, and protects personal information when you use our website, dashboard, software, AI reply tools, integrations, and related services.

1. Overview

Business/legal name: Keiyora. Trading name: Sasha Tufnell. App name: Keiyora Assistant. Website: https://keiyora.com. Contact email: support@keiyora.com. Privacy email: privacy@keiyora.com. Business address: Available on request. Governing privacy jurisdiction: Western Australia, Australia.

Keiyora is an AI-assisted messaging and lead management platform for businesses. It helps business owners manage customer enquiries from connected communication channels including Instagram, WhatsApp, Messenger, Gmail, Outlook, and email.

We process personal information to provide the service, operate connected integrations, generate AI-assisted replies, manage leads, provide analytics, process payments, prevent misuse, and comply with legal and platform obligations.

2. Information We Collect

Account Information

  • Name.
  • Email address.
  • Login information.
  • Authentication provider details.
  • User ID.
  • Account creation date.
  • Billing customer ID.
  • Subscription status.
  • Plan information.

Business Profile Information

  • Business name.
  • Business type or profession.
  • Business logo.
  • Business colours and branding.
  • Business location.
  • Business phone number.
  • Business email.
  • Website.
  • Opening hours.
  • Services and pricing.
  • FAQs.
  • Booking links.
  • Staff names and working hours.
  • AI prompt and assistant instructions.
  • Custom responses.

Customer and Lead Information

  • Customer name or profile name.
  • Customer message content.
  • Customer reply history.
  • AI-generated reply content.
  • Channel source.
  • Customer phone number, where relevant.
  • Customer email address, where relevant.
  • Instagram, Facebook, WhatsApp, Messenger, Gmail, Outlook, or email identifiers where relevant.
  • Timestamps.
  • Booking status.
  • Follow-up status.
  • Lead notes and related metadata.

Connected Channel Information

  • Instagram Business account identifiers.
  • Facebook Page identifiers.
  • Messenger user identifiers.
  • WhatsApp Business phone number IDs.
  • WhatsApp sender phone numbers.
  • Gmail email address and OAuth tokens.
  • Outlook email address and OAuth tokens.
  • Calendly account identifiers and OAuth tokens.
  • Email routing addresses.
  • Webhook metadata.

Payment Information

Payments are processed by Stripe. We may receive Stripe customer IDs, subscription IDs, checkout session IDs, plan, billing interval, price tier, payment status, trial status, invoice status, and subscription cancellation status. We do not store full card numbers.

Technical and Usage Information

  • Device and browser information.
  • IP address where available.
  • Log data.
  • Error information.
  • Feature usage.
  • Reply counts.
  • Overage usage.
  • Top-up usage.
  • Authentication and security events.
  • Integration connection status.

3. How We Use Information

  • Create and manage user accounts.
  • Authenticate users.
  • Provide the dashboard.
  • Connect and operate messaging channels.
  • Receive inbound customer messages.
  • Generate AI-assisted business replies.
  • Send replies through connected channels.
  • Store leads and conversation records.
  • Show analytics and reporting.
  • Manage bookings and availability.
  • Manage staff hours.
  • Provide support.
  • Process subscriptions and payments.
  • Enforce reply limits, top-ups, and overage.
  • Send service notifications.
  • Maintain security and prevent misuse.
  • Debug and improve the service.
  • Comply with laws, platform rules, and third-party provider requirements.

4. AI Processing

Keiyora may send customer message content, business instructions, service information, FAQs, booking links, and related context to an AI provider to generate a business reply.

AI replies are generated based on the information configured by the business user. Business users are responsible for ensuring their prompts, services, pricing, and business details are accurate and appropriate.

We instruct the AI assistant to only respond to business-related enquiries, avoid offensive or inappropriate language, avoid unrelated political, religious, or off-topic discussions, avoid medical, legal, and financial advice, avoid fabricating information, and be respectful and professional.

5. Meta Data Use

If a business connects Instagram, Messenger, WhatsApp, or Facebook-related services, we may process Meta-related data only to provide business messaging and lead management functionality.

  • Receiving customer messages sent to the connected business account or page.
  • Sending business replies.
  • Saving message content and lead information for the business user.
  • Displaying conversations in the business dashboard.
  • Measuring reply and lead activity.
  • Supporting follow-up workflows where enabled.

We do not use Meta data to sell personal information, build unrelated consumer profiles, scrape or harvest data, send spam, circumvent Meta enforcement actions, or use permissions for unrelated purposes.

6. Google API Data Use

If a user connects Gmail, we use Google API data only to provide Gmail-related messaging functionality, including reading unread business enquiries, sending replies, marking messages as read, and displaying relevant lead information in the dashboard.

We do not sell Google user data. We do not use Google Workspace or Gmail data for unrelated advertising. We do not allow humans to read Gmail message content except where necessary for security, support, legal compliance, abuse investigation, or with user consent.

7. Microsoft Data Use

If a user connects Outlook or Microsoft 365, we use Microsoft account data only to provide Outlook-related messaging functionality, including reading unread business enquiries, sending replies, and saving lead records.

8. Sharing Information

We may share information with service providers that help us operate Keiyora.

  • Firebase and Google Cloud for hosting, authentication, database, and cloud functions.
  • OpenAI for AI reply generation.
  • Meta/Facebook/Instagram/WhatsApp for connected messaging.
  • Google for Gmail and authentication.
  • Microsoft for Outlook and Microsoft Graph.
  • SendGrid for email.
  • Calendly for booking integration.
  • Stripe for billing and payments.
  • Analytics, logging, support, and infrastructure providers where used.

We may also share information with your consent, to comply with law, to protect rights, safety, and security, to investigate fraud, abuse, or platform policy violations, or in connection with a business sale, merger, acquisition, or restructuring.

9. Data Storage and Security

We use reasonable technical and organisational safeguards to protect information.

  • Authenticated user accounts.
  • Firestore security rules.
  • Server-side processing for webhooks and API calls.
  • Restricted access to backend credentials.
  • OAuth token storage for connected integrations.
  • Stripe for payment processing.

No system is completely secure. You are responsible for protecting your login credentials and for controlling access to your connected business accounts.

10. Data Retention

We keep personal information for as long as needed to provide the service, comply with legal obligations, resolve disputes, enforce agreements, maintain security, and support business operations.

Business users may request deletion of account data, subject to legal, billing, security, and backup retention requirements. Connected channel tokens may be deleted or invalidated when a user disconnects an integration.

11. User Controls

  • Update account information.
  • Update business profile information.
  • Edit AI instructions.
  • Disconnect channels.
  • Delete or update certain business data.
  • Cancel subscriptions.
  • Request account deletion.
  • Export certain lead data where available.

12. Customer Rights

Depending on your location, you may have rights to access, correct, delete, restrict, object to, or receive a copy of personal information. To make a privacy request, contact us using the details below. We may need to verify your identity before responding.

If you are a customer of a business using Keiyora, we may direct you to that business because the business may be the controller of your customer relationship data.

13. International Transfers

Your information may be processed in countries other than your own, including by third-party providers used to operate Keiyora. Where required, we rely on appropriate safeguards or lawful transfer mechanisms.

14. Children's Privacy

Keiyora is not intended for children under 13, and business users must be at least 18 years old. We do not knowingly collect personal information from children through our account system.

15. Cookies and Similar Technologies

We may use cookies, local storage, or similar technologies for authentication, security, preferences, analytics, and service functionality.

16. Marketing Communications

We may send service-related emails and, where permitted, marketing communications. You may opt out of marketing communications, but we may still send important service, billing, security, or legal notices.

18. Changes to This Policy

We may update this Privacy Policy from time to time. If changes are material, we will take reasonable steps to notify users. Continued use of Keiyora after an update means you acknowledge the updated policy.

19. Contact

For privacy questions or requests, contact: Keiyora, privacy@keiyora.com, Available on request, https://keiyora.com. For general support, contact support@keiyora.com.