Effective Date: 23-08-2026
RIBLAI ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the RIBLAI application, which integrates with the Meta (Facebook) WhatsApp Business API, Facebook Pages API, and Instagram Messaging API.
1. Information We Collect
We may collect and process the following types of information from your use of the RIBLAI application:
a. Business Information
- WhatsApp Business Account (WABA) ID
- Business phone number(s)
- Business profile information
- Facebook Page IDs and basic page details
- Instagram Business Account IDs and connected profile details
b. Catalog Data
- Product names, descriptions, images, and prices
- Catalog metadata linked to your Facebook or Instagram Catalog
c. Messaging Data
- WhatsApp message templates and logs (timestamps, recipient info, delivery status)
- Facebook Page messages (for customer support integrations)
- Instagram Direct messages and metadata (message IDs, sender IDs, timestamps)
- Message content where necessary for service delivery (we do not use message content for marketing)
d. User Data
- Admin contact details
- Meta Business Manager ID and roles
- Page and Instagram Account Admin/Editor details (where permission is granted)
2. Permissions and Their Use
RIBLAI requests and uses the following Meta platform permissions only to provide core application functionality and in accordance with Meta Platform Policies.
WhatsApp Permissions
- whatsapp_business_management: Manage your WhatsApp Business Account (WABA), phone numbers, profiles, and related settings.
- whatsapp_business_messaging: Send and receive WhatsApp messages, message templates, and delivery status updates via the WhatsApp Cloud API.
- whatsapp_business_manage_events: Subscribe to and receive webhook events related to WhatsApp messaging, templates, message status updates, and account activity to ensure reliable message delivery and real-time system behavior.
- catalog_management: Sync and manage product catalogs used for WhatsApp, Facebook, and Instagram catalog-based messaging.
- business_management: Verify, manage, and link Meta Business Manager assets such as WhatsApp accounts, Pages, Instagram accounts, and ad accounts.
Facebook Page Permissions
- pages_show_list: Retrieve the list of Facebook Pages that you manage or have access to.
- pages_manage_metadata: Manage Page settings and metadata required for integrations.
- pages_messaging: Send and receive messages through Facebook Pages for customer communication and support.
- pages_read_engagement: Access engagement metrics such as likes, comments, and interactions to help analyze customer engagement.
- pages_read_user_content: Read Page posts, comments, and reviews to enable moderation, customer support, and response workflows.
- page_events: Subscribe to and receive webhook events related to Page messaging and interactions to enable real-time updates and automated responses.
Instagram Permissions
- instagram_business_basic: Access basic information about your connected Instagram Business Account, such as username, profile picture, and account type.
- instagram_business_manage_messages: Send and receive Instagram Direct messages on behalf of your connected Instagram Business Account.
- instagram_manage_events: Subscribe to and receive webhook events related to Instagram messaging and account activity for real-time message handling and system synchronization.
Ads and Advertising Permissions
- ads_read: Read advertising account information and performance data for reporting, analytics, and integration purposes only.
- Ads Management - Standard Access: Access advertising assets (such as ad accounts linked to your Business Manager) as required for campaign visibility, reporting, and integration features.
RIBLAI does not create, modify, or run ads unless explicitly authorized by the business user.
Permission Usage Statement
- All requested permissions are strictly limited to required app functionality.
- Used only on behalf of the authenticated business user.
- Never used for unauthorized data access or advertising.
- Never shared or sold to third parties.
3. Google Account, Gmail, Email Forwarding, and AI Processing
Google Account and Gmail Integration
Riblai allows users to connect their Google accounts to provide email communication and AI-assisted communication features.
When a user connects a Google account, Riblai may access basic Google account information, such as the user's name and email address, as authorized by the user through Google's OAuth consent process.
For Gmail functionality, Riblai uses the Gmail API to send emails and replies through the user's connected Gmail account.
Riblai does not use the Gmail API to read, retrieve, modify, or delete messages from the user's Gmail mailbox.
Sending Emails Through Gmail
Riblai may request the Gmail API permission necessary to send emails through a user's connected Gmail account.
Riblai uses this permission to provide user-facing functionality including:
- Sending emails initiated by the user from within Riblai.
- Sending replies to customer conversations from within Riblai.
- Sending responses generated by the Riblai Smart Agent when the user has explicitly enabled the Smart Agent for the applicable email channel.
Riblai's Gmail API access is used for sending messages and replies and is not used to retrieve incoming messages from the user's Gmail mailbox.
Receiving Emails Through Email Forwarding
Riblai does not require Gmail API read access to receive incoming email conversations.
Users may configure Gmail or another email provider to forward incoming emails to a Riblai-provided inbound email address associated with their Riblai workspace or email channel.
When an email is forwarded to Riblai, Riblai may receive and process information contained in or associated with the forwarded email, including:
- Sender and recipient information.
- Email addresses.
- Subject lines.
- Message bodies and conversation content.
- Message headers and identifiers.
- Timestamps.
- Attachments, where supported.
- Other information included in or associated with the forwarded email.
Forwarded email content is received by Riblai through standard email delivery and forwarding mechanisms. Riblai does not retrieve this incoming email content from the user's Gmail mailbox through the Gmail API.
Riblai may process and store forwarded emails to provide user-facing functionality, including:
- Synchronizing email conversations within the user's Riblai workspace.
- Displaying email conversations within Riblai.
- Associating conversations with relevant customer, contact, CRM, and communication records.
- Routing and managing customer communications.
- Processing incoming messages for automation and AI-assisted communication functionality.
Riblai Smart Agent and Google Cloud Vertex AI
When a user explicitly enables the Riblai Smart Agent for an email channel, relevant incoming email content and related conversation context may be processed by Riblai and Google Cloud Vertex AI to understand the communication and generate an appropriate response.
Depending on the configuration selected by the user, the Smart Agent may automatically generate and send a response through the user's connected Gmail account.
Where Gmail is connected, Riblai uses the Gmail API sending permission to send the generated response through that Gmail account.
Users control whether the Riblai Smart Agent is enabled for their email channel.
Riblai uses Google Cloud Vertex AI solely to provide this user-facing AI functionality. Riblai does not use Google Workspace API data or forwarded email content to create, train, or improve generalized or foundational artificial intelligence or machine learning models.
Riblai does not sell Google user data or forwarded email content and does not use the content of private email communications for personalized advertising.
Storage and Protection of Email and Google Data
Riblai may store forwarded email content, conversation information, Google account information, and other data necessary to provide its email, CRM, Smart Agent, and related functionality.
Riblai applies technical and organizational safeguards designed to protect such information against unauthorized access, disclosure, alteration, or destruction.
Access to email and Google-related data is limited to authorized users, systems, and service providers where access is necessary to operate, maintain, secure, support, or provide functionality requested by the user.
Sharing and Third-Party Processing
Riblai does not sell Google user data or forwarded email content.
Riblai may use service providers acting on its behalf where processing is necessary to provide, maintain, or secure Riblai's user-facing functionality.
For Riblai's AI-assisted email functionality, relevant email content and conversation context may be processed using Google Cloud Vertex AI for the purpose of understanding messages and generating responses.
Riblai does not transfer Google Workspace API data or forwarded private email content to third-party AI or machine learning services for the purpose of training, developing, or improving generalized or foundational AI/ML models.
Data Retention and Deletion
Riblai retains Google account information, forwarded email content, conversation information, and related data only for as long as necessary to provide the applicable Riblai services, meet legitimate security and operational requirements, and comply with applicable legal obligations.
Users may disconnect their Google account or email channel from Riblai and may request deletion of their data in accordance with the data deletion procedures described in this Privacy Policy.
Revoking Google's authorization prevents Riblai from performing future Gmail API operations using the revoked authorization.
Because incoming emails may be received through email forwarding independently of Google OAuth authorization, revoking Riblai's Google OAuth authorization does not automatically disable email forwarding configured separately in the user's Gmail or email-provider settings. Users who wish to stop forwarding incoming emails to Riblai should also disable the applicable forwarding rule or forwarding configuration with their email provider.
Data previously received or stored by Riblai is handled in accordance with Riblai's applicable retention and deletion practices.
Google API Services User Data Policy and Limited Use
Riblai's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Riblai uses information received from Google APIs only to provide or improve prominent user-facing features that are visible and relevant to the user.
Riblai does not use or transfer Google Workspace API data, including raw or derived Google Workspace API data, to create, train, or improve generalized or foundational artificial intelligence or machine learning models.
Riblai does not sell Google API user data, use Google API user data for personalized advertising, or transfer Google API user data for advertising purposes.
4. How We Use Your Data
- Authenticate and manage your WhatsApp Business, Facebook Page, and Instagram integrations.
- Send automated and manual messages via WhatsApp Cloud API, Facebook Pages API, and Instagram Messaging API.
- Manage product catalogs for catalog-based messaging.
- Provide customer engagement insights and improve your business communication.
- Ensure compliance with Meta's platform requirements.
We never sell or share your data with third parties for advertising purposes.
5. Data Retention and Security
- We only store data necessary to provide services, for as long as your account is active.
- All data is encrypted, access-controlled, and protected with industry-standard security measures.
6. Your Rights
You have the right to:
- Access your data.
- Request corrections or deletion.
- Revoke permissions (note: this may affect app functionality).
For requests, email us at support@ribl.ai.
7. Third-Party Services
RIBLAI integrates with Meta platforms (WhatsApp Business API, Facebook Pages API, and Instagram Messaging API). Your use of these services is also subject to Meta's Data Policy.
8. Policy Updates
We may update this Privacy Policy periodically. Updates will be posted on this page with a revised effective date. Continued use of RIBLAI after updates indicates your acceptance of the revised terms.
9. Contact
If you have any questions about this Privacy Policy or our data practices, please contact us at:
support@ribl.ai