Privacy Policy
Last updated: August 18, 2026
1. Introduction
BengalBound ("we", "our", or "us") respects your privacy and is committed to protecting it through our compliance with this Privacy Policy. This policy describes the types of information we may collect from you when you use the Kriva mobile application and website (the "Service"), and our practices for collecting, using, maintaining, protecting, and disclosing that information.
2. Information We Collect
We collect several types of information from and about users of our Service, including:
- Account Information: Name, email address, phone number, and business details provided during registration.
- Meta Integration Data: When you connect your Facebook or Instagram accounts, we collect Page/Profile IDs, access tokens, and webhook data (incoming messages and comments).
- Customer Interactions: Text content of messages and comments sent to your business via connected Meta platforms, which are processed by our AI models.
- Device & Usage Data: Device identifiers (used for anti-abuse device fingerprinting on the free tier), IP addresses, app version, and interaction logs.
- Payment Information: Billing details are processed securely by our third-party payment processors (Paddle for international payments, and bKash in Bangladesh). We do not store raw card numbers or bKash credentials on our servers.
3. How We Use Your Information
We use information that we collect about you or that you provide to us:
- To provide, maintain, and improve our Service.
- To power the AI automation (routing messages to Large Language Models to generate replies).
- To enforce our Terms & Conditions, including quota limits and anti-abuse mechanisms.
- To provide customer support and respond to your inquiries.
- To notify you about changes to our Service or your subscription.
4. Data Processing by AI Models
To generate automatic replies, the text of incoming messages to your business is securely transmitted via API to our LLM partners (such as OpenAI, Anthropic, or Google). We explicitly instruct these partners not to use your conversational data to train their underlying models. Data sent to LLM providers is retained by them only for short-term abuse monitoring (typically 30 days) before being deleted.
5. Customer Profiles and Agent Memory
So that your agent recognises someone who has messaged you before, we build a profile for each person who contacts your business. A profile is derived from message metadata — it is not a copy of the conversation.
What a profile contains:
- A reference code we generate (for example
KC-4F2A9C), the display name the platform gives us, and the platform's own identifier for that person. - Counts: how many messages they sent, how many replies they received, how many comments they left, and when they were first and last in contact.
- Which language they write in, counted per message.
- Which items in your catalogue their questions matched, and what kind of question it was.
- Short summary lines such as "Asked the price of Cotton Panjabi", built from the catalogue match and the question type.
- Any notes or tags you add yourself.
What a profile never contains: the text of the message itself. Summary lines are constructed from what was matched, never copied from what was written, so a profile cannot be used to reconstruct a private conversation.
Profiles are visible only to you, within your own account. Our staff can see aggregate statistics and profile summaries for support and abuse investigation; they cannot read a customer's messages from these tools.
The summary lines are included in the instructions sent to the language model when that person messages you again. This is what allows the agent to remember a returning customer rather than starting over.
6. What Your Agent Learns From Other Businesses
Kriva keeps a shared playbook of selling craft — how to answer somebody who says a price is too high, how to respond when a customer goes quiet, how to handle a complaint. Your agent draws on it, and traffic across all businesses helps build it. Because this is the one place where anything crosses between accounts, we describe exactly what does and does not.
What never enters the shared playbook:
- Your prices, products, catalogue, stock or supplier information.
- Your business profile — hours, address, delivery terms, policies.
- Anything your agent or your staff wrote. Your own words stay in your account.
- Customer names, contact details or profiles.
- The text of any conversation, in either direction.
What does: short, common phrases that customers use to signal a situation — things like "too expensive" or "is it available" — recorded only as a signal that a known situation occurred. The responses themselves are written by us, not learned from anybody's account.
The threshold that protects you: a phrase is discarded unless it has been seen at five or more unrelated businesses. Anything particular to one shop — a brand it carries, a product it names, a phrase its customers use because of what it sells — cannot reach that threshold and is never used. This is a property of how the system is built, not a review step someone performs.
The result is that a new business benefits from selling patterns proven across the platform on its first day, while nothing identifiable, commercial or competitive about any business is shared with any other.
7. Data Security
We have implemented rigorous security measures designed to secure your information from accidental loss and unauthorized access:
- Meta Access Tokens are stored using AES-256-GCM encryption at rest.
- Row-Level Security (RLS) is enforced at the database level to ensure strict isolation between different tenants/businesses.
- All data transmitted between the app, our servers, and third-party APIs is encrypted in transit using TLS/HTTPS.
8. Data Retention and Deletion
We retain your personal information and message history only for as long as necessary to provide the Service.
- Customer profiles and conversations are deleted automatically when a person has had no contact with your business for 24 months. The profile, the message threads and the comment records all go together.
- On request, you can delete any individual customer immediately from the customer screen in the app. This erases their profile, their conversations, the messages within them and their comment records. It cannot be undone. This is the mechanism to use when one of your own customers asks you to erase their data.
- On account closure, we purge your Meta access tokens and your conversation history from our active databases.
- Usage and billing records are kept for as long as tax and accounting obligations require, and contain no message content.
Where your business is subject to data protection law such as the GDPR, you are the controller of your customers' data and we are your processor. The deletion tools above exist so that you can meet a request you receive.
9. Third-Party Disclosures
We do not sell, trade, or otherwise transfer your personally identifiable information to outside parties for marketing purposes. We may share data with trusted third-party service providers (such as hosting partners and payment processors) who assist us in operating our Service, so long as those parties agree to keep this information confidential.
10. Changes to Our Privacy Policy
We may update our Privacy Policy from time to time. If we make material changes to how we treat our users' personal information, we will notify you by email or through an in-app alert. The date the privacy policy was last revised is identified at the top of the page.
Contact Information
To ask questions or comment about this Privacy Policy and our privacy practices, contact us at hello@kriva.app.