Last updated 2026-10-04
Privacy Policy
01Who we are
The azimai.uz service ("we", "us") is provided by NOIB LLC (OOO "NOIB"), taxpayer identification number (TIN) 313 380 383, registered address: Samarqand Darvoza ko'chasi 2B-uy, 51-xonadon, Qoratosh MFY, Shaykhantakhur district, Tashkent, Uzbekistan. NOIB LLC (OOO "NOIB") is the data controller for the data described in this policy, except where stated otherwise below.
We build and deploy AI agents that work inside Telegram and, when a client connects it, inside Instagram Direct. Contact: via the links in the site footer (Telegram / Instagram / LinkedIn).
02What this policy covers
This policy applies to the website azimai.uz, to the AI agents we deploy for clients, and to the Instagram connection service at azimai.uz/connect/instagram (the "Instagram Connector").
03Data we collect on the website
Contact details you submit in forms (name, phone, Telegram username, company) — to answer your request.
Technical data: IP address, browser, pages visited — via analytics tools listed on the site, used in aggregate to improve the site.
If you sign in with Telegram, your Telegram user id and display name — to show you member-only content.
04Instagram Connector: what we receive from Meta
When a business connects its Instagram professional account through Business Login for Instagram, Meta shares with us: the account ID and username, an access token, and — via webhooks — the messages, comments and related events that the account receives (sender ID, text, attachments' URLs, timestamps).
We request only the permissions needed for the service: instagram_business_basic (account identity), instagram_business_manage_messages (receive and answer Direct messages), instagram_business_manage_comments (see and reply to comments), instagram_business_manage_insights (the account's own statistics: reach, views, followers — shown to the business in its dashboard), instagram_business_content_publish (publish posts on the business's behalf when it asks its agent to or presses “Publish” in its dashboard). We never ask for the account password.
05Instagram Connector: how we use it
Messages and comments are forwarded, within seconds, to the client's own server where the client's AI agent runs. The agent drafts and sends replies on behalf of the business, and hands the conversation to a human operator when needed.
We use the data solely to provide this service to the business that connected the account. We do not sell it, do not use it for advertising, do not build advertising or cross-business profiles of the people who write to the business (the conversation stage and source described below are visible only to the business the person is talking to), and do not share it with third parties other than the infrastructure providers below.
Replies are sent only within the messaging window allowed by Meta's policies; the agent stops when a human operator joins the conversation.
06Where the data is stored and for how long
On our platform (azimai.uz, hosted on Vercel; key-value storage on Upstash) we store: the account ID and username, the access token (encrypted with AES-256-GCM), the client's server address, delivery statistics, and — only if the client's server is temporarily unavailable — a short queue of undelivered events, which is emptied as soon as delivery succeeds.
Conversation view in the client's dashboard. So that the business owner can see its conversations and numbers in one place, we keep a copy of the Direct messages and comments of the connected account. The text of every message is encrypted at rest with AES-256-GCM (the same scheme and key handling as the access token); alongside it we keep the writer's Instagram ID, the public profile name and username (when Meta sends them with the message, or when we look them up as described below), the time and the direction of each message, and when the person read the business's reply (Meta's read receipt). We do not copy attachments — only how many there were. Limits: the last 200 messages per conversation and the last 500 conversations per account.
Retention: 30 days. Each conversation is stored with an expiry set in the storage itself and disappears automatically 30 days after its last message — there is nothing to forget to clean up. The dashboard is read-only: nobody on our side writes into a conversation from it; replies are produced by the client's own agent on the client's server.
Conversation path. For each conversation we also keep where it started (a Direct message, a reply to a story, or a comment — with the trigger word and the post) and how far it has progressed through the business's own sales stages (for example "replied", "read the reply", "request", "paid"). The business defines these stages in its agent's settings; the agent marks them, and two of them ("replied" and "read") we derive from Meta's events. A short note the agent may attach to a stage is encrypted like message text. Purpose: so the business owner can see which channels and replies lead to requests. It is kept with the conversation and disappears with it — 30 days after the last message.
Name, username and profile photo. If Meta does not include them with a message, we request them once through the Instagram API with the connected account's token (Meta returns them only for people who have themselves written to the business). We do not copy the photo: we keep Meta's link, which stops working by itself within a few days.
Comments. The business's agent tells us about comments under its posts (the text arrives with phone numbers and other contacts already masked and at most 200 characters long), which trigger word it matched, and whether the person got a public reply and a private reply. The text is encrypted like message text; comments are kept for 30 days, at most the last 500 per account. Aggregated counts by trigger word contain no personal data.
A client may switch this copy off at any time — we then store no conversations, stages, sources or comments for that account at all, and what was already stored is erased at the moment of switching off.
On the client's server the message history is stored by the client as part of its customer relationship records. The client is the controller of that data; we act on the client's instructions.
Account statistics (aggregated numbers about the business's own account and posts, shown in its dashboard) are cached on our platform for up to a few hours to respect Meta's rate limits; they contain no data about individual people. For posts published from the dashboard we keep a short log (time, the dashboard key used, the post link and the first 120 characters of the caption) — the last 20 entries per account.
The access token is refreshed automatically and is deleted when the connection is removed.
07How to delete your data
Business (account owner): remove the app in Instagram → Settings → Apps and websites, or ask us to disconnect. Meta then sends us a deauthorization and/or data deletion request; we immediately delete the token, the account record, any queued events and the whole stored conversation history — together with conversation stages, sources, agent notes and comments — and provide a confirmation code with a status page. Deletion is irreversible: there is no archive to restore from.
Person who wrote to a business: contact that business directly — it controls the conversation history; or contact us and we will forward the request to the client and confirm.
You can also email or message us via the footer links; we respond within 30 days.
08Security
Access tokens, the text of stored messages and comments and the agent's stage notes are encrypted at rest; webhook traffic is verified by cryptographic signatures (Meta's X-Hub-Signature-256 on the way in, our own HMAC on the way to the client's server and on the events the client's agent sends back to us); all connections use HTTPS; secrets are stored in environment variables and never in source code.
09Third-party processors
Meta Platforms (Instagram API), Vercel (hosting), Upstash (storage), Telegram (notifications and sign-in). Each processes data under its own terms.
10Changes
We may update this policy; the date of the last update is shown at the top (2026-10-04). Material changes to the Instagram Connector sections will be announced to connected clients.