Sesame ("we", "our", "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your information when you use our platform.
1. Information We Collect
We collect the following types of information:
- Account information: Name, email address, and password when you register.
- Business information: Business name, category, description, and catalog/menu data you provide.
- Social media data: When you connect your Instagram or Facebook account, we access your pages, conversations, and messages through the Meta API to provide inbox management and auto-reply features. When you connect a YouTube channel or a TikTok account, we access that account's profile, statistics, and content as described in sections 4 and 5.
- Content data: Posts, images, captions, and media you create or upload.
- Usage data: How you interact with our platform, including pages visited, features used, and timestamps.
2. How We Use Your Information
Authorized Sesame support and engineering staff may review conversations with the Telegram assistant when needed to investigate failures and maintain service reliability. Access is restricted and audited.
- Provide and improve our services (inbox management, content creation, AI replies).
- Send and receive messages on your behalf through connected Instagram and Messenger accounts.
- Generate AI-powered content, branding, and reply suggestions.
- Display your catalog or menu through public-facing pages.
- Analyze usage patterns to improve the platform.
3. Meta Platform Data
When you connect your Meta (Facebook/Instagram) account, we access and process data in accordance with the Meta Platform Terms. Specifically:
- We read and send messages on Instagram and Messenger on your behalf.
- We access your Facebook Pages and Instagram Business accounts to publish content.
- We do not sell, rent, or share your Meta data with third parties.
- Meta data is stored securely and only used to provide the features you've enabled.
- Access tokens are encrypted at rest.
4. YouTube and Google Data
Sesame's YouTube features use YouTube API Services. By connecting a YouTube channel you also agree to the YouTube Terms of Service, and Google's handling of your data is governed by the Google Privacy Policy.
We request Google permissions one at a time, and only when you enable the feature that needs them:
- Viewing your channel — we read your channel title, handle, description, keywords, subscriber and view counts, and the titles, descriptions, and statistics of your uploaded videos. This powers the YouTube analytics panel, and is also used to learn your brand's voice and to answer customer questions about your business.
- Comments — with your separate consent, we read comments on your videos so they appear in your Sesame inbox, and post replies that you or your assistant send.
- Uploads — with your separate consent, we upload videos and Shorts you create in Sesame to your channel.
- Google access and refresh tokens are encrypted at rest and used only for the features above.
- We do not sell, rent, or transfer Google user data to third parties, and we do not use it for advertising.
- You can revoke Sesame's access at any time from your Google account permissions page, or by disconnecting the channel inside Sesame. Disconnecting deletes the stored tokens and the channel data we ingested; you can also request full deletion on our Data Deletion page.
Sesame's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
5. TikTok Data
When you connect a TikTok account, we access and process data in accordance with the TikTok Terms of Service. Specifically:
- We read your basic profile (display name, avatar, and handle) and your follower and video statistics to show your TikTok analytics.
- We read your list of published videos and their metrics.
- We upload and publish videos you create in Sesame to your account, at your instruction.
- Access tokens are encrypted at rest, and we do not sell, rent, or share your TikTok data with third parties.
- You can revoke access from TikTok's app settings, or by disconnecting the account inside Sesame.
6. Data Storage & Security
Your data is stored on secure, encrypted servers powered by Supabase. We use industry-standard security measures including encryption in transit (TLS) and at rest, row-level security policies, and secure token storage.
7. Data Sharing
We do not sell your personal data. We may share data only with:
- Service providers: Cloud hosting (Supabase), AI processing (OpenAI) — solely to provide our services.
- Legal requirements: When required by law, regulation, or legal process.
8. Data Retention
We retain your data for as long as your account is active. You can request deletion of your data at any time by visiting our Data Deletion page or contacting us.
9. Your Rights
You have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate data.
- Request deletion of your data.
- Withdraw consent for data processing at any time.
- Export your data in a portable format.
10. Cookies
We use essential cookies for authentication and session management. We do not use third-party tracking cookies or advertising pixels.
11. Children's Privacy
Our service is not intended for children under 16. We do not knowingly collect data from children.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by email or through the platform.
13. Contact Us
If you have questions about this Privacy Policy, please contact us at: info@sesames.io
