Privacy Policy

Last updated: July 10, 2026

1. Introduction

Welcome to Jobx ("Jobx", "we", "us", or "our"), operated at jobx.me. We provide an AI-powered support agent platform that helps businesses automate customer interactions across multiple channels, including Facebook Messenger, Instagram, WhatsApp, TikTok Direct Messages, LinkedIn, YouTube, Telegram, and email.

This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website jobx.me or use our platform. Please read it carefully. By using Jobx you agree to the practices described here.

2. Information We Collect

2.1 Information you provide

  • Account registration details: full name, business name, email address, website, and phone number.
  • Payment information processed securely through our payment provider (we do not store card details).
  • Content you upload to the knowledge base (documents, URLs, text).
  • Messages and conversations exchanged through your AI agents.
  • Communications you send to our support team.

2.2 Information collected automatically

  • Log data: IP address, browser type, pages visited, and timestamps.
  • Usage data: features used, agent interactions, and token consumption.
  • Device information: operating system and browser version.
  • Cookies and similar tracking technologies (see Section 8).

2.3 Connected platform integrations (overview)

Jobx only accesses data from a third-party platform after you explicitly connect that platform and authorize the specific permissions (scopes) required. For every integration we follow the same principle: we collect the minimum data needed to (a) identify your business account, (b) receive the messages or comments sent to you, and (c) send an AI-generated reply on your behalf. We never sell this data, and it is only ever shared with our AI model provider to generate a reply (see Section 4). The subsections below describe, per platform, exactly what we collect and why.

2.4 Facebook Messenger data (Meta Graph API)

When you connect a Facebook Page to Jobx, we access the following via the Meta Graph API, limited to the permissions you grant (pages_messaging, pages_manage_metadata, pages_read_engagement, and related scopes):

Data about your Facebook Page (the Jobx user):

  • Page ID and Page name
  • Page access token (used to receive webhooks and send replies on your behalf)
  • Token expiry timestamps

Data about people who message or comment on your Page:

  • Page-scoped ID (PSID) — an identifier scoped to your Page, not the person's real Facebook ID
  • Display name and profile picture, where returned by Meta
  • Message content and comment content on your Page's posts
  • Conversation, comment, and message timestamps

Why we collect this data:

Solely to operate the AI-automated message-reply and comment-reply service on your behalf. Message and comment content is passed to an AI language model to generate a reply; conversation history is retained to provide context for follow-ups.

Data we do NOT collect from Facebook:

  • Your personal Facebook profile, friends list, or newsfeed
  • Any Page data beyond what is required to receive and reply to messages and comments

2.5 Instagram data (Meta Graph API)

When you connect an Instagram professional account (linked to a Facebook Page) to Jobx, we access the following via the Meta Graph API, limited to the permissions you grant (instagram_manage_messages, instagram_manage_comments, instagram_manage_engagement, and related scopes):

Data about your Instagram account (the Jobx user):

  • Instagram Business Account ID and username
  • The linked Page access token used to receive webhooks and reply
  • Token expiry timestamps

Data about people who message or comment on your account:

  • Instagram-scoped ID (IGSID) — an identifier scoped to your account
  • Username and profile picture, where returned by Meta
  • Direct Message content and comment content on your posts and reels
  • Conversation, comment, and message timestamps

Why we collect this data:

Solely to operate the AI-automated DM-reply and comment-reply service (including comment-to-DM private replies) on your behalf. Content is passed to an AI language model to generate a reply; conversation history is retained for follow-up context.

Data we do NOT collect from Instagram:

  • Follower/following lists or account analytics beyond message and comment engagement
  • Media or Stories unrelated to a message or comment we are replying to

2.6 WhatsApp data (WhatsApp Business Cloud API)

When you connect a WhatsApp Business phone number to Jobx (via Meta Embedded Signup or Meta OAuth), we access the following via the WhatsApp Business Cloud API, limited to the whatsapp_business_messaging and whatsapp_business_management scopes:

Data about your WhatsApp Business account (the Jobx user):

  • WhatsApp Business Account (WABA) ID and phone number ID
  • Business display name and phone number
  • Access token used to receive webhooks and send replies

Data about people who message your business:

  • The sender's WhatsApp phone number and WhatsApp ID
  • Profile display name, where returned by WhatsApp
  • Message content (text and supported media) sent to your business number
  • Message timestamps

Why we collect this data:

Solely to operate the AI-automated response service on your behalf. Message content is passed to an AI language model to generate a reply; conversation history is retained for follow-up context.

Data we do NOT collect from WhatsApp:

  • Your phone's contact list or address book
  • Any personal (non-business) WhatsApp messages

2.7 TikTok Business Messaging data

When you connect a TikTok Business Account to Jobx via the TikTok Business Messaging API, we collect and process the following Protected Data as defined by TikTok's Business Messaging terms:

Data about your TikTok Business Account (the Jobx user):

  • TikTok Open ID (unique identifier assigned by TikTok to your business account)
  • Display name / username of your TikTok Business Account
  • OAuth access token and refresh token (used to send messages on your behalf)
  • Token expiry timestamps

Data about TikTok end users who message your business:

  • TikTok unique identifier (user ID of the person sending the DM)
  • Display name (if returned by TikTok's API)
  • Message content (text of each Direct Message sent to your business)
  • Conversation ID assigned by TikTok
  • Message timestamps

Why we collect this data:

Solely to operate the AI-automated Direct Message response service on your behalf. Message content is passed to an AI language model to generate a reply. Conversation history is retained to provide context for follow-up messages.

Data we do NOT collect from TikTok:

  • TikTok profile photos or follower data
  • Video content, likes, or analytics
  • Any data beyond what is strictly required to process and reply to Direct Messages

2.8 LinkedIn Page messaging & community data

When you connect a LinkedIn Company Page to Jobx via LinkedIn's Community Management API, we collect and process the following data, limited to the scopes you authorize:

Data about your LinkedIn Company Page (the Jobx user):

  • Organization (Company Page) URN — the unique identifier LinkedIn assigns to your page
  • OAuth access token and refresh token (used to read and reply on your behalf)
  • Token expiry timestamps

Data about LinkedIn members who interact with your page:

  • LinkedIn member URN / unique identifier of the person who commented or messaged
  • Display name (if returned by LinkedIn's API)
  • Comment content on your page's posts
  • Message / conversation content sent to your page
  • Conversation and comment timestamps

Page-level engagement data:

Where you authorize the analytics scope, we read aggregate engagement metrics for your page's posts (such as impression, reaction, and comment counts) to surface performance insights inside Jobx. We do not collect analytics about individual members beyond the comments and messages they send you.

Why we collect this data:

Solely to operate the AI-automated comment-reply and message-reply service on your behalf, and to display the page analytics you ask us to show. Comment and message content is passed to an AI language model to generate a reply; conversation history is retained to provide context for follow-ups.

Data we do NOT collect from LinkedIn:

  • Member profiles, connection lists, or contact details beyond the identifiers above
  • Personal (non-page) messages or feed data unrelated to your Company Page
  • Any data beyond what is strictly required to operate the service and scopes you granted

2.9 YouTube / Google API data

When you connect a YouTube channel to Jobx, we access data through the YouTube Data API v3 using Google OAuth. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We request only the scopes needed to read and reply to comments (such as youtube.force-ssl).

Data about your YouTube channel (the Jobx user):

  • Channel ID, channel title, and avatar
  • Google OAuth access token and refresh token (used to read and reply on your behalf)
  • Token expiry timestamps

Data about people who comment on your videos:

  • Commenter's YouTube channel ID and display name
  • Comment content on your channel's videos
  • Comment timestamps and comment/reply thread IDs

Why we collect this data:

Solely to operate the AI-automated comment-reply service on your behalf. Comment content is passed to an AI language model to generate a reply; comment history is retained to provide context for follow-ups.

Data we do NOT collect from YouTube:

  • Video content, watch history, or channel analytics
  • Any Google account data beyond the channel identifiers and comments above

We do not use YouTube/Google user data to train generalized AI models, and we do not transfer it to third parties except the AI model provider used to generate a reply.

2.10 Telegram data

When you connect a Telegram bot to Jobx by providing a bot token from Telegram's BotFather, we access the following via the Telegram Bot API:

Data we process:

  • Your bot token (used to receive updates and send replies)
  • The sender's Telegram user ID, username, and display name, where available
  • Message content sent to your bot and message timestamps

Why we collect this data:

Solely to operate the AI-automated response service on your behalf. Message content is passed to an AI language model to generate a reply; conversation history is retained for follow-up context. We do not access any Telegram data beyond messages sent to your connected bot.

2.11 Email data (Gmail & IMAP/SMTP)

When you connect an email inbox to Jobx — via Google OAuth (Gmail API) or standard IMAP/SMTP credentials — we access the following:

Data we process:

  • The connected email address and OAuth tokens or IMAP/SMTP credentials (stored encrypted)
  • Incoming email messages sent to the connected address: sender address, subject, and body
  • Message timestamps and thread identifiers

Why we collect this data:

Solely to generate and send AI-automated email replies on your behalf. For Gmail, our use of data received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We only read messages needed to produce a reply and do not scan your mailbox for any other purpose.

3. How We Use Your Information

We use the information we collect to:

  • Create and manage your account.
  • Provide, operate, and improve the Jobx platform.
  • Power your AI agents and process knowledge base content.
  • Send automated replies to your customers' messages and comments on connected platforms, including Facebook Messenger, Instagram, WhatsApp, TikTok, LinkedIn, YouTube, Telegram, and email.
  • Send transactional emails (account confirmation, password reset, billing).
  • Respond to support requests and communicate platform updates.
  • Monitor usage against your plan limits and prevent abuse.
  • Comply with legal obligations.

We do not sell your personal data or your customers' personal data to third parties.

4. How We Share Your Information

We may share your information only in the following circumstances:

  • AI model providers: message content and knowledge base queries are sent to AI model APIs (Anthropic and/or OpenAI) to generate automated responses. These providers process data under their own privacy policies and data processing agreements.
  • Database hosting: all data is stored in Supabase (PostgreSQL), a cloud database service with encryption at rest and in transit.
  • Payment processors: billing data is handled by our payment provider. We do not store card details.
  • Legal requirements: we may disclose data if required by law, court order, or to protect the rights and safety of Jobx, our users, or the public.
  • Business transfers: in the event of a merger, acquisition, or sale of assets, your data may be transferred with prior notice.

Messaging and comment data from all connected platforms — Facebook Messenger, Instagram, WhatsApp, TikTok, LinkedIn, YouTube, Telegram, and email (content, user/member/commenter IDs) — is shared only with the AI model provider for the purpose of generating a reply. It is not shared with any other third party.

5. Data Retention

We retain data only as long as necessary to deliver the service:

  • Account data: retained while your Jobx account is active. Deleted within 30 days of account closure.
  • Conversation and comment history: retained while you maintain the connected channel. Deleted within 30 days if you remove the channel or close your account.
  • On disconnecting any platform (Facebook, Instagram, WhatsApp, TikTok, LinkedIn, YouTube, Telegram, or email): the associated conversation and comment history, message content, and platform user identifiers are deleted, and stored OAuth tokens or credentials are revoked and removed. For TikTok specifically, this deletion is automatic and immediate on disconnect. See our Data Retention & Deletion Policy for full details.
  • Backups: encrypted backups are purged within 30 days of the primary data deletion.

You may also request deletion at any time by contacting privacy@jobx.me.

6. Data Security

We implement industry-standard security measures to protect your data:

  • Encryption at rest: all data in our database is encrypted using AES-256.
  • Encryption in transit: all data transmitted between your browser, our servers, and third-party APIs uses TLS 1.2 or higher.
  • Access control: data access is restricted by user account (row-level security). Platform employees access data only on a need-to-know basis.
  • Authentication tokens: OAuth tokens and API credentials for all connected platforms (Meta, TikTok, LinkedIn, Google/YouTube, Telegram, email) are stored encrypted and are accessible only to the account that authorized them.
  • Vulnerability management: we conduct regular vulnerability scans and address identified issues promptly.

No method of transmission over the internet is 100% secure. We cannot guarantee absolute security but are committed to protecting your data using best practices.

7. International Data Transfers

Your information may be transferred to and processed in countries other than your own, including the United States where our cloud infrastructure and AI providers operate. We ensure appropriate safeguards are in place for such transfers in accordance with applicable data protection laws, including GDPR Standard Contractual Clauses where required.

For TikTok Business Messaging: TikTok end-user messages originating from the European Economic Area (EEA) are processed in accordance with GDPR requirements. We process these messages solely to deliver the automated response service you have configured.

8. Cookies

We use cookies and similar technologies to maintain your session, remember your preferences, and analyze usage. You can control cookies through your browser settings. Disabling cookies may affect the functionality of the platform.

9. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

  • Access: request a copy of the data we hold about you.
  • Correction: request correction of inaccurate data.
  • Deletion: request permanent deletion of your personal data.
  • Portability: request your data in a machine-readable format.
  • Objection / restriction: object to or restrict certain processing activities.
  • Withdraw consent: disconnect any third-party integration (Facebook, Instagram, WhatsApp, TikTok, LinkedIn, YouTube, Telegram, or email) at any time from your dashboard, which will immediately stop data collection and trigger deletion of associated data.

To exercise any of these rights, contact us at privacy@jobx.me. We will respond within 30 days. For TikTok-related data requests, see our Data Retention & Deletion Policy.

10. Children's Privacy

Jobx is not directed at children under the age of 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by posting the new policy on this page and updating the "Last updated" date. Your continued use of Jobx after changes are posted constitutes acceptance of the revised policy.

12. Contact Us

If you have questions or concerns about this Privacy Policy, please contact us:

Jobx

Website: jobx.me

Email: privacy@jobx.me