LEGAL
Privacy Policy
Last updated: June 20, 2026
Who We Are
Ahjelek (ahjelek.com) is an AI commerce platform built for Iraqi businesses. We help store owners manage customer conversations and receive orders across social platforms (Instagram, Facebook Messenger, Telegram) using an AI agent.
Ahjelek acts as a data processor on behalf of the store owner (the data controller). This policy explains what personal information we collect, how we use it, and with whom we share it.
Operator: Ahjelek, Baghdad, Republic of Iraq. Contact: [email protected].
Information We Collect From Store Owners
- Account information: name, email address, password (hashed)
- Store information: store name, description, logo, products, prices
- Staff information: invited staff emails and their roles
- Platform connection credentials (encrypted) for Instagram, Facebook Messenger, and Telegram
- Subscription information: plan, billing dates, payment history
- AI configuration: custom instructions that shape the AI agent’s behavior
- Web push notification subscription data (when enabled by the user)
Google User Data (Google Sign-In)
When a store owner chooses to sign in or sign up using Sign in with Google, we receive a Google ID token from Google Identity Services. We verify that token locally against Google’s public JWKS and read the following claims from it:
- Email address (
email) — used as the account identifier - Full name (
name) — used as the display name on your account - Profile picture URL (
picture) — saved as your account avatar - Google account ID (
sub) — stored to stably link your Ahjelek account to your Google account across email changes - Email verified flag (
email_verified) — used only at sign-in time to confirm Google has verified the address
We only use this Google user data to: (a) create or sign you into your Ahjelek account, (b) display your name and avatar inside the Ahjelek dashboard, and (c) send you the service-related emails described below.
We do not sell Google user data, share it with third parties for advertising, transfer it to data brokers, use it to train AI/ML models, or use it for any purpose other than the ones listed above. The Google ID token itself is verified in memory and discarded; only the claims listed above are persisted.
Ahjelek’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Information We Collect From End Customers (Via Connected Platforms)
When an end customer messages a store through a connected social platform, we receive and process the following on the store owner’s behalf:
- Identity information: name, username, profile picture, platform user ID
- Contact information: phone number and delivery address (when the customer provides them while placing an order)
- Message content: the full text of conversations between the customer and the store
- Voice messages: voice notes sent through the platforms — transcribed to text via third-party services (see Subprocessors below)
- Images: images sent by the customer — analyzed via AI services to understand their content (for example, a photo of a product)
- Order data: ordered products, quantities, delivery notes
Automatically Generated Data
- AI Memory: the AI agent automatically compiles behavioral notes about each end customer (product preferences, ordering patterns, delivery preferences) to improve the quality of future replies. These notes accumulate across multiple conversations.
- Tags and segments applied to customer profiles by the store owner or the system
- Usage metrics: number of processed messages, AI consumption
- Upload logs: filename, size, and content type when images are uploaded
Data From Platform APIs
We receive data through the official APIs of the following connected platforms:
- Instagram — via the Meta Graph API
- Facebook Messenger — via the Meta Graph API
- Telegram — via the Telegram Bot API
The data received includes user IDs, names, profile pictures, and message content (text, audio, images). We comply with the terms of use of each platform.
How We Use Data
- Operate the service: manage stores, accept orders, manage conversations
- Generate automated AI replies to customer messages
- Transcribe voice messages to text so the AI agent can understand them
- Analyze images to understand their content (for example, to recognize products)
- Build AI Memory: aggregate contextual notes about customers to improve interactions
- Send transactional emails: verification codes, security notifications, order alerts
- Improve the service: analyze aggregate usage patterns to develop the platform
Subprocessors and Data Sharing
We only share data with third parties to the extent necessary to provide the service. The table below lists the subprocessors we use:
| Subprocessor | Purpose | Data sent |
|---|---|---|
| Google (Gemini API) | Generate AI replies, transcribe audio, analyze images | Message content, voice notes, images, conversation context, AI Memory |
| OpenAI | Speech-to-text (fallback) | Customer voice notes |
| Meta (Instagram, Facebook) | Receive and send messages on the platform | Reply content, user IDs |
| Telegram | Receive and send messages through the bot | Reply content, user IDs |
| Resend | Deliver transactional email | Recipient email, email subject and body |
Google, OpenAI, Meta, and Resend are headquartered in the United States. Message, voice, and image data is sent to their servers for processing. We comply with each provider’s data-use policy and, where available, opt out of using customer data to train their models.
Google user data from Sign-In is not shared with any of these subprocessors. It stays inside Ahjelek and is used only for authentication and your account profile.
Voice and Biometric Data
When an end customer sends a voice message via Instagram, Telegram, or Facebook Messenger:
- The audio file is downloaded from the platform’s servers
- It is sent to Google Gemini or OpenAI for transcription
- The transcribed text is saved as the message content
Voice notes may contain biometric data (voiceprint). This data is processed by the third parties listed in the Subprocessors table above.
Image Analysis
When an end customer sends an image through a connected platform, it may be sent to Google Gemini Vision to analyze its content and generate a text description. The AI agent uses that description to understand the conversation and respond appropriately.
AI Profiling (AI Memory)
The AI agent automatically compiles a behavioral profile for each end customer (called AI Memory) that includes:
- Product preferences and ordering patterns
- Delivery preferences (preferred address, availability windows)
- Context from previous conversations
- Any other information the AI extracts from the conversations
The store owner can view these notes from the dashboard. This data is used solely to improve the quality of automated replies and customer service.
We use your email address only to send essential service messages:
- Account verification codes
- Account security notifications
- Order and subscription alerts
All emails are sent from [email protected] through our transactional email subprocessor. We do not send marketing emails.
Data Security
We use technical and organizational measures to protect your data, including:
- Hashing of passwords and encryption of platform connection credentials at rest
- Encrypted transport via HTTPS/TLS
- Role-based access control to limit who can view what
- Redaction of sensitive values in application logs
- Local verification of Google ID tokens against Google’s JWKS — credentials are never sent to a third-party verifier
Data Retention
Account and store data is retained for as long as the account is active. Conversation history, orders, customer profiles, and AI Memory are currently retained indefinitely unless deletion is requested.
When an account is deleted, the data is held for 30 days so you can recover the account, then permanently removed (see Data Deletion below). We are progressively rolling out automated retention windows and will update this policy when they apply.
Data Deletion
You can request deletion of your data at any time by emailing [email protected] from the email address on your Ahjelek account. We process deletion requests within 30 days. Deletion covers: account data, store data, conversation history, customer profiles, AI Memory, and the Google account ID (sub) and profile data we received via Google Sign-In.
Note: data that was previously sent to subprocessors (Google Gemini, OpenAI, Meta, Resend) is governed by their own retention policies and may persist on their servers beyond our control.
Revoking Ahjelek’s access from your Google Account permissions page stops future Sign-In events but does not by itself delete the account; email us to delete the account.
Your Rights
You have the right to:
- Request a copy of your personal data
- Request correction of inaccurate data
- Request deletion of your data
- Object to the processing of your data
To exercise any of these rights, contact us at the email below.
Children
Ahjelek is intended for users 18 years of age and older. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, contact us and we will delete it.
Changes to This Policy
We may update this policy from time to time. We will notify you of material changes by email or by a notice on the platform. Continued use of the platform after an update constitutes acceptance of the updated policy.
Contact Us
For privacy inquiries and data deletion requests:
Email: [email protected]
General support: [email protected]