Privacy policy
Blue Chaty is a shared inbox. A business connects the accounts it already answers customers on — a Facebook Page, an Instagram professional account, a LINE official account, a mailbox — and this application carries those conversations to the people who work there. This page says what it keeps while doing that.
In effect from 20 August 2026.
Two kinds of people are described here
Members are the people who sign in: the staff of a business that uses Blue Chaty. Customers are the people who message that business on a connected channel. Customers never sign in and are not asked to agree to anything here — they wrote to a business, and this is the software that business reads them in.
What is stored about members
- Name, email address, and a hash of the password — or, if Google sign-in is used, the account identifier Google returns. The password itself is never stored.
- Which workspaces the member belongs to and their role in each.
- Which conversations are assigned to them, which they have read, and the saved replies they created. Replies and internal notes are stored against the conversation rather than against the member who wrote them, so the text of a message carries no author record.
What is stored about customers
- The messages they sent to the connected account, and the files attached to them.
- The account-scoped identifier the provider issues — a page-scoped Messenger id, an Instagram-scoped id, a LINE user id, an email address. These are scoped by the provider to the business they wrote to.
- A display name and profile picture, when the provider returns them. Meta gates these behind app review, so a refusal is ordinary: the customer then keeps a placeholder name until somebody in the workspace renames them.
- The replies, delivery and read receipts, and any note staff wrote about the conversation.
Identifiers from two different channels are never merged into one person on a guess. A Messenger id and an Instagram id stay separate people until somebody in the workspace links them deliberately.
What it is used for
Only to run the inbox: showing a conversation to the workspace it belongs to, sending replies back through the provider, reporting how many conversations a workspace handled and how quickly, and keeping the service working. Nothing here is sold, rented, or used to build advertising profiles, and message content is never used to train models.
Platform data from Meta
When a workspace connects Facebook Messenger or Instagram, this application receives message events for the connected Page or Instagram professional account, and holds an access token for that Page. The permissions requested are the narrow set the inbox needs: listing the Pages the person administers, sending and receiving Page messages, and managing the Page’s webhook subscription — plus, for Instagram, reading the linked professional account and its direct messages.
Page access tokens are encrypted before they are written to the database. Every request to Meta is signed with an application proof, so a token on its own is not enough to act as this application. Disconnecting a channel removes the token and unsubscribes the Page.
Who else can see it
Members of the workspace the conversation belongs to, and nobody else. Workspaces are isolated from one another: one connected account belongs to exactly one workspace, and a request scoped to a workspace a member does not belong to is refused rather than answered.
Beyond that, data reaches only the infrastructure this instance runs on:
- The hosting provider and the PostgreSQL database where conversations are stored.
- The object storage where files sent by staff are kept so a provider can fetch them.
- The mail relay used for workspace invitations and password resets.
- An error-monitoring endpoint, if the operator configured one. Reports carry identifiers, provider names, and error codes only — never message content and never credentials.
The messaging providers themselves — Meta, LINE, the mail host — already hold these conversations; that is where they arrive from.
How long it is kept
Conversations, customers, and notes are kept for as long as the workspace exists, because a shared inbox whose history disappears is not one. Disconnecting a channel deletes that channel and its stored credentials immediately, and takes its conversations, customers, and messages with it.
There is no self-service “delete my workspace” button yet. A workspace is erased on request to the address below; when it is, everything filed under it goes — members, channels, conversations, customers, messages, attachments, and notes.
Asking for data to be removed
A member can ask the owner of their workspace, or write to the address below. A customer can ask the business they messaged, or follow the steps on the data deletion page.
Changes
If what this page promises changes, the date at the top changes with it in the same release. The wording in force is always the wording on this page.
Contact
This instance has not published a contact address. Ask the owner of the workspace whose Page, Instagram account, LINE account, or mailbox you were messaging — they hold the data and can act on your request.