Be Affluence LLC
Privacy Policy
This policy covers Be Affluence LLC and every product we operate, including ReplyReady.ai. Section 4 covers data we receive from Facebook and Instagram specifically.
Last updated: July 29, 2026
1. Who we are
Be Affluence LLC ("Be Affluence", "we", "us", "our") is a limited liability company formed in New Mexico with its principal office at:
1209 Mountain Road Pl NESte RAlbuquerque, NM 87110United States
We are the parent company and sole legal operator of ReplyReady.ai ("ReplyReady", the "Service"), together with our other brands. ReplyReady.ai is a product of Be Affluence LLC, not a separate company. Where this policy says "we", it means Be Affluence LLC.
Privacy and data-rights requests: privacy@beaffluence.com. Product support: support@replyready.ai. Telephone: +1 (408) 345-5424.
2. Scope, and the two kinds of people in this policy
ReplyReady is business software. That means two different groups of people appear in our systems, and they have different relationships with us:
- Business customers. The business owner or staff member who signs up for ReplyReady, connects their phone line, Facebook Page or Instagram professional account, and configures the service. For their own account data, we are the controller.
- End users. The members of the public who call, text, or send a message to one of our business customers. Their information belongs to that business. For end-user data, the business customer is the controller and we act as a processor / service provider strictly on that business's instructions.
If you are an end user and you want your data deleted, you can ask us directly and we will act on it — see our Data Deletion Instructions. You may also ask the business you were messaging.
3. Information we collect
3.1 Account information (from business customers)
Name, business name, email address, telephone number, industry, time zone, and authentication credentials. Sign-in is handled through Supabase using JWT-based sessions; we do not store passwords in plain text.
3.2 Business configuration
The instructions you give your agent: services offered, business hours, service area, pricing rules, booking links, keyword replies, escalation preferences, and notification settings.
3.3 Conversation data
The content of conversations our agents handle on your behalf: inbound messages and their replies, telephone call transcripts generated by our voice agent, SMS threads, website chat threads, and the lead records we extract from them (such as a caller's name, telephone number, email address, and what they asked for).
3.4 Payment information
Subscriptions are billed through Stripe. Stripe processes and stores card details under its own PCI-DSS compliance; we receive only a customer token, the last four digits, the card brand, and the billing outcome. We never see or store a full card number or CVV.
3.5 Technical and usage data
Server logs including IP address, user agent, requested URL, timestamps and error traces, retained for security, debugging and abuse prevention. We use only essential cookies — the session cookie that keeps you signed in. We do not run advertising or cross-site tracking cookies.
4. Data we receive from Facebook and Instagram
This section describes our use of the Meta platforms in the specific terms Meta requires. It applies only to business customers who choose to connect a Facebook Page or Instagram professional account to ReplyReady, and only from the moment they complete that connection.
4.1 How the connection is made
A signed-in business customer clicks Connect Facebook in the ReplyReady dashboard and is redirected to Facebook Login. Facebook — not ReplyReady — presents the permission screen and asks which Pages the person wishes to grant access to. We receive an access token only for the Pages the person selects, and only for Pages on which they already hold an administrative role. We cannot connect, view or message a Page that our customer does not administer.
4.2 Permissions we request, and why
| Permission | What it gives us | Why the product cannot work without it |
|---|---|---|
pages_show_list | The list of Facebook Pages the signed-in person administers: Page ID, Page name and Page category. | So the customer can choose which of their own Pages to connect. Without it we would have to ask them to paste a Page ID by hand and could not confirm they administer it. |
pages_messaging | The ability to receive messages sent to the connected Page and to send the reply back into that same conversation. | This is the product. ReplyReady exists to answer the customer enquiries a business would otherwise miss. Reading the message and sending the reply both require this permission. |
pages_manage_metadata | The ability to subscribe the connected Page to our webhook, and to unsubscribe it when the customer disconnects. | Meta delivers inbound messages by webhook. Without this subscription we receive nothing and no reply is ever possible. We use it for subscription management only — we do not use it to alter Page settings. |
instagram_basic | The Instagram professional account linked to the connected Page: account ID, username and profile picture. | To identify which Instagram account to answer for, and to display it in the dashboard so the owner can confirm the right account is connected. |
instagram_manage_messages | The ability to receive direct messages sent to the Instagram account and send the reply into that same conversation. | Customers reach a business on Instagram as well as Facebook. The same feature, on a second surface. |
instagram_manage_comments | The ability to reply to comments left on the business's own Instagram posts. | When someone comments asking where to buy, we answer within seconds with the product link rather than letting the question go cold. We reply only to comments on the business's own posts. |
We request no other permissions. In particular we do not request permission to publish posts, manage advertising, access audiences, read follower or insights data, or access any personal Facebook or Instagram profile beyond what is described above.
Instagram comment replies are rule-based, not AI-generated. A comment reply is public, so we treat it differently from a private message. The business writes explicit keyword rules and we send only those replies; comments that match no rule get no reply at all. We reply at most once to any given comment, enforced by a uniqueness constraint in our database rather than by application logic, so a repeated delivery from Meta cannot produce a duplicate public reply. We never comment on anyone else's posts, and we do not delete or hide comments.
4.3 Webhook events we subscribe to
For each connected Page we subscribe to these fields and no others: messages, messaging_postbacks, hours, location, phone, description. The first two deliver customer enquiries. The last four notify us when the business updates its own published hours, address, telephone number or description, so the agent can answer "what time do you close?" correctly instead of guessing.
Where an Instagram professional account is connected, we additionally subscribe to the Instagram messages and comments events, which deliver direct messages sent to the account and comments left on the business's own posts.
4.4 Exactly what we store
| Data | Purpose | Retention |
|---|---|---|
| Page ID, Page name, Page category | Identify the connected Page and label it in the dashboard. | Until the Page is disconnected. |
| Page access token | Receive webhooks for, and send replies from, that Page. Stored encrypted at rest, never exposed to any browser or API response. | Deleted immediately when the Page is disconnected or access is revoked in Facebook. |
| Page-scoped user ID (PSID) of the person who messaged the business | Address the reply to the right conversation and group repeat messages from the same person. A PSID is scoped to that one Page; it cannot be used to identify a person elsewhere on Facebook, and we make no attempt to do so. | Lifetime of the subscription, then per section 7. |
| Message content, both directions | Understand the enquiry, generate an accurate reply, keep conversational context for follow-up messages, and let the business owner read the thread in their dashboard. | Lifetime of the subscription, then per section 7. |
| Contact details the person volunteers in the conversation (name, telephone, email) | Create the lead record and, where the person asks to book, the appointment. | Lifetime of the subscription, then per section 7. |
| Published Page business information: hours, location, telephone, description | Let the agent answer factual questions about the business correctly. | Until the Page is disconnected. |
| Reply events and timings | Produce the business's own reporting: enquiry volume, response time, booking rate, attributed revenue. | Aggregated metrics are retained for the life of the account for year-over-year reporting. |
4.5 How replies are generated
When a message arrives we first try the business's own keyword rules. If none match, the message text and the recent conversation history are sent to our AI provider (OpenAI) to draft a reply consistent with the instructions the business configured. The reply is then sent back into the same Facebook conversation. Our AI provider processes this data on our instructions under a commercial agreement and does not use it to train its models. If the AI cannot produce a reply, we notify the business owner instead of sending anything.
4.6 Restrictions we accept on Meta data
In addition to everything else in this policy, and consistent with the Meta Platform Terms and Developer Policies, we commit that data received from Meta platforms ("Platform Data") is:
- used only to deliver the messaging and reporting features our business customer authorized — never for any separate purpose of our own;
- never sold, rented, licensed or otherwise transferred to a data broker, advertising network, monetization platform or information-resale service;
- never used to build advertising audiences, target advertising, or construct profiles of individuals for any purpose outside the conversation the person started;
- never used to attempt to re-identify anonymous or aggregated data, or to link a Page-scoped user ID to a person's wider Facebook or Instagram identity;
- never used to send unsolicited outbound messages, or to message anyone who has not first contacted the business;
- kept confidential, encrypted in transit and at rest, and access-controlled;
- deleted on request, on disconnection, and when it is no longer needed for the purpose it was collected for.
We also honour opt-out immediately. If a person tells the business to stop messaging them, the agent stops and the conversation is flagged for the owner. We do not attempt to re-engage them through automation.
4.7 Disconnecting
A business customer can disconnect a Page at any time from the ReplyReady dashboard, or revoke ReplyReady entirely from Facebook Settings → Business Integrations. On either action we unsubscribe the Page from our webhook and delete the stored access token immediately. Conversation history is then handled under section 7, or deleted straight away on request.
5. How we use information
- Operate, maintain and secure the Service.
- Answer inbound calls and messages on behalf of our business customer, using the instructions that customer configured.
- Capture, qualify and route leads; schedule appointments.
- Notify the business owner of new enquiries by email, SMS or messaging app, according to their settings.
- Produce the business's own reporting on enquiry volume, response time, bookings and attributed revenue.
- Process subscription payments and prevent fraud.
- Provide support and respond to your requests.
- Comply with law and enforce our Terms.
We do not sell personal information, and we do not share it for cross-context behavioural advertising. We do not use customer conversation content to train general-purpose AI models.
6. Who we share information with
We use the following service providers. Each processes data on our instructions under a written agreement, and only to the extent needed for its function.
| Provider | Function | Data involved |
|---|---|---|
| Supabase | Application database and authentication | All account, configuration and conversation data |
| Google Cloud (Cloud Run, Secret Manager) | Backend hosting and secrets management | All data in transit and at rest |
| Vercel | Frontend and dashboard hosting | Request logs; no conversation content is stored here |
| OpenAI | Draft agent replies | Message text and recent conversation context; not used for model training |
| Meta Platforms | Deliver and send Facebook / Instagram messages | Message content and Page-scoped IDs, per section 4 |
| VAPI | Voice AI telephony | Call audio and transcripts (voice product only) |
| Telnyx | SMS delivery | Telephone numbers and message content (SMS product only) |
| Stripe | Subscription billing | Billing contact and payment tokens |
We also disclose information:
- to the business customer whose Page or phone line generated the conversation — this is the point of the Service;
- when the law requires it, in response to a valid subpoena, court order or lawful government request;
- to protect people, where disclosure is necessary to prevent imminent harm or investigate fraud or abuse;
- in a corporate transaction, where a merger, acquisition or asset sale occurs — the acquirer remains bound by this policy for data received.
Our providers are located primarily in the United States. If you are outside the United States, your information will be processed there.
7. How long we keep information
| Category | Retention |
|---|---|
| Platform access tokens (Facebook Page tokens) | Deleted immediately on disconnection or revocation |
| Conversations, transcripts and lead records | Life of the subscription, then 90 days after cancellation to allow reactivation, then permanently deleted |
| Account and configuration data | Life of the account, then 90 days, then permanently deleted |
| Aggregate reporting metrics (no message content) | Life of the account |
| Billing and tax records | Seven years, as required by law |
| Security and server logs | 90 days |
A verified deletion request overrides the retention periods above, except where we are legally required to keep a record (billing and tax). See Data Deletion Instructions.
8. Security
Data is encrypted in transit with TLS and at rest. Every record is scoped to a single customer account and that isolation is enforced at the database level with row-level security, so one customer's data is not reachable from another customer's session. Secrets and platform tokens are held in a managed secrets service, not in application code or configuration files. Webhook payloads from Meta are rejected unless the request signature verifies against our app secret. Access to production systems is limited to personnel who need it.
No system is perfectly secure. If a breach affects your personal information we will notify you and the relevant regulators as required by law.
9. Your rights
Depending on where you live you may have the right to access, correct, export, restrict or delete your personal information, to withdraw consent, and to object to certain processing. Residents of California, Colorado, Connecticut, Virginia, Utah and other US states with comprehensive privacy laws, and individuals in the UK, EU and EEA, hold these rights under their respective laws.
- We do not sell personal information and we do not share it for cross-context behavioural advertising, so there is no sale to opt out of.
- We will not discriminate against you for exercising a privacy right.
- You may appeal a refused request by replying to our decision; a different reviewer will consider the appeal.
To exercise any right, write to privacy@beaffluence.com or follow the Data Deletion Instructions. We verify identity before acting and respond within 30 days, or 45 days where the law allows an extension and we tell you why.
If you are an end user whose data reached us through a business customer, we will act on your request directly and also notify that business.
10. Automated replies and AI disclosure
Replies sent by ReplyReady are generated by software, not typed by a person. Our business customers are contractually required to disclose that an automated assistant may respond, and our agents identify themselves as an assistant when asked. An automated agent never provides legal, medical, tax or financial advice, and requests that need a human are escalated to the business owner.
11. Health information
The Service is not HIPAA-compliant and must not be used to transmit or store Protected Health Information. We offer templates for clinics and practices for scheduling and general enquiries only. Business customers in healthcare are responsible for keeping PHI out of the Service.
12. Children
The Service is for businesses and is not directed to anyone under 18. We do not knowingly collect personal information from children. If we learn that we have, we delete it promptly.
13. Changes to this policy
We may update this policy. Material changes will be announced by updating the "Last updated" date at the top of this page and, for business customers, by email at least 14 days before the change takes effect. The current version is always published at beaffluence.com/privacy.
14. Contact us
Be Affluence LLC
1209 Mountain Road Pl NESte RAlbuquerque, NM 87110United States
- Privacy and data rights: privacy@beaffluence.com
- Product support: support@replyready.ai
- General: info@beaffluence.com
- Telephone: +1 (408) 345-5424