On this page
The short version
- We process the information needed to run your connected workspace.
- AI uses conversation context and knowledge you authorize.
- You can stop automated replies and request access or deletion.
Who handles your information
Sayw is operated by Comment Key LLC. Contact: legal@sayw.app. We handle account administration, security, support and billing information for our own service purposes.
When a business uses Sayw to manage its audience, that business decides how to use its customer conversations and leads. We process that workspace content to provide the service on its instructions. Contact the business you spoke with about its own privacy practices; you may also contact us for help with a Sayw data request. This notice does not replace any data-processing agreement required for a business relationship.
Information we process
- Account and access details: Instagram identifiers, usernames, available profile images, connection permissions, encrypted access tokens, account preferences, and team-member roles and email addresses.
- Conversations: incoming and outgoing text, message/comment identifiers, timestamps, delivery status, attachments or media links, AI answers, human replies, assignments and internal notes. These are stored as workspace history, not only processed temporarily.
- CRM and automation data: contacts, interests, qualification answers, lead stages, summaries, tags, configured messages, trigger matches, follow checks when enabled, opt-outs and reminder status.
- Knowledge and transcription: facts, documents and approved conversation material submitted for AI use; uploaded recordings or submitted URLs; transcripts, generated titles, processing status and usage.
- Billing and support: plan, subscription/customer identifiers, allowance usage, billing events, contact details and support correspondence. Stripe, or FreeKassa for RUB checkout where available, handles payment details; Sayw does not store full card details. For FreeKassa we send your verified email, IP address, order identifier, amount and currency, and store encrypted contact information and a recurring-payment identifier to process authorized renewals.
- Technical information: session and preference storage, IP addresses and request metadata in infrastructure logs, security checks, error records, and site-performance measurements.
Why we use it
We use information to authenticate users, provide automations and human/AI replies, organize leads, retrieve approved knowledge, transcribe requested media, manage plans, prevent duplicate sends and abuse, diagnose failures, and respond to support or rights requests.
Where a data-protection law requires a lawful basis, our own processing relies on providing a requested service or contract, legitimate interests in operating and securing the service, compliance with legal obligations, or consent where it is required. A workspace business is responsible for its own lawful basis and notices for customer data. Workspace messages and uploaded content are not included in the optional advertising measurement described below.
A unique delivery link can record that a resource was opened to suppress its reminder. It is not a record of browsing on the destination website. Sending STOP, UNSUBSCRIBE or CANCEL stops further automated messages for that connected account; it does not delete existing records or recall a message already sent.
AI, knowledge and human review
When AI features are used, relevant conversation context, approved knowledge and requested media are sent to OpenAI for responses, retrieval or transcription. Approved knowledge may be stored in provider-hosted files and vector stores. In Sayw, approving content for training means adding it to the workspace knowledge used for answers; it does not itself fine-tune a general-purpose model.
The workspace team can review conversations, correct knowledge, take over replies and manage lead qualification. AI can make mistakes. A qualification score or summary supports the team’s workflow and should not be treated as an independently verified fact or a decision about a person’s legal rights. Do not submit sensitive information that is unnecessary for the task.
Who receives information
Authorized workspace team members can access information according to their roles. Providers receive information needed for their functions: Meta/Instagram for connected account and messaging services; Railway for hosting and storage; Cloudflare for delivery, security, site analytics and transactional email; OpenAI for AI, transcription and optional advertising measurement on the public site; and Stripe for checkout and subscription management. Apify is used when the Reels-discovery feature is enabled.
If you connect Frappe or another external service, the data selected for that integration is sent to the configured destination. Those copies are controlled by that service and the workspace business. We may also disclose information when required by law or necessary to address fraud, security threats or legal claims.
Providers may process information in countries other than yours. Their contracts, locations and applicable transfer requirements affect that processing. Contact us for information about the providers and safeguards relevant to your workspace; this policy does not promise storage only in a particular country.
Cookies, local storage and site analytics
We use a signed session cookie for access and security, and preference storage to remember the language you choose. The landing-page notice lets you accept or reject optional advertising measurement. An earlier acknowledgement of the informational notice does not grant this permission. You can change your choice through Cookies in the site footer. These choices do not accept our terms. Browser controls can remove or block storage, but doing so may sign you out or reset preferences.
Cloudflare Web Analytics is also present on the public site. Its beacon measures page views and performance without analytics cookies, according to Cloudflare’s documentation. Infrastructure security and request logs are separate from this measurement.
If you accept advertising measurement, Sayw sends public page views, sign-in button clicks, successful sign-ins and new-account registrations from its server to the OpenAI Conversions API to measure our ChatGPT ads. Events include their type, time and an identifier to prevent duplicate counts, plus an ad-click reference (oppref) when available. Sayw does not load OpenAI’s browser pixel or scan form fields for this measurement. We do not forward names, email addresses, phone numbers, message content, IP addresses or browser user-agent details to OpenAI for advertising measurement. Events are marked as opted out of future user-level personalization. Rejecting or withdrawing permission stops new advertising-measurement submissions and clears the saved ad-click reference. Events already queued may still be delivered; withdrawal does not recall events already sent. Do Not Track and Global Privacy Control also disable this measurement. Storage lifetimes below are browser storage periods, not OpenAI’s conversion-data retention periods.
Sayw also records public page views and sign-in activity for its admin reports. These records contain a page path, referring domain and campaign labels (UTM parameters), not message content, full URLs or a persistent visitor identifier. When you sign in, campaign labels can be linked to your workspace using the existing signed login session. These analytics records are retained for up to 90 days. Browser Do Not Track and Global Privacy Control signals disable this new collection; they do not disable essential operational records or Cloudflare’s separate analytics.
| Storage | Purpose | Typical lifetime |
|---|---|---|
| session | Signed login, invitation and security session | Session or up to 14 days for a persistent session |
| sayw_site_language (cookie) | Chosen public website language, separate from the workspace language | Up to 1 year |
| sayw_language (cookie) | Workspace interface language preference | Up to 1 year |
| commentkey_language (legacy cookie) | An existing language preference is read for compatibility; no new cookies use this name | Until the existing cookie expires or is cleared (up to 1 year) |
| sayw_language (local storage) | Workspace language preference in this browser | Until cleared or replaced |
| sayw_cookie_notice_ack (legacy local storage) | Earlier informational acknowledgement; never used as advertising consent | Until cleared |
| sayw_ads_measurement_consent (local storage) | Your choice about optional advertising measurement; controls whether events are submitted | 180 days, or until the consent version changes |
| sayw_ads_consent (cookie) | Shares your advertising-measurement choice with the sign-in service | 180 days, or until the consent version changes |
| sayw_ads_oppref (cookie, only after consent) | The original OpenAI ad-click reference, used to attribute events to an ad | 30 days, or until permission is withdrawn |
How long information is kept
Retention depends on the record and the feature; there is no single automatic expiry for the entire workspace. Records may need to be retained for security, disputes or legal obligations. Provider copies and backups are subject to their own deletion procedures and retention schedules.
| Record type | Retention approach |
|---|---|
| Legacy automation activity, completed transcript history and Reels results | Routine cleanup uses the configured 90-day window for the covered records. |
| Completed webhook queue records | Successful records: 7 days; terminal failed records: 30 days, under configured cleanup. Pending or retrying events are kept for processing. |
| Accounts, team access, chat history, CRM and AI knowledge | Kept for the workspace service until removed through supported controls or an applicable deletion request. These are not covered by the general activity timer. |
| Temporary downloaded/extracted transcription media | Removed after the processing attempt; resulting transcripts are stored separately. |
| Queued transcription uploads | Stored for processing until the job releases the upload, is deleted or expires. |
| Advertising-measurement delivery records | Event identifiers, types, page paths, times and delivery status are kept for up to 7 days. Ad-click references and event payloads are cleared after delivery or a final failure. |
| Billing, support, provider records and backups | Kept as needed for the service, applicable legal obligations and the relevant provider’s retention process. |
Security and your controls
We use HTTPS, signed sessions, role-based access, webhook signature verification and encryption of stored Instagram access tokens. No system is completely secure. Keep your accounts protected, grant access only to trusted team members and contact us promptly about suspected unauthorized access.
Deleting a transcript or knowledge source, disconnecting a workspace, revoking Meta access, cancelling a subscription and opting out of messages are different actions. In particular, disconnecting does not cancel a Stripe subscription or erase copies already exported to another service. Review billing before disconnecting.
Requests, rights and updates
Depending on your location, you may have rights to access, correct, delete, restrict or object to processing, receive portable data, withdraw consent, or complain to the relevant data-protection authority. These rights have legal conditions and exceptions. We may request proportionate proof of identity and will respond within the timeframe required by applicable law.
Write to legal@sayw.app and identify the connected Instagram account and the information involved. Do not send passwords or access tokens. If we process data for a workspace business, we may coordinate the request with it. We update this notice when practices change and show the updated date; material changes will be communicated as required.
A question about your data?
Contact us about privacy, these terms, or a data request.
legal@sayw.appService operatorComment Key LLC