Legal
Privacy Policy
Last updated: September 7, 2026
OpenLivery is an AI agent platform for agencies, available as an open-source project you can self-host and as a managed cloud service at app.openlivery.com, operated by Megacubos, LLC ("we", "us"). This policy describes what personal information we collect through openlivery.com, the OpenLivery mobile apps and the managed cloud service, and how we handle it.
Self-hosted deployments of the open-source software are operated by the organization that hosts them; that organization is responsible for its own privacy practices.
Information we collect
- Account information. Name, email address and login credentials when you create a workspace. In the managed service, agency administrator authentication uses Supabase. Mobile portal operators sign in to the workspace API with credentials managed by their organization. We never store plain-text passwords.
- Workspace content. The clients, AI agents, knowledge documents and conversations that you create and manage in your workspace.
- End-user messages. Messages that your clients' customers send through the channels you connect (such as web chat or WhatsApp), which we process on your behalf to generate responses.
- Billing information. Payments are processed by Stripe. We store your subscription status and invoicing details, never full card numbers.
- Technical data. Log data such as IP addresses, request metadata and aggregate usage metrics that keep the service secure and reliable.
Mobile app, media and your choices
Workspace information. The mobile app accesses your operator identity and the contacts, names, phone numbers, notes, conversations and activity associated with your portal. Messages and the photos, recordings, videos and files you send are stored in that workspace and delivered through its connected messaging channels.
AI and connected services. Depending on the workspace configuration, conversation text and history, photos and audio may be sent to configured AI providers. Voice recordings may be transcribed and images described; the resulting text can be stored with the conversation. This processing can also occur while a human operator is handling a case. Configured tools and integrations may receive conversation information needed to perform their actions. The mobile privacy screen lists the service names, destination hosts and processing capabilities reported by your workspace, including custom provider endpoints.
Optional device permissions. The app requests microphone, camera or photo access when needed for the feature you choose. Recordings can be reviewed before you choose to send them. Notification permission is optional and can be changed in your device settings.
Push delivery. When notifications are enabled and the managed service is configured to use OneSignal, our server sends the native push token and platform to OneSignal to create a subscription. To deliver an alert, it sends subscription identifiers, the notification title and message preview, and conversation or client identifiers through OneSignal's API. Apple or Google push services deliver the alert to your device. The mobile app does not embed the OneSignal SDK. Other deployments may use a different notification provider, identified in the workspace disclosure.
Storage on your device. The native app stores its session token and consent record in the operating system's protected credential storage. Media downloaded for playback and files prepared for sending can be kept in the app's local cache. Draft text is kept in memory during the app session. Signing out removes the saved session credentials and clears those in-memory drafts; cached media may remain until the app or operating system clears the cache.
Consent and withdrawal. Before opening workspace content, the app asks you to review and explicitly accept its data processing disclosure. A changed disclosure requires new consent. You can review this information or withdraw consent under Privacy and data in the account menu. Withdrawal closes access from the app and signs you out; it does not delete existing workspace records or disconnect services managed by your organization. For deletion requests, follow the retention and rights sections below or contact the organization that operates your self-hosted workspace.
WhatsApp and Meta Platform Data
When you connect a WhatsApp Business account through our integration with Meta, we receive information about the business assets you choose to share (such as the WhatsApp Business Account id, phone number id and display name) and an access token that lets the platform operate the channel. Access tokens are stored encrypted. Message content delivered to us by Meta's webhooks is used only to provide the service: generating and sending the replies configured by the workspace that owns the channel. We use Meta Platform Data only as permitted by the Meta Platform Terms, we do not sell it, and we delete it when the channel is disconnected or the workspace is deleted.
How we use information
- Providing and operating the service, including routing conversations to the AI agents you configure.
- Generating AI responses. Conversation content is sent to the AI provider configured for your workspace (for example OpenAI or another compatible provider), acting as a processor.
- Billing, support, security, abuse prevention and compliance with legal obligations.
We do not sell personal information, and we do not use your workspace content to train our own models.
Who we share it with
We share data only with the service providers needed to run the platform: cloud infrastructure (Google Cloud), our database and authentication provider (Supabase), payment processing (Stripe), message delivery (Meta, for WhatsApp channels), optional notification delivery (OneSignal when configured), and the AI providers and integrations configured for your workspace. Each provider processes data only to provide its service to us.
Retention and deletion
We keep your data while your workspace is active. When you delete your workspace, or ask us to, we delete the associated personal information within 30 days, except where a longer retention is required by law (for example invoicing records).
Security
All traffic is encrypted in transit with TLS. Credentials such as AI provider keys and channel access tokens are encrypted at rest, and every workspace is isolated from the others.
Your rights
You can access, correct, export or delete your personal information at any time from the platform or by contacting us. If you are in a jurisdiction with specific data protection rights (such as the GDPR), we honor requests to exercise them.
Children
The service is intended for businesses and is not directed to children.
Changes
If we make material changes to this policy we will update this page and note the new date at the top.
Contact
For privacy questions or requests, write to support@megacubos.com.
