Privacy policy
This application helps authorized staff manage customer-initiated inquiries for nonmedical appointment businesses. The operating entity has not yet been configured. The fictional sample workspace uses sample customer conversations.
Information processed
When you authorize a live connection, Sumi processes account identifiers, display names, granted permissions, authorization tokens, and the conversations or channel content you ask it to retrieve. Instagram and X connections support messaging; YouTube supports comments; TikTok supports your basic profile and videos. Twilio supports SMS inquiries; we process sender and recipient phone numbers, message bodies, message identifiers, consent/opt-out events and delivery results. We also store business information you enter, reply drafts, workflow status and an activity trail.
AI processing
When you request a draft or setup proposal, the relevant business facts, inquiry text and any image you attach may be sent through OpenCode Go to deepseek-v4-flash-vision-exp, using a project-local Pi agent. AI assistance is available when enabled by the workspace operator. Processing live account content is disabled by default and requires the operator to establish the appropriate platform permissions and processing arrangements first.
This application does not train or fine-tune models on your data. Provider processing and retention are governed by the operator’s applicable provider agreements; provider retention may differ from Sumi’s retention periods. The AI proposes text for your review and cannot send messages itself.
Storage and retention
Application records are stored in Postgres. Connection tokens are encrypted. JetStream carries job identifiers, not conversation text or images. Uploaded image payloads are removed from the job record after processing. Sample workspaces expire after one day; inactive live workspaces and their content expire after 30 days. Session access expires after 12 hours. You may delete your workspace sooner using the in-app controls.
Message history is limited to 30 days, including within active conversations. Social account metadata and tokens expire after 30 days unless refreshed or reauthorized; an expired connection must be reconnected. Platform revocation and deletion requirements take precedence. The operator must also establish appropriate retention and deletion for production backups before public use.
Sharing and control
Data is used to provide the features above. Sumi does not sell data or use it for advertising audiences. You can disconnect a platform, revoke its access, and delete your local workspace records. A platform may retain its own copy of messages you sent.
For Google authorization, you can also remove access in your Google account permissions. Sumi’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements. YouTube use is also subject to the YouTube Terms of Service and Google Privacy Policy.
Mobile information and consent
Mobile numbers and SMS opt-in or consent information are not sold, rented, or shared with third parties or affiliates for marketing or promotional purposes. We use service providers such as Twilio to deliver and operate your requested messaging service. Any enabled model processing is limited to preparing the requested reply, as described above. SMS frequency varies with your inquiry; message and data rates may apply. Reply STOP to opt out or HELP for help.
SMS consent events and delivery records expire after 30 days. A keyed, non-readable contact fingerprint and suppression status are retained after disconnect or workspace deletion to prevent unwanted texting if the sender is reconnected. Only an authenticated customer opt-in message changes an existing opt-out; ordinary messages do not reset it. Twilio and carriers maintain their own opt-out records and message retention.
Cookies
A necessary HttpOnly session cookie keeps you signed in. Sumi does not install advertising pixels or analytics trackers.
Operator contact
Operator identity not configured.
support@asksumi.ai