Privacy Policy

Last updated: 1 June 2025

1. Who we are

Effora AI ("Effora", "we", "us") is a SaaS platform operated by Leadflow AI Systems. We help service businesses — primarily coaches and consultants — manage their Instagram DM and WhatsApp inbox, automate booking and payment workflows, and grow their client base.

Contact: leadflowai.systems@gmail.com

2. Data we collect

  • Account data: your name, email address, and password hash when you register.
  • Business data: your organisation name, voice profile (tone, offer), and configuration settings.
  • Lead data: names, Instagram handles, phone numbers, email addresses, and conversation history for your leads — entered by you or automatically captured from connected channels.
  • Messages: the content of Instagram DMs and WhatsApp messages exchanged between your leads and your account. We store these to power the AI reply feature and your inbox.
  • Booking and payment data: meeting dates/times, booking links, payment amounts, and transaction references (Razorpay order IDs). We do not store full card numbers.
  • Usage data: page views, feature usage events, error logs — collected to improve the service.
  • Device and access logs: IP addresses, browser type, and access timestamps for security auditing.

3. How we use your data

  • Operate and display your inbox, CRM, bookings, and payments dashboards.
  • Generate AI-drafted replies in your voice (content is sent to Groq's API — see §5).
  • Send booking confirmation and payment reminder messages on your behalf.
  • Send transactional emails (booking confirmations, payment receipts) via Brevo.
  • Process subscription payments via Razorpay.
  • Provide customer support when you contact us.
  • Detect and prevent fraud, abuse, and security incidents.
  • Comply with legal obligations.

We do not sell your data to third parties. We do not use your leads' data for advertising.

4. Retention

We retain your data for as long as your account is active. If you delete your account, we delete all associated data within 30 days, except where we are legally required to retain it (e.g., financial records for 7 years under Indian law).

Inactive accounts (no login for 18 months) may be deleted after 30-day notice by email.

5. Third-party services

ServicePurposeData shared
SupabaseDatabase + authAll user and app data
VercelHosting + CDNRequest logs, IP addresses
Groq APIAI message generationMessage content (no PII beyond conversation context)
Meta (Instagram / WhatsApp)Channel integrationMessage content, user IDs
RazorpayPayment processingPayment amounts, customer name
BrevoTransactional emailRecipient email, name
Cal.comCalendar bookingMeeting times, attendee name
UpstashRate limiting cacheRequest identifiers only

6. Your rights

  • Access: request a copy of all data we hold about you.
  • Correction: ask us to fix inaccurate data.
  • Deletion: request deletion of your account and all associated data (see §7).
  • Portability: export your leads, bookings, and payments data as CSV from within the app (Settings → Account → Export data).
  • Withdraw consent: disconnect any channel integration at any time from Settings → Channel.
  • GDPR (EU/EEA users): you also have the right to object to processing and to lodge a complaint with your local supervisory authority.

To exercise these rights, email leadflowai.systems@gmail.com.

7. Data deletion

To delete your account and all associated data:

  1. In the app: Settings → Account → Delete account.
  2. By email: send a deletion request to leadflowai.systems@gmail.com with subject "Data deletion request" and your registered email address.

We process deletion requests within 30 days. See also our Data Deletion Instructions page.

8. Cookies

We use strictly necessary cookies (session tokens for authentication) and basic analytics cookies. No advertising or tracking cookies are used. You can disable cookies in your browser but this will prevent login from working.

9. Security

We implement industry-standard security: TLS 1.3 in transit, AES-256-GCM encryption for sensitive credentials at rest, access controls, and regular security audits. See our Security page for details.

10. Children

Effora is not directed at children under 13. We do not knowingly collect data from children. If you believe a child has registered, contact us immediately.

11. Changes to this policy

We will notify you by email at least 14 days before material changes take effect. Continued use of the service after the effective date constitutes acceptance.

12. Governing law

This policy is governed by the Information Technology Act 2000 (India) and, where applicable, the GDPR. Disputes are subject to the jurisdiction of courts in Pune, Maharashtra, India.

Contact

Privacy questions: leadflowai.systems@gmail.com