Skip to content
Dichat.ai
Channels Features In action Integrations Pricing FAQ
  • UZ — O'zbekcha
  • RU — Русский
  • EN — English
Sign in Start free

Dichat.ai

Privacy Policy

Last updated: 2026-08-14

This policy explains how personal data is collected, used, and protected when you use Dichat.ai. It is written to meet the requirements of the Republic of Uzbekistan’s Law on Personal Data.

1. Who processes the data

The service operator is Dichat.ai (“we”). Contact: privacy@dichat.ai.

The business using the service (you) is the owner of its customers’ data; we act as a processor working on your instruction. You decide what happens to customer data; we work only within what is needed to deliver the service.

2. What we collect

Your account

Signing in with Telegram gives us your Telegram ID, first and last name, username, and profile photo (if public). You additionally provide a phone number and an organisation name.

About your organisation

During onboarding you describe your business: industry, website or Instagram page, opening hours, address, product and service descriptions, prices. The AI agent needs this to answer.

Conversations with your customers

Message text from Instagram Direct and comments, the customer’s Instagram profile data, the contact details the agent extracted (name, phone number), and the goal and status formed during the conversation.

Payment data

Plan payments run through Click and Payme. Card details never reach us — they stay with the payment provider. We store only the fact, amount, and date of a payment.

Technical data

Sign-in time, IP address, browser and device type. Used for security and to detect suspicious sign-ins.

3. Why we use it

  • To deliver the service: the agent’s replies, storing conversations, syncing to your CRM.
  • To protect your account and detect suspicious activity.
  • To count plan limits and process payments.
  • To improve the service — in aggregate, non-identifying form.
  • To answer official requests from authorities where the law requires it.

We do not sell your data or your customers’ data, and we do not pass it to third parties for advertising.

4. Instagram and Meta

Your Instagram account connects only through Meta’s official API. You grant permission on your own Instagram page and we receive an access token.

  • Your password is never visible to us.
  • The token is stored encrypted and is never logged.
  • We request only the permissions a shipped feature exercises.
  • You can revoke access at any time, from Instagram’s settings or from our dashboard.

Once revoked, we stop receiving new data from Instagram.

5. Who we share with

The service relies on the following providers:

Who What for Where
Meta Platforms Instagram Direct and comments US / EU
AI model provider Producing the agent’s replies US / EU
amoCRM, Bitrix24, Google The CRM and sheets you connect The service you choose
Click, Payme Taking payments Uzbekistan
DigitalOcean Servers and database Germany (Frankfurt)

Each has its own privacy policy, and we share only what delivering the service requires.

6. Where it is stored

Data is held on servers in Germany (Frankfurt). Each organisation’s data is separated at the database level — reaching another tenant’s conversation is not technically possible.

All tokens and secret keys are stored encrypted. Connections to the service run over TLS only.

7. How long we keep it

  • Conversations and customer data — 12 months, then deleted automatically.
  • Trial data — 30 days after the trial ends.
  • Payment records — for the period accounting law requires.
  • Audit log — longer, for security.

A deletion request is carried out immediately, regardless of these periods, except for records the law requires us to keep.

8. Your rights

You have the right to:

  • Know — ask what data is held.
  • Correct — fix inaccurate data.
  • Erase — your own data, or a specific customer’s.
  • Port — receive your data in a machine-readable format.
  • Withdraw consent — disconnect Instagram, close your account.

Step-by-step instructions are on the Data deletion page. Send requests to privacy@dichat.ai; we answer within 30 days.

9. Cookies and similar technologies

The marketing site (dichat.ai) uses no tracking cookies. Your browser stores only the theme you chose (light or dark) in localStorage, and that is never sent to a server.

The dashboard (app.dichat.ai) uses an HttpOnly cookie to hold your session. It is strictly necessary and cannot be turned off.

10. Minors

The service is intended for business users. We do not knowingly collect data from anyone under 18.

11. Changes

When this policy changes, the date on this page is updated. We notify you of material changes by email or in the dashboard.

12. Contact and company details

Questions: privacy@dichat.ai

The full legal name, tax identification number, and registered address will be added to this section before the service launches publicly.

Dichat.ai

An AI sales manager answering across your messengers, 24/7.

Solutions

  • Instagram Direct
  • Instagram comments
  • Clinics
  • Online stores
  • Beauty salons
  • amoCRM integration

Product

  • Features
  • In action
  • Integrations
  • Pricing

Company

  • FAQ
  • Contact

Legal

  • Privacy policy
  • Terms of service
  • Public offer
  • Data deletion

© 2026 Dichat.ai. All rights reserved.

  • O'zbekcha
  • Русский
  • English