Privacy Policy
Last updated: September 29, 2026
Baljia AI ("Baljia", "we", "us") runs the Baljia platform at baljia.ai, which gives founders AI agents that build, market and help sell for their business. This policy explains what personal data we collect, why we use it, who we share it with, how long we keep it, and the choices and rights you have. It applies to our website, the Baljia dashboard, and Baljia on WhatsApp and Slack.
1. Who we are
Baljia AI is operated by Baljia AI Private Limited, India. For the personal data described in this policy, Baljia is the data controller (a "data fiduciary" under India's Digital Personal Data Protection Act, 2023). When we process data about your customers, prospects or app users on your behalf, you are the controller and Baljia acts as your processor under our Data Processing Addendum.
Privacy questions and requests: privacy@baljia.ai. Complaints: see section 13.
2. Information we collect
Information you give us
- Account information - your name, email address, and how you sign in (Google sign-in or an emailed sign-in link). We keep a record of your active sign-in sessions so they can be ended.
- Company information - details about your business that you provide (name, idea, website, brand, customers, goals) or that our agents generate on your behalf, including the notes Baljia saves to your company's memory.
- Your content and conversations - messages you send to Baljia in the dashboard, on WhatsApp or in Slack, the tasks you create or approve, files and images you upload, and the work our agents produce.
- Billing details - your plan, payments, credit purchases, and, for Indian tax invoices, the billing name, address and GSTIN you give us.
- Team members - if you invite teammates, their name, email address or phone number, and their role.
- Communications - messages you send to us, and emails received at the company email address Baljia sets up for your business.
- Free SEO audits and the waitlist - if you request a free SEO audit on our website, the email address you give us and the web address you ask us to audit (we email you the report). If you join our waitlist, your email address.
Information collected automatically
- Usage and log data - pages and features you use, tasks run, agent activity, errors, and timestamps. Error reports go to our error-monitoring provider.
- IP address and device information - your IP address, browser and device type, time zone and language. We use your IP address to protect the service (for example rate limiting and abuse prevention) and to estimate your country so we can show the right currency and prices. When you set up a company, we look up your approximate location (city, region, country and time zone) from your IP address and save it to your company's memory, so the agents know where you are based. If you request a free SEO audit or join our waitlist, we store your IP address with that request.
- Cookies and similar technologies - see section 14.
Payment information
Plans and credit packs are billed through Razorpay (in rupees in India, in US dollars elsewhere). Some older plans and some ad-spend charges are billed through Stripe. These payment providers collect your card, UPI or bank details directly. We receive the payment result, amount, currency, plan, and customer and subscription IDs. We do not receive or store full card numbers.
Accounts and channels you connect
We only receive this data if you choose to connect the account or channel.
- Connected Instagram professional-account data - the account ID, username, access permissions, selected post/reel/story IDs, and the minimum media details needed to let you choose where an automation runs.
- Connection credentials - the Instagram access token and its expiry, stored in encrypted form while the connection is active.
- Instagram interaction data - signed webhook events for comments, direct messages, quick-reply or button responses, including the sender's Instagram-scoped ID, username when Meta makes it available, message or comment text, media IDs, timestamps, and delivery results.
- Consented Instagram profile data - after a person starts a qualifying messaging interaction, we may read their name, username, follower count, and whether they follow the connected business when an automation you configured needs those values. A comment by itself is not treated as consent for this profile lookup.
- Lead information - an Instagram interaction may create an inbox or CRM lead record. If a person voluntarily provides an email address in the conversation, the email may be attached to that lead.
- WhatsApp - if you use Baljia on WhatsApp (through Meta's WhatsApp Business Platform), your phone number, WhatsApp profile name, and the messages, voice notes, images and documents you send, including messages in WhatsApp groups you add Baljia to. Voice notes are transcribed to text so Baljia can act on them.
- WhatsApp customer support assistant - if you connect your own WhatsApp Business number and turn on the support assistant: your WhatsApp Business account and phone number IDs, the access token for your number (stored encrypted), the business information you write for the assistant, and, for each customer who messages that number, their phone number, WhatsApp profile name and message text. The customer's message and your business information are sent to our AI providers (see section 4) to write the reply. The assistant is instructed to answer only from the information you give it and to hand questions it cannot answer to you. Messages that mention refunds, payments, cancellations, invoices, chargebacks or discounts get no reply from the assistant; you are alerted instead. For your customers' data you are the controller and Baljia acts as your processor (see section 1).
- LinkedIn - if you connect LinkedIn, either through LinkedIn's own sign-in (for posting) or through our provider Unipile (for messages, invitations, profile visits, reactions and comments): your profile basics and connection status, the posts, messages and invitations Baljia drafts or sends for you, the replies you receive, and public profile details of the people you engage with.
- X, Reddit, Facebook and Instagram publishing - if you connect these accounts (through X's own sign-in or through our provider Composio): your handle or page, the posts and replies Baljia publishes for you, and engagement on them such as likes, replies and comments.
- Slack - if you add Baljia to Slack: your workspace and channel IDs, the names and IDs of members allowed to use Baljia, and the messages sent to Baljia there.
- Google and other business apps - if you connect apps through our provider Composio, such as Gmail, Google Calendar, Google Drive, Google Sheets, Google Analytics, Google Search Console, Google Ads, Outlook, HubSpot, Salesforce, Notion, Calendly, Airtable, Zoom, Shopify or Stripe: the data Baljia needs from them for the work you ask for, and the actions it takes in them on your instructions. See section 5 for Google data.
- Advertising accounts - if you run ads through Baljia: your Facebook Page, ad campaigns, budgets and performance data, and any contact lists you upload for audiences (hashed before upload, see section 6).
- Your own payment and publishing accounts - if you connect your own Stripe or Razorpay account so your app can take payments, or a WordPress site, GitHub repository or SMS account so Baljia can publish for you: the account IDs and the keys or passwords you provide, stored encrypted.
- Website logins for the browser agent - if you ask Baljia's browser agent to work on a website that needs a login, the site, username and password you provide. Passwords are encrypted when we save them and are used only to sign in to that site for your tasks.
Information about other people
- Prospects - to find potential customers for your business, Baljia may collect business contact details about people who are not Baljia users: name, job title, company, business email address, whether that email address is deliverable, public profile URLs (such as LinkedIn), and public posts. This comes from lead-data and research providers (Apollo, Hunter, Apify and Explorium) and from public web pages and social profiles.
- People who reply or engage - replies to messages Baljia sends for you, comments and messages on your connected accounts, and opt-out or unsubscribe requests. When someone opts out, we mark them as opted out of that founder's outreach so Baljia does not contact them again for that business.
- Link clicks - when someone clicks a tracked link in content Baljia published for you, we record the time, the referring page, the browser type and the campaign tags, to measure results. We do not store the clicker's IP address with this record.
- Users of apps built with Baljia - apps and websites Baljia builds and hosts for you may collect data from your own users (for example sign-up details and what they enter in your app). We process it for you as your processor.
If you are a prospect or contact and want to know what we hold about you, or want it deleted, email privacy@baljia.ai. To stop emails, reply "unsubscribe" to any email Baljia sent for a business.
3. How we use information, and our legal bases
Where the EU or UK GDPR applies, we rely on the legal bases below. Under India's DPDP Act we rely on your consent, given when you sign up and when you connect an account, and on the legitimate uses the Act allows.
| Purpose | Main data used | Legal basis |
|---|---|---|
| Create and run your account, company and AI agents, and host the apps and pages Baljia builds | Account, company, content, usage | Performance of our contract with you |
| Do the work you ask for in connected accounts and channels (posting, messaging, outreach, ads, reading your business apps) | Connected-account data, content, prospect data | Contract; consent where the platform or law requires it, which you can withdraw by disconnecting |
| Receive the Instagram comments and messages you subscribe to, match them against automations you configure, send permitted replies or messages, enforce conversation windows and opt-outs, and show results in your Baljia inbox and CRM | Instagram data listed above | Contract; the messaging person’s qualifying interaction, as Meta’s rules require |
| Answer customers who message your connected WhatsApp Business number, inside the customer-service window Meta allows, and pass the messages the assistant must not answer to you | WhatsApp support assistant data listed above | Contract with you; for your customers’ data Baljia acts as your processor, and the customer’s own message starts the conversation |
| Run and optimize advertising you authorize (for example, Meta ads), including building audiences from contact lists you provide | Advertising account data, hashed contact lists | Contract |
| Take payments, manage plans and credits, issue invoices, and keep tax records | Billing and payment data | Contract; legal obligation |
| Provide support and send service messages (task updates, approvals, billing notices) | Account, content, communications | Contract |
| Keep the platform secure, prevent fraud and abuse, and enforce our Terms | IP address, device, usage and log data | Legitimate interests (keeping Baljia and its users safe); legal obligation |
| Fix errors and improve the service | Usage, log and error data | Legitimate interests (running a reliable product) |
| Understand how our website is used (analytics cookies) | Cookie and usage data, and for signed-in users their name and email address | Consent, which you can withdraw at any time |
| Measure how the product is used: sign-ups, tasks created and completed, and purchases (server-side product analytics, sent whether or not you accept cookies) | Company and account IDs, and event details such as a task title or the plan bought | Legitimate interests (understanding and improving the product). You can object by emailing us, see section 12 |
| Run a free SEO audit you request and email you the report | Email address, the web address audited, IP address | Steps you asked us to take |
| Find and contact prospects for a founder | Prospect data | The founder’s legitimate interests or consent, decided by the founder as controller; see our DPA |
| Comply with law and respond to lawful requests | Any data the request covers | Legal obligation |
| Handle a merger, acquisition or sale of assets | Any data needed for the transaction | Legitimate interests |
4. How AI processes your data
Baljia's agents run on large language models and other AI services. To do the work you ask for, we send the relevant parts of your data (your messages, company context, task details, documents, and data from connected accounts that the task needs) to AI providers, which return results to us. The providers we use include:
- Language model providers - OpenAI, Anthropic (directly and through Amazon Bedrock), Google (Gemini), MiniMax and DeepSeek directly, and OpenRouter, which passes each request to a company that runs the model we choose, either the model's maker or another host. Some of these model makers are based in China, for example Alibaba Cloud (Qwen), Zhipu AI (GLM), Moonshot AI (Kimi), MiniMax and DeepSeek.
- Specialist AI services - speech-to-text for voice notes (Deepgram), image and video generation (fal.ai and HeyGen), and web search, crawling and research tools (such as Tavily, Parallel, Perplexity and Firecrawl).
Which provider handles a request can change as we route work for quality, availability and cost. We do not use your business data to train foundation models. The AI providers process the data under their own API terms to return results to us. AI output can be wrong, so Baljia asks for your review and approval at the points you choose.
5. Google user data
If you sign in with Google, we receive your name, email address and Google account ID. If you connect Google services such as Gmail, Google Calendar, Google Drive, Google Sheets, Google Analytics, Google Search Console or Google Ads, Baljia reads and acts on that data only to provide the features you ask for, for example reading an email you ask about, checking your calendar, or checking your site's search performance. We do not sell Google user data, and we do not use it to serve ads (including personalised or retargeted ads). We do not use Google user data to develop, improve or train generalized or non-personalized AI or machine-learning models.
Baljia's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The use of information received from Google Workspace scopes will adhere to the Google User Data Policy, including the Limited Use requirements.
6. Advertising
When you authorize advertising, we create and manage campaigns on your behalf. Audience lists you provide are hashed before being sent to ad platforms. You control budgets and approve campaigns.
If you turn on conversion tracking for your ads, Baljia can send conversion events from your app to Meta, with identifiers such as email addresses hashed (SHA-256) first, so Meta can measure and optimise your campaigns.
7. Instagram automation
Only a Baljia workspace administrator can connect an Instagram professional account and configure its automations. Baljia requests instagram_business_basic, instagram_business_manage_comments, and instagram_business_manage_messages for this feature. We use comments, messages, and messaging postbacks; we do not request Instagram content-publishing or insights permission for AutoDM.
Comment-triggered private replies are limited to Meta's permitted reply flow. Ongoing direct messages and profile lookups require the person's qualifying messaging interaction, and Baljia stops automated sends for people who opt out.
Incoming Instagram webhook request bodies are verified and processed but are not stored as raw request bodies. We retain only normalized connection, event, rule-match, delivery, suppression, inbox, CRM, and security records needed to operate and protect the feature.
Instagram access tokens are encrypted at rest. We retain connected-account, webhook, automation-run, delivery, inbox, and CRM records while they are needed to provide the connected feature. When Meta sends a valid deauthorization or data-deletion request, Baljia removes the connection and its Meta-derived webhook, delivery, inbox, CRM lead, and captured-email records from active systems. Founder-authored automation definitions may remain disconnected without the deleted Instagram personal data. You may also request deletion using our data-deletion instructions.
Disconnecting Instagram removes the provider subscription, pauses active automations, and destroys the reusable access token. Founder-authored automation definitions and limited disconnected connection or audit records may remain so the workspace owner can manage them.
8. How we share information
We do not sell your personal information, and we do not sell Instagram Platform Data. We share personal data only as follows:
- Service providers (subprocessors) that host, store, secure, bill, email and run AI for Baljia, under contracts that limit their use of the data. The full list, with what each one does and where, is on our Subprocessors page.
- Meta Platforms - Instagram professional-account login, webhooks, messaging/comment APIs, WhatsApp messaging, and advertising via the Meta Marketing API. Contact lists used for matched advertising audiences are hashed (SHA-256) before upload.
- Platforms you connect - when Baljia posts, messages or acts for you on LinkedIn, X, Reddit, Facebook, Instagram, Slack, Google or another connected service, that service receives the content and handles it under its own terms and privacy policy.
- People you contact - messages Baljia sends for you go to their recipients, with you as the sender.
- Your team - members of your company workspace can see company data according to their role.
- Legal reasons - when required by law, court order or a lawful request from authorities, or to protect the rights, safety and property of Baljia, our users or others.
- Business transfers - if Baljia is involved in a merger, acquisition, financing, reorganisation or sale of assets, personal data may transfer to the successor, which must keep protecting it as this policy describes. We will tell you before your data becomes subject to a different privacy policy.
- With your consent - in any other case, only when you ask us to.
9. International transfers
Baljia is operated from India, and our application servers run in the United States. Our service providers process data in the United States, India, the European Union and other countries, and some of the AI model makers we use (Alibaba Cloud, Zhipu AI, Moonshot AI, MiniMax and DeepSeek) are based in China. So your data may be processed outside the country where you live.
When personal data from the European Economic Area, the United Kingdom or Switzerland goes to a country without an adequacy decision, where required we rely on Standard Contractual Clauses or another lawful transfer mechanism. Transfers of data from India follow the DPDP Act, including any country restrictions the Government of India notifies.
10. How long we keep data
| Data | How long we keep it |
|---|---|
| Account and company data, conversations, tasks, memory and generated work | While your account is open. When you ask us to delete your account or company, we delete it within 30 days of confirming your request. Deletion is permanent and cannot be undone (see our Data Deletion page). |
| Access tokens and keys for connected accounts | Until you disconnect the account or we delete your company account. |
| Website passwords saved for the browser agent | Until you ask us to remove them or we delete your company account. |
| Instagram connection and automation records | As described in section 7. Removed from active systems when you disconnect or when Meta sends a valid deletion request. |
| WhatsApp support assistant settings and customer message records | While your company account is open. Disconnecting your number stops the assistant and destroys the access token, and later messages to that number are not answered; records of past messages stay until you ask us to delete them or delete your company account. |
| Prospect and contact records | While the founder’s company account is open, or until they are deleted on the founder’s instruction or where the law requires. |
| Opt-out and unsubscribe records | While the founder’s company account is open, so Baljia does not contact that person again for that business. |
| Free SEO audit requests and waitlist sign-ups | Until you ask us to delete them. |
| Payment records and tax invoices | As long as tax and accounting law requires. |
| Sign-in session cookie | 30 days, or until you sign out. |
| Security, usage and error logs | As long as needed to keep the service secure and fix problems, then deleted. |
| Analytics data | As long as needed to understand how the site and product are used, then deleted or aggregated. |
| Backups | Until the backup lifecycle completes. |
We may retain limited records when required by law, and backup copies may remain until the applicable backup lifecycle completes.
11. Security
We protect data with encryption in transit (HTTPS), encryption of the access tokens, keys and passwords you give us when we store them, access controls, revocable sign-in sessions, and audit records for sensitive actions. No method of transmission or storage is fully secure. If a personal data breach affects you, we will notify you and the relevant authorities as the law requires, without undue delay. To report a security issue, email security@baljia.ai (see our security reporting guidelines).
12. Your rights
Depending on where you live, you may have the right to:
- access the personal data we hold about you and get a copy of it;
- correct data that is wrong or incomplete;
- delete your data;
- export your data in a portable format;
- object to or restrict certain processing, including processing based on legitimate interests;
- withdraw consent at any time, without affecting processing that already happened (for example, by declining analytics cookies or disconnecting an account);
- nominate another person to exercise your rights if you die or become unable to, under India's DPDP Act.
You need to give us your email address to create an account. Other information is optional, but some features cannot work without it (for example, Baljia cannot post to an account you have not connected). We do not make decisions about you based solely on automated processing that have legal or similarly significant effects. Automated security checks, such as rate limits, can slow or block requests for a time; if you think one affected you wrongly, email support@baljia.ai.
To use any of these rights, email privacy@baljia.ai from the email address on your account (or tell us how to identify you if you are not a Baljia user). We may ask you to confirm your identity before acting. We reply within 30 days, or sooner where the law requires; if a request is complex we will tell you why we need more time. For account and Instagram deletion steps, see our Data Deletion page. If you are a user of an app built with Baljia, please contact that app's owner first, and we will help them respond.
13. Complaints and Grievance Officer
If you have a concern about how we handle your data, please contact our Grievance Officer first:
Grievance Officer
Email: grievance@baljia.ai
We acknowledge complaints within 24 hours and resolve them within 15 days.
If you are not satisfied with our response, you can complain to the Data Protection Board of India. If you are in the European Economic Area or the United Kingdom, you can also complain to your local data protection authority (in the UK, the Information Commissioner's Office).
14. Cookies and similar technologies
We use strictly necessary cookies for sign-in and security; these are required for the platform to work. With your consent, we also use analytics tools (Google Analytics and PostHog) to understand how the site is used so we can improve it. Analytics cookies are set only after you accept them in our cookie banner, and declining them does not affect your ability to use the platform. If you accept them and are signed in, PostHog links this browsing data to your account, including your name and email address.
Separately from cookies, our servers send PostHog a small set of product events for every account (sign-ups, tasks created and completed, and purchases), with your company and account IDs and details such as a task title or the plan bought, but not your name or email address. We do this on the basis of our legitimate interests in understanding and improving the product. To object, email privacy@baljia.ai.
| Name | Type | Purpose | Duration |
|---|---|---|---|
baljia-session | Strictly necessary | Keeps you signed in | 30 days |
oauth-state, oauth-redirect | Strictly necessary | Protects Google sign-in from forged requests, and remembers where to return you | 10 minutes |
baljia-*-state | Strictly necessary | Protects connections to Instagram, social accounts and Stripe from forged requests | 10 minutes |
baljia_cookie_consent | Strictly necessary (browser storage) | Remembers your cookie choice | Until you clear your browser storage |
baljia-theme | Preference (browser storage) | Remembers light or dark mode in the dashboard | Until you clear your browser storage |
_ga, _ga_* | Analytics, only with consent | Google Analytics: counts visits and how the site is used | Up to 2 years |
ph_*_posthog | Analytics, only with consent | PostHog: product analytics (session recording is off) | Up to 1 year |
You can change or withdraw your choice at any time using Cookie settings in the site footer or .
15. Children
Baljia is for people aged 18 and over. The platform is not directed to individuals under 18, and we do not knowingly collect their information. If you believe a child has given us personal data, email privacy@baljia.ai and we will delete it.
16. Changes to this policy
We may update this policy. We will post the updated version here with a new "Last updated" date, and if a change materially affects how we use your personal data, we will tell you by email or in the dashboard before it takes effect.
17. Contact
Privacy questions and requests: privacy@baljia.ai. Everything else is on our Contact page.