Privacy Policy
Pivra.ai — Operated by Bluebird Technologies Pty Ltd (ABN 57 628 676 764)
Last updated: 30 August 2026
1. Overview
We comply with the Privacy Act 1988 (Cth) and Australian Privacy Principles (APPs).
2. Information We Collect
Information You Provide
- Name and email address
- Business information
- Uploaded documents and content
- Chatbot configuration data
- Conversation content
Automatically Collected Information
- IP address
- Device and browser information
- Usage logs and analytics data
Payment Information
Payments are processed by Stripe. We do not store full credit card details.
3. How We Use Information
We use personal information to:
- Provide and maintain the Service
- Process payments
- Improve product reliability, safety and answer quality
- Provide support
- Prevent fraud and misuse
- Comply with legal obligations
We do not sell personal information.
4. Data Storage and Location
Pivra configures its core application and database services in Sydney or Australian regions where the relevant provider offers and supports that configuration. This does not mean every service operation or provider access occurs only in Australia.
Our material provider categories and current providers include Vercel for web and embed delivery, Fly.io for application infrastructure, Supabase for database, authentication and file storage, OpenAI for AI generation and embeddings, and Stripe for payment processing.
Depending on the features a customer enables, Pivra may also use Amazon SES for transactional email, Twilio or Meta for messaging channels, and customer-selected integration providers. Optional website analytics and advertising measurement may use Google Analytics, Google Ads and Meta Pixel after the relevant consent choice and only when configured.
These providers may process or permit authorised support access from jurisdictions outside Australia. We take reasonable steps appropriate to the circumstances to assess providers and address applicable cross-border disclosure obligations.
5. AI Data Processing
User content, knowledge sources and conversations may be sent to OpenAI's API to generate responses and embeddings. Pivra sends the context needed for the requested operation rather than giving the provider direct access to a customer's Pivra account or WordPress administration.
Provider security or abuse-monitoring retention may apply under the provider account configuration and current service terms. Pivra does not promise zero provider retention unless that control has been specifically verified for the applicable production service.
You are responsible for ensuring you have lawful authority to submit personal information for processing and for configuring your chatbot so it does not request information your business does not need.
6. Data Security
We implement reasonable safeguards including:
- Encryption in transit and at rest
- Access controls and authentication mechanisms
- Regular security reviews
No system is completely secure.
6A. Agent Actions and Interactive Widgets
Customers may configure agent actions that send visitor-provided fields to customer-selected third-party endpoints and display interactive forms, cards or controls in a conversation. The customer decides which actions to enable, supplies the endpoint and disclosure, and is responsible for having lawful authority to process the information.
Pivra encrypts configured action credentials and does not intentionally expose them to the AI model or visitors. Actions that change external data require an explicit, time-limited visitor confirmation. The destination provider's privacy terms also apply.
7. Data Retention
Account, chatbot, knowledge, conversation and lead data is generally retained while the customer account is active and as needed to provide the selected features. Shorter feature-specific windows may apply to delivery logs, diagnostics and recoverable archived items.
WordPress connection records, including the connected domain, plugin version and health history, are retained while the installation is active. A disabled record may remain after disconnect for security, abuse prevention and operational history. Raw one-time setup codes are not retained after exchange; Pivra stores a one-way hash and limited audit metadata.
After account deletion or a verified deletion request, we remove or de-identify data from active systems subject to legal, tax, fraud-prevention, security, backup and dispute obligations. Backup copies expire through the applicable provider's backup lifecycle rather than being individually edited. Payment providers may retain transaction records under their own legal obligations.
We may retain aggregated or de-identified information that no longer identifies an individual. Contact us for the retention boundary that applies to a particular feature or account.
7A. Email Helpdesk Channel
When a customer enables email forwarding, Pivra processes the forwarding address, sender and recipient addresses, selected email headers, subject, message body, authentication and spam/virus verdicts, thread identifiers, delivery events and support-agent replies. Amazon SES and the customer's own email provider process the message in transit.
Pivra stores the original bounded plain-text body for audit and a trimmed working copy for the Helpdesk timeline. Attachments are rejected in the current release. Verified sender authentication may be used to associate messages with an existing contact; an unauthenticated From address is not treated as a verified identity.
The customer is responsible for lawfully configuring mailbox forwarding, informing correspondents, controlling who can access the original mailbox, and removing forwarding when the channel is disabled. Message and delivery records are retained with the workspace's support history and may be retained longer where required for security, complaint, bounce, dispute or legal evidence.
7B. Facebook Messenger Channel
When a customer connects a Facebook Page, Pivra receives Page-scoped Messenger events from Meta and processes message text, postback choices, delivery identifiers, event timestamps, encrypted Page access credentials, encrypted Page-scoped sender identifiers, conversation history, and authorised team replies. Meta also processes these communications under the customer's Meta account and Meta's terms.
Pivra stores only the bounded text and operational metadata needed to route, secure, audit, and support the conversation. Page access tokens and sender identifiers are encrypted at rest and are not displayed in the dashboard or intentionally disclosed to the AI model. Unsupported attachments are not processed as conversation content in the current release.
The customer is responsible for administering its Facebook Page, obtaining any required notices or consent, maintaining Meta permissions, responding to data-rights requests, and disconnecting the channel when no longer required. Disconnecting erases Pivra's stored Page access token, while support and security history may remain under the workspace retention settings and applicable legal obligations.
7C. Instagram Direct Channel
When a customer connects a Professional Instagram Business or Creator account, Pivra receives account-scoped Direct events from Meta and processes bounded message text, quick replies, postback choices, event timestamps, encrypted access credentials, encrypted Instagram-scoped sender identifiers, conversation history, and authorised team replies. Meta also processes these communications under the customer's Meta account and Meta's terms.
Access tokens and visitor identifiers are encrypted at rest, are not displayed in the dashboard, and are not intentionally disclosed to the AI model. Unsupported attachments, comments, reactions, publishing events, and other unsupported event classes are recorded only as bounded operational events or ignored and are not used as model input.
The customer is responsible for account administration, notices and consent, Meta permissions, data-rights requests, and disconnecting the channel when no longer required. Disconnecting erases Pivra's stored access token, while support and security history may remain under workspace retention settings and applicable legal obligations.
7D. Slack Conversation Channel
When a customer connects a Slack workspace, Pivra receives supported direct-message and explicit mention events and processes bounded message text, event timestamps, encrypted bot and refresh credentials, encrypted channel, thread, and Slack member identifiers, conversation history, and authorised team replies. Slack also processes these communications under the customer's Slack account and Slack's terms.
Credentials and provider identifiers are encrypted at rest, are not displayed in the dashboard, and are not intentionally disclosed to the AI model. Unsupported files, canvases, arbitrary history, group direct messages, and other unsupported event classes are ignored and are not used as model input.
The customer is responsible for workspace administration, notices and consent, Slack permissions, data-rights requests, and disconnecting the channel when no longer required. Disconnecting erases stored Slack tokens, while support and security history may remain under workspace retention settings and applicable legal obligations.
8. Your Rights
Subject to law, you may request:
- Access to personal information
- Correction of inaccurate information
- Deletion of your account and data
Requests can be made via support@pivra.ai .
9. Cookies
We use essential cookies for authentication and security. Optional analytics or advertising storage remains denied until the visitor grants the relevant consent through our consent controls.
You may change optional consent choices or disable cookies through your browser settings, although blocking essential storage may affect sign-in and Service functionality.
10. Children's Privacy
The Service is not intended for individuals under 18 years of age.
11. Limitation of Liability
To the extent permitted by law, we are not liable for unauthorised access, third-party breaches, or events beyond our reasonable control. Liability is limited as described in the Terms of Service.
12. Changes to this Policy
We may update this Privacy Policy periodically. Material changes will be notified via email or in-app notice.
13. Contact
Privacy Officer — Bluebird Technologies Pty Ltd — support@pivra.ai