Skip to legal content

Privacy and trust

Privacy Policy

How StrataDesk AI collects, uses, protects, and shares information.

StrataDesk AIEffective Date: July 19, 2026 - Version 1.1
On this page

This Privacy Policy explains how Bscale Laboratories, Incorporated, doing business as Bscale Labs ("Bscale Labs," "we," "us," or "our") collects, uses, stores, protects, and discloses information in connection with StrataDesk AI, including the StrataDesk AI operator dashboard, AI agent runtime, public chat pages, booking pages, payment pages, order pages, APIs, support services, and related websites or documentation (collectively, the "Service").

StrataDesk AI is built for business operations such as customer messaging, AI-assisted support, knowledge base management, booking and reservation workflows, product order workflows, manual payment-proof collection, contact management, task management, and operational reporting. It is not a bank, payment processor, escrow service, marketplace, licensed professional service provider, medical provider, law firm, financial adviser, or tax advisory service.

This Privacy Policy should be read together with the StrataDesk AI Terms of Service, the StrataDesk AI Data Deletion page, any separate order form, service agreement, statement of work, data processing agreement, or written contract between Bscale Labs and the customer organization, and the Bscale Labs Sub-processors page.

This Privacy Policy covers StrataDesk AI as a product and service. The bscalelabs.com marketing website where this policy may be published has its own site Privacy Policy.

This policy is written for three groups:

  • Operators: businesses and their team members who create or manage a StrataDesk AI workspace.
  • End-customers: people who message, comment on, book with, buy from, or otherwise interact with an operator through StrataDesk AI-powered channels or public pages.
  • Visitors: people who visit public StrataDesk AI pages, including login, booking, payment, order, data deletion, or support pages.

This policy is not a substitute for an operator's own privacy notice. Operators remain responsible for telling their own customers how the operator collects and uses customer data.

1. Our role

For operator account, billing, security, and service administration data, Bscale Labs acts as the personal information controller under the Philippine Data Privacy Act of 2012 and similar controller concepts under other privacy laws.

For customer conversations, booking records, order records, payment-proof uploads, contact records, and business content that an operator processes through its workspace, Bscale Labs generally acts as a personal information processor or service provider on behalf of the operator. The operator decides what data to collect from its customers, which channels to connect, what knowledge to upload, and how human teams or AI agents respond.

2. Data we collect from operators

We collect the following information from operators and workspace team members:

  • Account identity: name, email address, profile image if provided by the login provider, email verification status, authentication provider IDs, session records, IP address, user agent, and login metadata.
  • Workspace information: workspace name, slug, owner email, logo, timezone, locale, plan, members, roles, invitations, branches, services, teams, and permission settings.
  • Channel configuration: connected Facebook Page and Instagram Business account metadata, Page IDs, Instagram account IDs, handles, profile pictures, app-scoped Meta user IDs, webhook subscription status, health status, encrypted channel credentials and access tokens, and legacy Twilio configuration where enabled.
  • Agent configuration: agent names, descriptions, system prompts, prompt versions, automation rules, channel bindings, booking bindings, test chats, and AI task proposals.
  • Knowledge base content: folders, pages, drafts, published content, uploaded files, extracted text, structured text, conflict records, embeddings, and vector-search metadata.
  • Booking and catalog setup: booking links, event types, room and reservation inventory, products, variants, options, add-ons, discount codes, custom booking questions, availability rules, and policy acknowledgments.
  • Payment setup: bank account names, bank names, account numbers, QR images, payment settings, payment verification policies, and audit records for payment-related actions.
  • Product and order administration: product catalogs, fulfillment actions, order workflows, fulfillment events, and operator notes.
  • Usage, diagnostics, and security records: audit logs, service logs, error reports, feature usage, rate-limit records, support messages, and records needed to investigate abuse, bugs, or security incidents.

3. Data we collect about end-customers

Depending on what the operator has enabled, we may process the following end-customer data:

  • Conversation data: inbound and outbound messages, comments, replies, attachments, media URLs, sender labels, delivery status, reactions, timestamps, unread state, AI-generated summaries, tags, and conversation status.
  • Platform metadata: platform user IDs, display names, profile picture URLs, channel type, external message IDs, Page or account identifiers, and webhook event metadata supplied by Meta, Twilio, or another enabled channel provider.
  • Contact data: name, email address, phone number, platform identity, notes, tags, branch associations, contact events, and metadata created from repeated interactions.
  • Booking data: booker name, email, phone number, guest count, selected event, room or resource, dates and times, timezone, special requests, custom field responses, add-ons, discount codes, status, cancellation reason, and self-service management-token activity.
  • Order data: buyer name, email, phone number, locale, order number, product and variant selections, quantity, order status, payment status, fulfillment events, and self-service management-token activity.
  • Payment data for manual bank-transfer flows: payment amount, currency, method, reference number, payment proof or slip image, verification or rejection status, rejection reason, refund state, and a bank-account snapshot shown for the relevant transaction.
  • AI interaction data: prompts sent to an AI agent, tool calls or proposed actions, retrieved knowledge snippets, generated replies, token counts, compacted conversation summaries, and classification outputs used to route or escalate a conversation.

Operators can configure custom fields. If an operator asks for sensitive personal information through custom fields or messages, we process that data according to the operator's instructions and this policy.

4. Data from connected Meta assets

When an operator connects Facebook Messenger, Instagram Direct, Facebook Page comments, Instagram comments, or related Meta features, StrataDesk AI may receive:

  • Page and Instagram account metadata, including Page ID, Page name, Page picture, Instagram business account ID, username, and profile picture.
  • The operator's app-scoped Meta user ID for connection and deletion-management purposes.
  • Page access tokens and related credentials, encrypted at rest.
  • Direct message content, attachments, sender IDs, timestamps, read or delivery metadata, and outbound replies.
  • Comment content, commenter metadata, post IDs, post context, mentions, and replies.
  • Webhook events, referrals, postbacks, and subscription health data.

We use Meta data only to provide the operator's connected channel features, comply with Meta platform rules, maintain security, and honor valid deletion requests. We do not sell Meta platform data or use it for advertising.

5. Cookies and similar technologies

StrataDesk AI uses cookies and similar local storage for authentication, session security, workspace routing, and basic preferences. We do not use StrataDesk AI product pages to run third-party advertising cookies. Operators may separately use their own websites or Meta pages, which are governed by their own cookie and privacy practices.

6. Why we use data

We use personal data to:

  • Provide the StrataDesk AI service, including operator workspaces, login, team management, permissions, dashboards, and public booking, payment, order, and chat pages.
  • Route messages, comments, replies, attachments, and channel events between end-customers and operators.
  • Generate, format, and deliver AI-assisted responses grounded in an operator's knowledge base and configured workflows.
  • Create and manage bookings, reservations, product orders, payment proof uploads, fulfillment tasks, reminders, confirmations, cancellations, reschedules, and refunds.
  • Search and retrieve knowledge base content using embeddings and vector search.
  • Provide analytics, inbox views, contact timelines, notifications, tasks, audit logs, and operational reports.
  • Send transactional emails, such as magic links, invitations, booking confirmations, reminders, payment notices, receipts, and alerts.
  • Detect, prevent, and investigate spam, abuse, fraud, unauthorized access, service misuse, bugs, and security incidents.
  • Support operators and respond to privacy, deletion, legal, and compliance requests.
  • Meet legal, tax, accounting, platform, and regulatory obligations.

We do not sell personal data. We do not share personal data with advertisers. We do not use end-customer conversations or operator workspace content to train Bscale Labs-owned general-purpose AI models.

7. AI and third-party model providers

StrataDesk AI uses third-party AI and embedding providers to run agent replies, message formatting, knowledge retrieval, content structuring, conflict detection, and internal assistant features. Depending on the feature, relevant message content, knowledge base content, booking or order context, and tool results may be sent to those providers.

Optional AI features may send conversation content and relevant context to OpenRouter, which may route requests to approved model infrastructure providers. Relevant context may include selected knowledge snippets, configured instructions, and tool results needed to produce or evaluate a response.

StrataDesk AI restricts OpenRouter routing to endpoints reviewed by Bscale Labs and requires zero-data-retention handling for model inputs and outputs. Zero-data-retention controls apply to prompt and response content at eligible model endpoints; they do not mean that every operational record is deleted. OpenRouter may still retain limited metadata, such as timestamps, model and provider selection, token counts, cost, latency, and account or API-key attribution, for activity records, billing, reliability, security, and abuse prevention.

Our maintained sub-processor list identifies the AI, hosting, storage, email, messaging, monitoring, and logging providers currently used by Bscale Labs. We configure vendors and product settings to minimize retention where available. Operators must follow the sensitive-data restrictions in Section 15 when using AI features.

8. How we share information

We do not sell personal information.

We may share information in the following limited circumstances:

  • With the operator and its authorized users.
  • With service providers and sub-processors that help us host, operate, secure, back up, maintain, or support StrataDesk AI.
  • With professional advisers, such as lawyers, accountants, auditors, insurers, or security consultants, where reasonably necessary.
  • With government authorities, courts, regulators, or law enforcement when required by law or valid legal process.
  • In connection with a business transfer, merger, acquisition, financing, restructuring, or sale of assets, subject to appropriate confidentiality protections.
  • To protect the rights, property, safety, security, and integrity of Bscale Labs, StrataDesk AI, operators, users, end-customers, or others.

9. Service providers and sub-processors

The Service uses infrastructure and service providers for AI inference, hosting, databases, cache services, object storage, email delivery, messaging APIs, monitoring, logging, security, and similar operations.

The current maintained sub-processor list is available at bscalelabs.com/subprocessors. As of the current list, providers may include:

ProviderPurposeTypical location
AnthropicAI inferenceUnited States
OpenAIAI inferenceUnited States
OpenRouterAI request routing and inference gatewayUnited States / international; routed model processing location varies
Meta PlatformsMessenger and Instagram APIsUnited States / EU
ResendTransactional email deliveryUnited States
RailwayApplication hosting, Postgres, and RedisUnited States
Tigris DataFile and attachment storage via RailwayUnited States
SentryError monitoring, opt-inUnited States
AxiomLog aggregation, opt-inUnited States

If we add, replace, or remove a sub-processor, we will update the sub-processor page. Customers under a written agreement that requires advance notice will be notified according to that agreement.

Sub-processors may process information in the Philippines or other countries. For OpenRouter-routed requests, the processing location may vary among the approved model infrastructure providers available for the selected feature. We do not promise fixed data residency unless a written agreement expressly provides it. Where required, we use available contractual, technical, and organizational safeguards for cross-border processing.

10. Security

We use reasonable administrative, technical, and organizational safeguards, including:

  • TLS for data in transit.
  • Encryption at rest for channel credentials and access tokens.
  • Role-based workspace access controls.
  • Tenant isolation checks across workspace-scoped data.
  • Rate limits for public chat, booking, payment proof, order, OAuth, and webhook surfaces.
  • Audit logs for sensitive workspace actions.
  • Limited staff access to production systems.
  • Error-reporting settings that avoid sending default personal data and strip sensitive headers.
  • Operational procedures for deleting S3 objects, vector collections, and database records during workspace hard-delete and Meta data-deletion flows.

Some operator-entered payment instruction data, such as bank account details used to display manual transfer instructions, must be stored so StrataDesk AI can show it to authorized operators and customers. Access to those fields is restricted and audited, but operators should avoid adding bank accounts they are not authorized to use.

No system is perfectly secure. If we become aware of a personal data breach requiring notice, we will notify affected parties and the National Privacy Commission of the Philippines within the timeframes required by law, generally within 72 hours after knowledge of or reasonable belief that a notifiable breach occurred.

11. Retention

We keep data only as long as needed for the purposes described above, unless a longer period is required by law, security, tax, accounting, or dispute obligations.

Data typeRetention
Active workspace data, including agents, channels, conversations, contacts, knowledge bases, bookings, orders, products, and payment recordsKept while the workspace is active
Soft-deleted workspace resourcesRecoverable during the workspace's configured restore window, typically 30 days
Deleted or deactivated workspace dataHard-deleted or rendered unavailable from active systems after the recovery window, generally within 90 days
Meta data deletion callback recordsProcessed as soon as practical; active contact/media/channel records associated with the request are removed, deleted, or disconnected, generally within 30 days
End-customer deletion requests sent by emailCompleted within 30 days after verification, unless retention is legally required
Backups containing deleted dataRotated out generally within 90 days
Billing, tax, accounting, and invoicing recordsKept as required by Philippine tax and accounting law, currently expected to be at least 5 years
Security logs, audit logs, and abuse-prevention recordsUp to 2 years, unless a longer period is needed for security, legal, or dispute reasons
Records of privacy and deletion requestsUp to 2 years to demonstrate compliance

Operators may also export or retain copies of end-customer data outside StrataDesk AI. Those copies are governed by the operator's own policies and systems.

12. Deletion and control options

End-customers can request deletion in two ways:

  1. Remove StrataDesk AI from Facebook settings where Meta provides a Data Deletion Callback. We verify Meta's signed request, process the deletion job, and provide a status URL.
  2. Email privacy@bscalelabs.com with the channel used, the business contacted, and enough information for us or the operator to identify the relevant records.

Operators can deactivate or delete workspace resources from the product, and may request workspace hard-delete by emailing privacy@bscalelabs.com from an authorized admin address. Details are on the StrataDesk AI Data Deletion page.

13. Your rights

Under the Philippine Data Privacy Act of 2012 and other applicable privacy laws, you may have data subject rights to:

  • Be informed about how your personal data is processed.
  • Access personal data held about you.
  • Correct inaccurate or incomplete data.
  • Object to certain processing.
  • Request erasure, blocking, or deletion.
  • Request data portability.
  • Withdraw consent where processing is based on consent.
  • File a complaint with the National Privacy Commission or another applicable authority.
  • Seek damages where allowed by law.

To exercise rights, email privacy@bscalelabs.com. We may need to verify your identity and, for end-customer requests, coordinate with the relevant operator because the operator usually controls the customer relationship. We aim to confirm receipt within 7 days and respond within 30 days, unless law allows or requires a different timeline.

14. International processing

Bscale Labs and StrataDesk AI are based in the Philippines and currently serve Philippine operators and customers. Some sub-processors, including OpenRouter, operate outside the Philippines. Personal data may be transferred to and processed in the United States or other countries where an approved provider operates. The exact processing location can vary by feature and available infrastructure, and StrataDesk AI does not provide fixed residency unless a written agreement expressly says otherwise. Where required, we use available contractual, technical, and organizational safeguards and follow the operator's instructions for customer data.

Operators are responsible for ensuring that their own use of StrataDesk AI complies with privacy laws that apply to their customers, including any cross-border transfer, sector-specific, or consent requirements.

15. Sensitive data and regulated use cases

StrataDesk AI may be used by clinics, wellness providers, training businesses, resorts, service businesses, and merchants. Some of those businesses may handle sensitive personal information. Operators must configure StrataDesk AI so they collect only the information they are legally allowed to collect and have told customers they will collect.

Unless Bscale Labs has separately contracted for and reviewed the use case, operators must not submit or configure AI features to process:

  • Health or medical data.
  • Payment-card data or payment slips and payment-proof images.
  • Government-issued identification numbers or documents.
  • Biometric identifiers or biometric data.
  • Passwords, authentication tokens, API keys, private keys, or other credentials and secrets.
  • Children's data.
  • Other sensitive personal information or special-category data under applicable law.

These restrictions apply to prompts, conversation context, knowledge base content, attachments, custom fields, and tool results supplied to AI features. Payment-proof uploads collected through a non-AI workflow must not be included in AI prompts or context unless the use case has been separately contracted and reviewed.

StrataDesk AI is not designed to replace licensed professional judgment. Operators should not use AI agents to provide medical diagnosis, legal advice, financial advice, or other regulated decisions unless the operator has appropriate licenses, notices, safeguards, and human review.

16. Children

Operator accounts are not intended for people under 18. End-customers under 18 may interact with an operator using StrataDesk AI only where the operator has the authority, consent, and safeguards required by law. If you believe a child has submitted data to StrataDesk AI without proper authority, email privacy@bscalelabs.com.

17. Changes to this policy

We may update this policy as StrataDesk AI changes. Material changes will be announced by email to operators or through the product where practical. The effective date above shows when this version took effect.

18. Contact

Bscale Laboratories, Incorporated Doing business as Bscale Labs Philippines Website: https://bscalelabs.com General contact: hello@bscalelabs.com Privacy contact: privacy@bscalelabs.com

For privacy concerns, use the subject line "Privacy Request."