Lahja | لهجة
FeaturesPricingHow it worksFAQContact
Sign inCreate workspace

Privacy policy

Last updated 4 August 2026

Lahja is a customer-service inbox. Businesses use it to read and answer messages from their own customers. This policy explains what we hold, why we hold it, and how to get rid of it.

Who we are

Lahja (“we”, “the service”) is operated from lahja.online. For any privacy question, write to info@lahja.online or use our contact form.

Two kinds of people in this policy

  • Our customers — the businesses and their agents who hold Lahja accounts.
  • Their customers — people who message those businesses on Instagram, Messenger or WhatsApp. We process those messages on behalf of the business, which decides why and for how long. If you are one of these people and want your data removed, contact the business you messaged; you can also contact us and we will pass the request on.

What we collect

DataWhy
Name, email, hashed passwordTo create and secure an account. Passwords are hashed with bcrypt and never stored in readable form.
Workspace settings and brand accent rulesTo shape how replies are written.
Customer messages and repliesTo show the conversation in the inbox and to produce the accent version of a reply.
Contact name and platform ID of the person messagingTo thread messages into one conversation and to deliver replies back.
Channel access tokensTo receive and send messages on the connected account. Stored server-side and never returned to a browser.
AI usage records — token counts, model, latency, costTo meter usage and bill accurately. These records contain no message text.
Audit log of actions taken in the workspaceAccountability: who sent, edited, assigned or changed what.
Email delivery recordsTo show whether an invitation or notification actually arrived.

What we do not do

  • We do not sell personal data, and we do not share it for advertising.
  • We do not use your customers’ messages to train AI models.
  • We do not send any message to a customer without an agent pressing send.
  • We do not read one workspace’s data from another. Every query is scoped to a single workspace.

Who processes data for us

ProcessorWhat it handles
Anthropic (Claude API)The text of a reply being transformed, and inbound message text when accent detection or translation is enabled. Sent over TLS for processing and not used for model training.
ResendTransactional email — invitations, password resets, notifications. Recipient address and message body.
Meta PlatformsInstagram, Messenger and WhatsApp message delivery, for the accounts a workspace connects.
Contabo GmbHInfrastructure. Hosts the application and the PostgreSQL database in which conversations, contacts and messages are stored. Servers are in France; Contabo administers them from Germany.
PolarSubscription billing — the account email, plan and payment status of the workspace owner. Customer conversations are never sent to Polar.

Where data is stored

On our own server infrastructure in France, in a PostgreSQL database, reachable only over encrypted connections. Access tokens and password hashes are never exposed through the API.

How long we keep it

  • Conversations, messages and audit entries: for as long as the workspace exists.
  • Password reset links: 45 minutes, and they are single-use.
  • Invitations: 7 days.
  • Usage and cost records: retained for billing history.
  • When a workspace is deleted, everything belonging to it — conversations, contacts, messages, tags, usage records — is removed with it.

Your rights

You can ask for a copy of your data, correction of anything wrong, or deletion. See Delete your data for how, or write to info@lahja.online. We answer within 30 days.

Security

Sessions use signed, HTTP-only cookies. Passwords are bcrypt-hashed. Invitation and reset tokens are stored only as SHA-256 hashes, so a database copy cannot be replayed into account access. Incoming platform webhooks are verified against a signing secret and rejected if they do not match. No system is perfectly secure, but we would rather tell you what we actually do than claim more.

Changes

If this policy changes materially, we will update the date above and notify workspace owners by email.

Lahja | لهجة

Reply in your customer’s accent.

Product

FeaturesPricingHow it worksFAQCreate a workspace

Legal

Privacy policyTerms of serviceDelete your data

Contact

Contact usinfo@lahja.online
© 2026 Lahja. All rights reserved.