Privacy policy
Last updated 4 August 2026
Lahja is a customer-service inbox. Businesses use it to read and answer messages from their own customers. This policy explains what we hold, why we hold it, and how to get rid of it.
Who we are
Lahja (“we”, “the service”) is operated from lahja.online. For any privacy question, write to info@lahja.online or use our contact form.
Two kinds of people in this policy
- Our customers — the businesses and their agents who hold Lahja accounts.
- Their customers — people who message those businesses on Instagram, Messenger or WhatsApp. We process those messages on behalf of the business, which decides why and for how long. If you are one of these people and want your data removed, contact the business you messaged; you can also contact us and we will pass the request on.
What we collect
| Data | Why |
|---|---|
| Name, email, hashed password | To create and secure an account. Passwords are hashed with bcrypt and never stored in readable form. |
| Workspace settings and brand accent rules | To shape how replies are written. |
| Customer messages and replies | To show the conversation in the inbox and to produce the accent version of a reply. |
| Contact name and platform ID of the person messaging | To thread messages into one conversation and to deliver replies back. |
| Channel access tokens | To receive and send messages on the connected account. Stored server-side and never returned to a browser. |
| AI usage records — token counts, model, latency, cost | To meter usage and bill accurately. These records contain no message text. |
| Audit log of actions taken in the workspace | Accountability: who sent, edited, assigned or changed what. |
| Email delivery records | To show whether an invitation or notification actually arrived. |
What we do not do
- We do not sell personal data, and we do not share it for advertising.
- We do not use your customers’ messages to train AI models.
- We do not send any message to a customer without an agent pressing send.
- We do not read one workspace’s data from another. Every query is scoped to a single workspace.
Who processes data for us
| Processor | What it handles |
|---|---|
| Anthropic (Claude API) | The text of a reply being transformed, and inbound message text when accent detection or translation is enabled. Sent over TLS for processing and not used for model training. |
| Resend | Transactional email — invitations, password resets, notifications. Recipient address and message body. |
| Meta Platforms | Instagram, Messenger and WhatsApp message delivery, for the accounts a workspace connects. |
| Contabo GmbH | Infrastructure. Hosts the application and the PostgreSQL database in which conversations, contacts and messages are stored. Servers are in France; Contabo administers them from Germany. |
| Polar | Subscription billing — the account email, plan and payment status of the workspace owner. Customer conversations are never sent to Polar. |
Where data is stored
On our own server infrastructure in France, in a PostgreSQL database, reachable only over encrypted connections. Access tokens and password hashes are never exposed through the API.
How long we keep it
- Conversations, messages and audit entries: for as long as the workspace exists.
- Password reset links: 45 minutes, and they are single-use.
- Invitations: 7 days.
- Usage and cost records: retained for billing history.
- When a workspace is deleted, everything belonging to it — conversations, contacts, messages, tags, usage records — is removed with it.
Your rights
You can ask for a copy of your data, correction of anything wrong, or deletion. See Delete your data for how, or write to info@lahja.online. We answer within 30 days.
Security
Sessions use signed, HTTP-only cookies. Passwords are bcrypt-hashed. Invitation and reset tokens are stored only as SHA-256 hashes, so a database copy cannot be replayed into account access. Incoming platform webhooks are verified against a signing secret and rejected if they do not match. No system is perfectly secure, but we would rather tell you what we actually do than claim more.
Changes
If this policy changes materially, we will update the date above and notify workspace owners by email.
