Privacy Policy
Last updated 9 October 2026
Sills is a shared inbox for small businesses. It brings conversations from Facebook Messenger, Instagram, WhatsApp and email into one place so a business and its team can answer customers without switching between apps.
This policy explains what personal data we handle, why, who we share it with, and how you can ask us to delete it. It applies to sills.ai and to the Sills application.
1. Who we are
Sills is operated by Devel Codes LLC, based in Texas, USA. Devel Codes LLC is the data controller for the purposes of this policy. For questions about this policy or about your data, contact developer@sills.ai, which is monitored.
Sills is in development and not yet generally available. Access is by invitation. This policy applies from the moment you create an account or a business you message connects a channel to Sills.
2. Two kinds of data, two different roles
This distinction matters, because our obligations differ depending on whose data it is.
| Whose data | Our role | What it means |
|---|---|---|
| Business users — the people who sign up for a Sills account | Controller | We decide how this data is used, and this policy governs it. |
| End customers — people who message a business through a connected channel | Processor | We handle this data on the business's instructions, on their behalf. That business is the controller and its own privacy policy applies. |
3. Data we collect
From business users
- Account details: name, email address, password (stored hashed), profile photo.
- Team and workspace information, including which inboxes each member can access.
- Credentials for the channels you connect, so we can send and receive messages on your behalf: the access tokens Meta issues when you authorise WhatsApp, Instagram or Messenger, and the IMAP and SMTP details you enter for an email inbox. These are stored encrypted.
- Technical logs: IP address, browser type and timestamps, used for security and troubleshooting.
From connected channels
When a business connects a channel, we receive the content needed to show that conversation in the inbox:
- Message content, attachments, and timestamps.
- The sender's public profile information as provided by the platform — typically name, username and profile picture.
- A platform-specific identifier used to thread replies back to the right person.
For Meta channels we receive only the messages sent to the connected Page, Instagram account or WhatsApp number, not your private messages with anyone else. For email we read mail delivered to the connected mailbox and nothing else in that account.
4. How we use data
- To deliver the core service: receiving, displaying, routing and sending messages.
- To authenticate users and keep accounts secure.
- To provide support when a business asks for help.
- To monitor reliability, diagnose faults and prevent abuse.
- To meet legal obligations.
We do not sell personal data. We do not use the content of customer conversations for advertising, and we do not use it to train machine learning models.
AI features. Sills does not currently use any artificial intelligence or automated decision-making on your data or on customer conversations. We plan to add optional AI assistance, such as suggested replies and conversation summaries. Before any conversation content is sent to an AI provider, we will update this policy to name the provider and explain what is shared, and the feature will be off until a business turns it on.
5. Legal bases
Where the GDPR applies, we rely on: contract, to provide the service a business has signed up for; legitimate interests, for security, abuse prevention and service improvement; consent, where you have given it, such as when authorising a channel connection; and legal obligation, where the law requires us to retain or disclose information.
6. Who we share data with
We share data only with providers that help us run the service:
- Meta Platforms — to send and receive messages on Messenger, Instagram and WhatsApp. Our use of this data follows the Meta Platform Terms and Developer Policies.
- Your email provider — where a business connects a mailbox, Sills reads and sends mail through that provider's IMAP and SMTP servers. The provider, for example Google or Microsoft, continues to hold the mailbox itself.
- Infrastructure and hosting providers — to store data and run the application.
We may also disclose data if required by law, or to protect the rights and safety of our users or the public.
7. International transfers
Data may be processed in countries other than your own. Where data leaves the European Economic Area, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.
8. How long we keep data
Conversation data is retained for as long as the business keeps its account open, because it is the record of their customer relationships. When a business asks us to close its account, we delete the account and its data from our live systems within 30 days of verifying the request, except where we are legally required to keep it longer. Copies may remain in backups for a limited period after that before they expire.
9. How to delete your data
You can ask us to delete your data at any time, and we will act on it without charge.
- Business users: there is no self-service delete button yet. Email developer@sills.ai from the address on the account and we will delete the account and all of its conversations, contacts and attachments.
- If you messaged a business using Sills: that business controls the conversation, so contact them first. You can also email developer@sills.ai and we will forward your request to them and help them action it.
- To disconnect Meta data: remove the Sills app from your Instagram or Facebook settings under Apps and websites. This revokes our access immediately. To also have data already received deleted, email us.
We confirm completion by email, normally within 30 days of verifying your identity.
10. Your rights
Depending on where you live, you may have the right to access a copy of your data, correct it, delete it, restrict or object to processing, receive it in a portable format, and withdraw consent. To exercise any of these, email developer@sills.ai. You also have the right to complain to your local data protection authority.
11. Security
Traffic is encrypted in transit with TLS. Channel access tokens and mailbox credentials are encrypted at rest; passwords for Sills accounts are stored hashed, never in plain text. Message content and attachments are stored on access-controlled infrastructure, and access to production data is limited to staff who need it. No system is perfectly secure, but if a breach affects your personal data we will notify you and the relevant regulator as required by law.
12. Children
Sills is a business tool and is not directed at children under 16. We do not knowingly collect their data. If you believe a child has provided us personal data, contact us and we will delete it.
13. Cookies
The Sills application uses strictly necessary cookies to keep you signed in and to secure forms. This marketing site sets no advertising or analytics cookies.
14. Changes
If we make a material change we will update the date at the top of this page and, where the change significantly affects you, notify account holders by email.
15. Contact
Sills — operated by Devel Codes LLC
Texas, USA
developer@sills.ai