Built on restraint.
Trustworthy first, clever second. Your channels, your customers, and your voice are yours — we hold them carefully and hand them back the moment you ask. Here is the real posture, no badges we don't have.
A short list we actually keep
Every claim on this page maps to how the product is built — not to a brochure. Here is what that looks like.
Tokens encrypted at rest
The OAuth tokens that connect your channels are encrypted with AES-256-GCM before they touch the database. The encryption key lives in Google Secret Manager, never in the code or the data.
Never trained on your data
We don't fine-tune models on your content. Your voice, replies, and knowledge base ground your agent — and only your agent. Nothing you feed it trains a shared or base model.
Per-customer by design
What the agent learns from your edits and corrections is stored against your account alone. It shapes your AI and no one else's — never another customer's behavior, never the platform default.
Human-in-the-loop
Approval mode is one click. The agent drafts, queues, and waits for your thumbs-up. Silence rules mute it on the topics, hours, or contacts you name — so the sensitive stuff always routes to you.
Billed only on success
Usage is logged after an action completes, not when it's attempted. If a platform API errors out, the retry is on us — you're never charged for something that didn't ship.
Erased on request
Delete your account and we purge it — every brand under it, its content, and its encrypted tokens — and revoke the channel permissions back at Meta and Google. Your data leaves when you do.
One cloud, one region, one IAM model
BABAV runs on Google Cloud — Cloud Run services in the us-west1 region, with Firestore as the datastore. Keeping the whole stack in one place next to the models we call means less surface and one access model to reason about.
- Encrypted in transit and at rest. Traffic runs over TLS; data at rest is encrypted with AES-256-GCM, Google Cloud's default.
- Secrets in Google Secret Manager. API keys and signing keys live there — never checked into code, never printed in logs.
- Channel tokens get a second layer. Your OAuth tokens are AES-256-GCM encrypted in Firestore and decrypted only in memory, at the moment of a channel call.
- Stateless containers. Cloud Run rebuilds on every deploy, and Firestore access is IAM-enforced per collection.
Where it lives, how long it stays
We keep what we need to operate the platform — nothing speculative, nothing for ad targeting (we don't run ads). Nothing here outlives your decision to keep it.
Tokens are decrypted only in memory at the moment of a channel call — never logged, never shown in plaintext.
No passwords to phish
Your dashboard uses passwordless magic links — no passwords, no third-party auth provider. There's no password to reuse, reset, or breach.
- Single-use, short-lived links. Each magic link works once and expires quickly.
- HMAC-signed sessions. Your session is a short-lived, signed token — no password database sits behind it.
- Sign out clears it. Signing out wipes the session immediately.
You stay in charge of every connection
Connecting a channel — Threads, Instagram, Facebook, WhatsApp, YouTube, Gmail, TikTok, X, Telegram, Discord, LinkedIn, or Twitch — works the same way every time, and you can walk it back whenever you want.
- One-click OAuth, minimum scopes. You authorize BABAV directly with each network — no passwords change hands, and we request only the scopes the features you turn on actually need.
- Revoke anytime. Disconnect from inside BABAV or from the network's own settings, and the stored tokens are wiped and revoked at Meta or Google.
- Approve before it sends. Turn on approval mode and the agent drafts and waits; silence rules keep it off the topics, hours, and contacts you name.
- Delete on request. Deleting your account purges every brand, its content, and its tokens — and, on Done-for-you, an operator only ever works inside your dashboard, visible to you, removable anytime.
Sub-processors, in full
These are the services BABAV relies on to run. Each sees only what its job requires.
Tell us, and we'll act on it
Found a security issue? Email support@babav.co with the details and we'll look into it and work with you on a fix. If an incident ever affects your data, we notify you directly — from a real person, not a noreply — and if channel tokens are involved we revoke them and force re-authentication.
On compliance: you can request a copy of your data, delete your account, and opt out — all available today. SOC 2 is on our roadmap — we are not yet certified, and we won't claim otherwise. If you have a specific security requirement, email us and we'll have an honest conversation about what we can sign and what we can't.
Careful with your data. Serious about your work.
Seven-day free trial. The first $25/mo of usage is included, then a hard cap you set. Cancel anytime.