Bonik AI — Privacy Policy

Privacy Policy

Last Updated: October 5, 2026 Version: 6.2 Google Play Data Safety Compliant

This Privacy Policy describes how Bonik AI (a product of Sharif Express, published under the developer name AI1952) collects, uses, and protects your personal information when you use our application. By using Bonik AI, you agree to this policy.

Introduction

Sharif Express, which publishes its apps under the developer name AI1952 (referred to in this policy as "AI1952," "we," "our," "us," or "the Company"), develops and operates Bonik AI — an AI-powered business management application for F-Commerce sellers in Bangladesh, available on the Google Play Store. This Privacy Policy describes how we collect, use, store, share, and protect your personal information when you download, install, and use Bonik AI.

This policy explains our data practices clearly so you can make informed decisions about using the app. If Bonik AI introduces new features with unique data practices, those differences will be disclosed within the app and in the Data Safety form on Google Play.

This Privacy Policy is designed to comply with:

  • Google Play Developer Program Policies (updated April 2026)
  • Google Play Data Safety requirements
  • Google Play AI-Generated Content Policy
  • Google Play Account Deletion Policy
  • Bangladesh Digital Security Act 2018
  • General Data Protection Regulation (GDPR) — where applicable
  • California Consumer Privacy Act (CCPA) — where applicable

By downloading, installing, or using Bonik AI, you agree to the practices described in this policy. If you do not agree, please discontinue use and uninstall the application from your device.


1. Who We Are

Business: Sharif Express (developer name: AI1952)

Application: Bonik AI — F-Commerce AI Business Assistant

Website: bonikai.app

Contact: [email protected]

Business Type: Remote-First, Globally Distributed

Sharif Express is a Bangladesh-based business that builds AI-powered applications for Bangladeshi businesses and publishes them under the developer name AI1952. Bonik AI integrates leading AI technologies to help F-Commerce sellers manage orders, generate marketing content, dispatch couriers, track finances, and grow their business — all in one place.


2. Information We Collect

The data collected depends on which features of Bonik AI you use. We may collect the following categories of information:

2.1 Information You Provide Directly
  • Account details — name, email address, username, and password
  • Profile information — profile photo, business name, and preferences
  • Content you create — product descriptions, marketing posts, prompts, messages, and other text you submit within the app
  • Support communications — messages you send to our support team
  • Payment details — in-app purchases are processed by Google Play Billing, and purchases on bonikai.app by EPS (Easy Payment System). We never receive or store your card number, bKash/Nagad/Rocket PIN, or OTP (see Section 30)
  • Website checkout details — if you buy a plan on bonikai.app: your name, mobile number, email address, and the plan you chose (see Section 30)
2.2 Information Collected Automatically
  • Device identifiers — Android Advertising ID (AAID), device model, OS version, unique device ID
  • App usage data — features accessed, session duration, button interactions, screen views
  • Performance data — app startup time, loading speed, API response times (via Firebase Performance Monitoring)
  • Crash and error reports — stack traces, error logs, device state at the time of crash (via Firebase Crashlytics)
  • Analytics events — user flows, feature engagement, retention data (via Firebase Analytics)
  • Network data — IP address, approximate geographic region (country/city level), connection type
  • Language and timezone settings
2.3 Information from Third-Party Sign-In
  • If you sign in via Google Sign-In, we receive your name, email address, and Google profile photo through Google's OAuth 2.0 service
  • We do not receive or store your Google account password
2.4 Courier & WordPress Integration Data
  • If you connect a courier/delivery service (e.g., Pathao, Steadfast, RedX, or other supported couriers), we collect the API credentials, order details, and delivery status you authorize us to access — solely to create and track shipments on your behalf
  • If you connect a WordPress/WooCommerce store, we collect the store URL and API keys you provide, along with order, product, and customer data synced from your store — used only to display and manage that information inside the app
  • These credentials are encrypted at rest and never shared with unrelated third parties
  • You can disconnect any courier or store integration at any time from within the app, which immediately revokes access
2.5 Telegram Bot Integration Data
  • If you choose to connect the optional Bonik AI Telegram bot (@BonikAIBot), we collect your Telegram chat ID and the date you connected — this is the only new data the integration collects
  • We do not receive your Telegram phone number, contacts, or message history
  • Disconnecting the bot (from the app, or by sending /stop to the bot) deletes the stored chat ID and stops all Telegram messages
2.6 WhatsApp AI Bot Integration Data
  • If you choose to connect the optional Bonik AI WhatsApp bot to your WhatsApp Business number (through Meta's Embedded Signup with Facebook Login), we collect your WhatsApp Business phone number, its WhatsApp display name, the related Meta account IDs, and an access token that Meta issues so the bot can reply from your number — plus the date you connected
  • Messages your customers send to your WhatsApp Business number are received by the bot; the ones it answers are processed to generate a reply, including a short recent-conversation history kept per customer so follow-up questions make sense
  • When a customer places an order through the bot (name, phone number, delivery address), those details are saved as an order in your Bonik account — exactly like any other order
  • When you connect a number that is also used in the WhatsApp Business app, Meta's rules require us to start a sync of your contacts and recent chat history; we only count these sync events and do not store their contents
  • When you reply to a customer yourself from the WhatsApp Business app, we only note that you replied (so the bot steps back from that chat) — we do not store what you wrote
  • Disconnecting the bot (from the app, More → WhatsApp AI Bot → Disconnect) deletes the stored access token and stops all bot replies immediately
2.7 Messenger AI Bot Integration Data
  • If you choose to connect the optional Bonik AI Messenger bot to your Facebook Page (via Facebook Login), we collect your Page ID, Page name, and a Page access token that Meta issues so the bot can reply on your Page — plus the date you connected
  • Messages your Page's customers send to your Page are received by the bot and processed to generate a reply — including a short recent-conversation history kept per customer so follow-up questions make sense
  • When a customer places an order through the bot (name, phone number, delivery address), those details are saved as an order in your Bonik account — exactly like any other order
  • We do not receive your personal Facebook password, your friends list, or conversations from Pages you have not connected
  • Disconnecting the bot (from the app, More → Messenger AI Bot → Disconnect) deletes the stored Page token, unsubscribes the Page, and stops all bot activity immediately
2.8 On-Device Text Recognition (OCR)
  • Bonik AI includes an on-device OCR feature that reads text from images you choose to scan or upload (e.g., turning a screenshot into an order)
  • This OCR processing happens entirely on your device — the image itself is never collected, uploaded, or stored by Bonik AI or any third party
  • Only the resulting text — not the image — may then be sent to an AI model API (see Sections 6 & 10) to generate a response, exactly like any other text you type into the app
  • We do not retain a copy of the scanned image
2.9 Information We Do NOT Collect
  • Precise GPS or real-time location
  • Contacts, call logs, or SMS messages
  • Audio or video recordings without explicit user action
  • Files or photos unless you explicitly upload them within the app
  • Sensitive personal data such as health records, financial accounts, biometric data, or government ID data

3. How We Use Your Information

We use the information collected for the following purposes:

  • Deliver our Services: Provide core app functionality, AI-powered features, and personalized content
  • Account management: Create, authenticate, and maintain your account and preferences
  • AI processing: Route your prompts to third-party AI model APIs to generate responses, marketing posts, or other content
  • Analytics (Firebase Analytics): Understand how users engage with Bonik AI to improve features, UX, and retention
  • Crash reporting (Firebase Crashlytics): Automatically detect, diagnose, and fix crashes and errors to improve stability
  • Performance monitoring (Firebase Performance): Measure app loading times, network latency, and screen rendering to identify bottlenecks
  • Customer support: Respond to inquiries, troubleshoot problems, and provide assistance
  • Security and fraud prevention: Detect abuse, unauthorized access, or violations of our Terms of Service
  • Legal compliance: Meet obligations under applicable laws and regulations
  • Marketing communications: Send product updates, new feature announcements, and promotional offers — only with your consent, and you may opt out at any time
  • Subscription and billing: Manage your in-app purchases and subscriptions via Google Play Billing, and plans bought on bonikai.app via EPS — including activating the plan, issuing redeem codes, and sending receipts
  • Payment follow-up: If you start a payment on bonikai.app but do not complete it, we may send up to two reminder emails about that order (Section 30). Each has a one-click unsubscribe link

We do not use your data for fully automated decisions that produce significant legal effects without human review.



5. User-Generated Content (UGC)

Bonik AI allows you to create, save, and share content within the app — including product descriptions, marketing posts, hashtags, creative copy, and images ("User-Generated Content" or "UGC").

Your Responsibilities
  • You retain ownership of the original content you create
  • You are solely responsible for ensuring your UGC does not violate any laws, third-party rights, or our Terms of Service
  • You must not submit content that is illegal, defamatory, obscene, harassing, or infringes any intellectual property rights
Our Rights
  • By submitting UGC, you grant AI1952 a limited, non-exclusive, royalty-free license to use, store, display, and process that content solely to operate and improve the Services
  • We do not claim ownership of your content and do not sell it to third parties
  • We reserve the right to remove any UGC that violates our policies, without prior notice
Content Moderation
  • We may use automated tools and manual review to detect policy violations in user-submitted content
  • AI-generated outputs based on your prompts are treated as UGC and are subject to the same responsibilities

6. Website & Product Link Content Policy

Bonik AI's Website feature (including product links) allows you to create a public website and product pages (your "Website") that you share with customers via a link. This section explains the content restrictions that apply and how related data may be handled.

Bonik AI strictly prohibits the promotion, sale, or sharing of any online store, product, or link related to adult (18+) content, sexually explicit or obscene material, illegal drugs or narcotics, or any product or service that is prohibited under the laws of Bangladesh.

  • Adult (18+) content, sexually explicit, or obscene material
  • Illegal drugs or narcotics
  • Any other product or service prohibited under the laws of Bangladesh

If any such activity is detected, Bonik AI reserves the right to suspend or permanently terminate the associated account without prior notice.

Where required by applicable law or in response to a valid request from authorized government or law enforcement authorities in Bangladesh, Bonik AI may disclose relevant information — such as account details, Website content, or associated order data — as legally required.

By using Bonik AI's Product Link feature, you acknowledge and agree to comply with this policy. See also Terms of Service Section 9.


7. AI-Generated Content

Bonik AI uses large language model (LLM) APIs to generate content on your behalf. In compliance with the Google Play AI-Generated Content Policy, we disclose the following:

Disclosure of AI Use
  • Content generated by Bonik AI is powered by AI models, including services from OpenAI, Google, and/or Anthropic
  • AI-generated content is clearly labelled within the app wherever applicable
  • We do not misrepresent AI-generated content as being created by a human
Accuracy & Responsibility
  • AI-generated content is provided as a starting point and may not always be accurate, complete, or suitable for your specific context
  • You are responsible for reviewing, editing, and verifying all AI outputs before publishing or sharing them
  • AI1952 is not liable for decisions made based solely on AI-generated content
Prohibited AI Use
  • You may not use our AI features to generate content that is illegal, harmful, deceptive, discriminatory, or violates any third-party rights
  • Generating content that impersonates real people, spreads misinformation, or facilitates fraud is strictly prohibited

8. How We Share Information

We do not sell your personal information to any third party. We share data only in the following limited circumstances:

  • AI API Providers: Your prompts are transmitted to AI API providers to generate responses. These providers process data under their own privacy policies and terms.
  • Firebase (Google): Analytics events, crash reports (Crashlytics), and performance metrics are sent to Firebase. Data is anonymized and aggregated where possible.
  • Google Play Billing: In-app payment transactions are handled entirely by Google Play's billing system. We do not receive or store your payment credentials.
  • EPS (Easy Payment System): For purchases on bonikai.app, your name, mobile number, email address, the amount, and an order reference are sent to EPS, a Bangladesh Bank–licensed payment gateway, to process the payment. You then pay on EPS's own page through bKash, Nagad, Rocket, your bank, or your card network, each under its own terms. We receive only the payment result — never your card number, PIN, or OTP.
  • Email delivery: Receipts, redeem codes, and service emails are delivered through our web host's mail server and email delivery providers (Amazon Web Services' Simple Email Service and Zoho ZeptoMail), which process your email address only to deliver the message.
  • Cloud Infrastructure Providers: Our backend services are hosted on secure cloud servers (Google Cloud Platform) for data storage and API delivery.
  • Legal Authorities: We may disclose data if required by law, court order, or to protect the rights, property, or safety of AI1952, our users, or the public.
  • Business Transfers: In the event of a merger, acquisition, or asset sale, user data may be transferred. Affected users will be notified via email and in-app notice.
  • Courier & Delivery Partners: If you connect a courier service, order and shipment details you choose to send are shared with that courier's API solely to create and track deliveries on your behalf.
  • WordPress/WooCommerce Store: If you connect your own store, order, product, and customer data is exchanged directly between the app and your store's API using the credentials you provide — this data is not shared with any other third party.
  • Telegram (Telegram FZ-LLC): If you connect the optional Bonik AI Telegram bot, order details (including your customers' names, phone numbers, and delivery addresses), sales summaries, and subscription notices are transmitted to your Telegram account through Telegram's Bot API. Messages delivered through Telegram are handled under Telegram's own Privacy Policy. See Section 27 for full details.
  • WhatsApp (WhatsApp LLC / Meta Platforms, Inc.): If you connect the optional Bonik AI WhatsApp bot to your WhatsApp Business number, your customers' messages and the bot's replies (which may include product, price, and order details) are transmitted through Meta's WhatsApp Business Platform (Cloud API) and are handled under the WhatsApp Privacy Policy and Meta's Privacy Policy. Customer messages are also processed by Google's AI services to generate the bot's replies. See Section 28 for full details.
  • Facebook Messenger (Meta Platforms, Inc.): If you connect the optional Bonik AI Messenger bot to your Facebook Page, your Page customers' messages and the bot's replies (which may include product, price, and order details) are transmitted through Meta's Messenger Platform and are handled under Meta's Privacy Policy. Customer messages are also processed by Google's AI services to generate the bot's replies. See Section 29 for full details.

All third-party service providers are required to handle your data in compliance with applicable privacy laws and are prohibited from using it for their own independent purposes.


9. Data Storage & Security

Storage Location: User data is stored on secure cloud infrastructure (Google Cloud Platform) in GDPR-compliant regions.

Retention Period: We retain your personal data for as long as your account is active. Upon account deletion, personal data is deleted or irreversibly anonymized within 30 days, except where retention is required by law.

Security Measures
  • All data in transit is encrypted using HTTPS / TLS 1.2+
  • Data at rest is encrypted using AES-256 encryption
  • Access to user data is restricted to authorized personnel only, with role-based access controls
  • Passwords are stored using industry-standard one-way hashing (bcrypt)
  • Regular security audits and penetration testing are conducted
  • Crash and error logs (via Firebase Crashlytics) are reviewed to detect security anomalies

No system is 100% secure. If you suspect unauthorized access, please contact us immediately at [email protected].


10. Account Deletion Rights

In compliance with Google Play Account Deletion requirements, Bonik AI provides a clear, accessible mechanism for users to delete their account and associated data.

How to Delete Your Account
  • In-App: Navigate to Settings → Account → Delete Account and follow the on-screen confirmation steps
  • By Email: Send a deletion request to [email protected] with the subject line: "Account Deletion Request" from your registered email address
What Is Deleted
  • Your profile, preferences, saved content, and account history — deleted within 30 days
  • AI prompt history and generated content associated with your account
  • Your email address and personal identifiers
What May Be Retained
  • Anonymized, aggregated analytics data that cannot be linked to you
  • Transaction records required for legal, tax, or financial compliance (retained for the minimum period required by law)
  • Crash logs and error reports, stripped of personal identifiers

Account deletion is permanent and irreversible. Active subscriptions must be cancelled via Google Play before deletion to stop future billing.


11. AI Content & Your Prompts

This section specifically addresses how we handle the prompts and inputs you provide to AI features within Bonik AI, and how the resulting AI-generated content is managed.

How Your Prompts Are Used
  • Prompts you submit (e.g., product details, topic requests, instructions) are transmitted to third-party AI model APIs to generate a response
  • Your prompt data is sent securely over HTTPS and is not stored permanently on our servers beyond the duration of the session, unless you explicitly save content within the app
  • We do not use your prompts to train our own AI models
Third-Party AI Provider Data Use Prompt Safety & Filtering
  • Prompts are subject to safety filters enforced by both Bonik AI and the AI providers to prevent harmful, illegal, or policy-violating outputs
  • We may log flagged or blocked prompts for safety review and platform integrity — these logs are handled with strict access controls
  • You must not submit prompts designed to bypass AI safety systems, generate harmful content, or extract model weights or training data
Your Rights Over AI Content
  • You may delete AI-generated content saved within the app at any time from your account history or by deleting your account (see Section 9)
  • AI1952 does not claim ownership of AI-generated content produced from your prompts
  • You are responsible for how you use, publish, or share AI-generated content outside of the app

12. Analytics & Diagnostics

Bonik AI uses Firebase — Google's mobile development platform — for analytics, crash reporting, and performance monitoring:

Firebase Analytics
  • Anonymized usage events (screen views, feature taps, session data) are shared with Firebase Analytics to help us understand user behavior and improve the app experience
  • No personally identifiable information (PII) is sent in analytics events
  • You can opt out of analytics data collection via your device's Settings → Privacy → Ads → Opt out of Ads Personalization
Firebase Crashlytics
  • When the app crashes, Crashlytics automatically sends a crash report including: device model, OS version, app version, crash stack trace, and app state at the time of crash
  • Crash reports do not include personal content, prompts, or identifiable user data — we take care to avoid logging PII
Firebase Performance Monitoring
  • Performance traces — including screen load times, HTTP request durations, and custom performance metrics — are sent to Firebase Performance to identify and resolve performance bottlenecks
  • This data is aggregated and does not contain personal content

13. Detailed Data Storage

Additional detail on storage and security practices by data type:

  • Account data (name, email, password hash): Stored in a secured, access-controlled database. Password is hashed and salted — never stored in plain text
  • AI prompt history (if saved): Encrypted at rest in our database. Not shared with third parties beyond AI API providers for processing
  • Analytics and crash data: Stored in Firebase infrastructure managed by Google, subject to Google's security standards
  • Payment records: In-app purchases are managed by Google Play Billing. For bonikai.app purchases we keep an order record (name, mobile number, email, plan, amount, payment status, and EPS reference) for accounting, support, and refund handling. Bonik AI never stores payment card details, PINs, or OTPs
  • Uploaded media (photos, images): Stored temporarily during processing; not retained longer than necessary. Users may delete uploaded content at any time
  • Courier & store API credentials: Encrypted at rest using AES-256. Only used to communicate with the specific service you connected

Data Breach Response: In the event of a data breach that may affect your personal information, we will notify affected users and relevant authorities within 72 hours of becoming aware, as required under GDPR.


14. Account Deletion — Additional Details

Additional details about how deletion works in Bonik AI:

  • The in-app deletion flow is accessible from Settings and meets Google Play's account deletion requirements
  • Deleting your account also immediately disconnects all courier and store integrations you have set up
  • Any saved AI-generated content, order history, and financial records stored in the app will be permanently removed within 30 days
  • If you use Bonik AI in guest mode (if available), simply uninstalling the app removes locally stored data — no deletion request is needed
  • Refunds for Google Play subscriptions are governed by Google Play's refund policy; refunds for plans bought on bonikai.app are governed by our Refund Policy

For any issues with account deletion, contact us at [email protected] — we will respond within 5 business days.


15. Your Privacy Rights

Depending on your location, you may have the following rights regarding your personal data. To exercise any right, contact us at [email protected]:

  • Right to Access: Request a copy of the personal data we hold about you
  • Right to Correction: Request correction of inaccurate or incomplete data
  • Right to Deletion: Request permanent deletion of your account and personal data (see Sections 9 & 13)
  • Right to Portability: Request your data in a structured, machine-readable format (JSON/CSV)
  • Right to Object: Object to processing based on legitimate interests, including profiling
  • Right to Restrict Processing: Request restriction of processing under certain circumstances
  • Right to Withdraw Consent: Withdraw any previously given consent (e.g., marketing emails) without affecting prior processing
  • CCPA Rights (California): Right to know, right to delete, right to opt-out of sale of personal information (we do not sell data), and right to non-discrimination for exercising your rights

We will respond to all verified requests within 30 days. We may request identity verification before processing sensitive requests.


16. Children's Privacy

Bonik AI is not directed at children under 13 years of age (or under 16 in certain jurisdictions such as the EU). We do not knowingly collect personal information from children.

Bonik AI is designed for adults and business users engaged in e-commerce, content creation, and business operations. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at [email protected]. We will promptly investigate and delete such information upon verification.


17. Device Permissions

Bonik AI requests Android permissions only when necessary and only at the time the relevant feature is used. The following permissions may be requested:

  • INTERNET: Required — needed to connect to AI APIs, sync orders, and deliver app content
  • POST_NOTIFICATIONS: Optional (Android 13+) — used to send order alerts, AI completion notifications, and reminders
  • CAMERA: Optional — used only when you choose to capture product photos within the app
  • READ_MEDIA_IMAGES / READ_EXTERNAL_STORAGE: Optional — used only when you choose to upload images from your device gallery
  • BILLING: Required for in-app purchases — processes subscriptions and purchases via Google Play Billing
  • VIBRATE: Optional — used for haptic feedback on UI interactions, if enabled in app settings
  • RECEIVE_BOOT_COMPLETED: Optional — used for scheduled reminders or background sync, only if enabled by you

You can manage and revoke any permission at any time via Android Settings → Apps → Bonik AI → Permissions. Revoking optional permissions disables related features but does not affect core app functionality.


18. Advertising

Bonik AI does not display third-party advertisements inside the app. There are no banner ads, interstitial ads, or rewarded video ads on any plan.

  • No ad networks (such as Google AdMob) are integrated in current versions of the app
  • Older versions of Bonik AI displayed optional rewarded ads on the former free tier; this has been removed entirely — if you are on an old version, please update to the latest version
  • We do not share your name, email, or personal content with advertisers

Bonik AI does run its own app-install marketing campaigns on platforms such as Facebook — see Section 19 (Meta SDK) for how campaign measurement works.


19. Meta (Facebook) SDK & App Install Campaigns

Bonik AI may integrate the Meta (Facebook) SDK for Android to run app-install advertising campaigns and measure ad performance on Meta platforms (Facebook, Instagram, Audience Network).

What the Meta SDK Collects
  • App Events: Automatic events such as app install, app open/launch, and in-app purchase events are logged to help measure the effectiveness of Meta ad campaigns
  • Device & advertising identifiers: Android Advertising ID (AAID), device model, OS version, app version, and network/locale information
  • Install attribution data: Used to determine whether an app install resulted from a Meta ad campaign
Why We Use It
  • To run and measure app-install advertising campaigns on Facebook and Instagram
  • To understand which ad campaigns and creatives drive installs and in-app actions
  • To deliver more relevant ads to people who may be interested in Bonik AI
Data Sharing with Meta
  • Event and device data described above is shared with Meta Platforms, Inc., which processes it under its own Meta Privacy Policy and Meta Platform Terms
  • We do not send your name, email address, in-app prompts, or any AI-generated content to Meta — only the limited event and device signals described above
Your Choices
  • Limit ad tracking by disabling Android Settings → Privacy → Ads → Opt out of Ads Personalization
  • Manage how your Facebook/Instagram activity is used for ads at facebook.com/adpreferences
  • Uninstalling the app stops further App Events from being logged on that device

This integration is disclosed in Bonik AI's Google Play Data Safety form under "Device or other IDs" and "App activity" shared with third parties.


20. File Access & Sharing (FileProvider)

Bonik AI may generate files on your device — for example, invoices, receipts, or exported reports — that you may want to view, share, or download using other apps (e.g., a PDF viewer, messaging app, or email client).

  • We use Android's FileProvider to securely expose these app-generated files to other apps you choose, without giving those apps broad access to your device storage
  • Only files explicitly generated by Bonik AI (such as invoice PDFs or order exports) within a designated, restricted app folder are made accessible — never your personal photos, downloads, or unrelated files
  • Access is granted temporarily and only to the specific app you select via the Android share/open sheet; it is not exported or accessible to other apps in general
  • These files remain on your device and are not uploaded to our servers as part of this sharing mechanism

You can delete app-generated files at any time by clearing the app's cache/storage via Android Settings → Apps → Bonik AI → Storage.


21. International Transfers

We are based in Bangladesh, but some of the services we rely on operate globally. When you use Bonik AI, your data may be transferred to and processed in countries other than Bangladesh — including the United States, where our AI API providers and cloud infrastructure operate.

We ensure that all international data transfers are subject to appropriate safeguards, including:

  • Standard Contractual Clauses (SCCs) — used with EU/EEA data transfers in compliance with GDPR
  • Data Processing Agreements (DPAs) — in place with all third-party processors including Firebase and AI API providers
  • Adequacy decisions — where applicable for specific destination countries

By using Bonik AI, you acknowledge and consent to the international transfer of your data as described in this policy.


22. Third-Party Links

Bonik AI may contain links to third-party websites, products, or services — including links to Google Play Store listings, social media profiles, or partner websites. This Privacy Policy applies only to Bonik AI.

We are not responsible for the privacy practices, content, or security of any third-party websites or services you access via links within the app. We encourage you to read the privacy policy of any third-party service you visit.

Third-party SDKs and services used in Bonik AI include:


23. Policy Changes

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, products, legal requirements, or other factors.

How We Notify You
  • The "Last Updated" date at the top of this page will be revised
  • For material changes, we will display an in-app notification prompting you to review the updated policy before continuing to use the app
  • We will send an email notification to your registered email address for significant changes that materially affect your rights

Your continued use of Bonik AI after the effective date of the updated policy constitutes your acceptance of the revised terms. If you do not agree with the changes, you may stop using the app and delete your account as described in Section 9.

We recommend checking this page periodically. The current version is always available at bonikai.app/privacy.php.


24. Google Play Data Safety

Bonik AI has a completed Data Safety form on its Google Play Store listing, which provides a transparent summary of data collection and sharing practices. Below is a general overview:

Data Collected
  • Account info (name, email) — required, collected from user
  • App interactions (feature usage, session data) — required, collected automatically
  • Crash logs — required, collected automatically via Crashlytics
  • Diagnostics (performance data) — required, collected automatically via Firebase Performance
  • Device or other IDs (Advertising ID) — optional, collected for ad campaign measurement (if applicable)
  • App activity (install/open events) — optional, collected via Meta SDK for ad campaign measurement (if applicable)
Data Shared
  • App interactions and diagnostics shared with Firebase (Google) for analytics and crash reporting
  • User prompts shared with AI API providers for content generation — not sold
  • Device IDs and app events shared with Meta Platforms, Inc. for app-install campaign measurement — if Meta SDK is enabled
  • Personal info (customer names, phone numbers, addresses in order alerts) shared with Telegram for message delivery — only if the user connects the optional Telegram bot; not sold
  • Customer messages, phone numbers and order details shared with WhatsApp (Meta, WhatsApp Business Platform) for message delivery, and with Google AI services for reply generation — only if the user connects the optional WhatsApp AI bot to their WhatsApp Business number; not sold
  • Page customer messages and order details shared with Meta (Messenger Platform) for message delivery, and with Google AI services for reply generation — only if the user connects the optional Messenger AI bot to their Facebook Page; not sold
Security Practices
  • Data is encrypted in transit (HTTPS/TLS)
  • Data can be deleted on request (in-app deletion available)
  • This policy is reviewed and updated to maintain Google Play compliance

Refer to Bonik AI's individual Data Safety section on Google Play for the most up-to-date app-specific disclosure.


25. Contact Us

For any questions, concerns, data requests, or complaints regarding this Privacy Policy or the handling of your personal data, please contact us:

Business: Sharif Express (developer name: AI1952)

Privacy Email: [email protected]

Website: bonikai.app

Response Time: Within 30 days (urgent requests: 5 business days)

Please use the following subject lines for faster routing:

  • "Privacy Request — Bonik AI" — for data access, correction, or portability requests
  • "Account Deletion Request — Bonik AI" — for account and data deletion
  • "Privacy Complaint — Bonik AI" — for reporting a privacy concern

If you are located in the EU and are not satisfied with our response, you have the right to lodge a complaint with your local Data Protection Authority (DPA).


26. Bangladesh User Disclosures

This section applies specifically to users of Bonik AI located in Bangladesh.

Applicable Law

The collection, use, and processing of personal data of Bangladeshi users is subject to the Bangladesh Digital Security Act 2018 and any subsequent amendments or regulations issued by the Bangladesh Telecommunication Regulatory Commission (BTRC) or other relevant authorities.

Data Localization

At present, Bonik AI stores user data on international cloud infrastructure (Google Cloud Platform). By using the app, Bangladeshi users acknowledge that their data may be processed and stored outside of Bangladesh. We are committed to reviewing and complying with any future data localization requirements introduced by Bangladeshi law.

Your Rights as a Bangladeshi User
  • You have the right to know what personal data Bonik AI holds about you
  • You have the right to request correction of inaccurate data
  • You have the right to request deletion of your personal data (see Section 9)
  • You have the right to withdraw consent for data processing at any time
  • You have the right to lodge a complaint with the relevant Bangladeshi regulatory authority if you believe your data rights have been violated
AI Content Disclosure (Bangladesh)

Bangladeshi users should be aware that AI-generated content produced by Bonik AI is created by international AI models and may not always reflect local laws, cultural norms, or regulatory requirements. Users are responsible for ensuring that any AI-generated content they publish or share complies with Bangladeshi law, including the Digital Security Act 2018 and the Information and Communication Technology Act 2006.

Contact for Bangladeshi Users

Bangladeshi users may direct privacy inquiries in Bengali or English to: [email protected] — subject: "Privacy Request — BD User"


27. Telegram Bot (Optional Integration)

Bonik AI offers an optional Telegram bot (@BonikAIBot) that sends business notifications to sellers on Telegram. The bot does nothing until you actively connect it from inside the app (More → Telegram Bot → Connect).

What We Collect
  • Your Telegram chat ID (a numeric identifier Telegram assigns to your chat with the bot) and the date you connected
  • We do not receive your Telegram phone number, password, contact list, or any of your other Telegram conversations
What the Bot Sends to Your Telegram
  • Order alerts — including the customer's name, phone number, delivery address, product, and order amount
  • Sales reports and summaries — daily/weekly/monthly totals, courier performance, best-selling products
  • Subscription notices — payment issues or renewal reminders relating to your Bonik AI plan
Your Customers' Data

Order alerts contain personal data of your customers (name, phone number, address). When you enable the bot, this data is transmitted through Telegram's Bot API and delivered to your Telegram account, where it is subject to Telegram's Privacy Policy. As the seller, you are responsible for keeping your Telegram account secure — anyone with access to your Telegram account can read these messages.

Control & Deletion
  • Connecting the bot is entirely your choice; every feature of Bonik AI works without it
  • Disconnect anytime from the app (More → Telegram Bot → Disconnect) or by sending /stop to the bot
  • On disconnect, your stored chat ID is deleted and all Telegram messages stop immediately
  • Deleting your Bonik AI account also removes the Telegram integration data

We never sell Telegram-related data, and the bot sends no advertising or third-party promotional messages.


28. WhatsApp AI Bot (Optional Integration)

Bonik AI offers an optional WhatsApp AI bot that answers your customers on your own WhatsApp Business number on your behalf — product questions, prices, stock, and order taking. The bot does nothing until you actively connect your number from inside the app (More → WhatsApp AI Bot → Connect), using Meta's own sign-up window. You can keep using the WhatsApp Business app on your phone as before.

What We Collect
  • Your WhatsApp Business phone number, its display name, the related Meta account IDs, and the access token Meta issues so the bot can send replies from your number — plus the date you connected
  • Messages your customers send to your number that the bot answers, processed to generate replies; a short recent-conversation history is kept per customer so follow-up questions make sense
  • Customers' WhatsApp phone numbers and, when they share them, the name, phone number and delivery address of an order — saved as orders in your Bonik account
  • Which advertisement a customer came from (ad ID and headline), so the bot knows which product they saw
  • Meta's delivery and billing notices for the bot's replies, used to keep the bot within Meta's free messaging windows
  • We do not receive your Facebook password or your WhatsApp password. Contact and chat-history sync events that Meta sends when you connect a number used in the WhatsApp Business app are counted, not stored
Which Chats the Bot Answers
  • By default the bot only answers chats that start from your Click-to-WhatsApp ads — Meta does not charge for these conversations for a limited time
  • Other chats are left for you to answer in the WhatsApp Business app, unless you switch on "Also answer direct chats", which uses Meta's monthly free messages for your number and switches itself off before they run out
  • When you reply to a customer yourself from the WhatsApp Business app, the bot steps back from that chat for a while
Your Customers' Data

As the business owner, you are the business your customers are talking to. Their messages and order details flow through Meta's WhatsApp Business Platform (under the WhatsApp Privacy Policy and WhatsApp Business Terms) and are processed by Google's AI services to generate replies. You are responsible for having the right to communicate with your customers and for keeping your WhatsApp account secure.

Payments to Meta

Meta requires a payment method on your WhatsApp Business account and bills you directly under its own pricing. Bonik AI never sees your card details. The bot is designed to stay within Meta's free messaging windows, but Meta's pricing is set and can be changed by Meta.

Your Controls
  • Disconnect anytime from the app (More → WhatsApp AI Bot → Disconnect) — the stored access token is deleted and the bot stops replying immediately. To unlink your number from the WhatsApp Business Platform completely, also use the WhatsApp Business app: Settings → Account → Business Platform → Disconnect
  • Deleting your Bonik AI account also removes the WhatsApp integration data and the bot's conversation history

We never sell WhatsApp-related data, and the bot sends no advertising or third-party promotional messages to your customers.

29. Messenger AI Bot (Optional Integration)

Bonik AI offers an optional Messenger AI bot that answers your Facebook Page's customers on your behalf — product questions, prices, stock, and order taking. The bot does nothing until you actively connect your Page from inside the app (More → Messenger AI Bot → Connect) by signing in with Facebook and choosing which Page to connect.

What We Collect
  • Your Facebook Page ID, Page name, and a Page access token issued by Meta when you grant access — stored securely and used only to receive and reply to your Page's messages
  • Messages your customers send to your connected Page, processed to generate the bot's replies; a short recent-conversation history is kept per customer so follow-up questions make sense
  • Order details customers provide to the bot (name, phone number, delivery address, product, amount) — saved as an order in your Bonik account, exactly like any other order
  • We do not receive your personal Facebook password, your friends list, your personal messages, or any conversation from Pages you have not connected
How the AI Replies Are Generated

To answer a customer, the bot sends the customer's message, the recent conversation, and your product Inventory (product names, selling prices, stock — never your cost prices) to Google's AI services, which generate the reply. This data is used only to produce the response and is handled under the Google Privacy Policy. The bot replies only with information from your Inventory; when it does not know something, it says the seller will follow up.

Your Customers' Data

As the Page owner, you are the business your customers are talking to. Their messages and order details flow through Meta's Messenger Platform (under Meta's Privacy Policy) to Bonik AI, which processes them on your behalf to run your shop. Orders taken by the bot appear in your app's Messenger Orders page, and you remain responsible for how you use your customers' information.

Usage Limits

The number of AI replies per day depends on your subscription plan. Past the limit, customers receive a polite notice that the seller will reply personally — no message is ever silently dropped.

Your Controls
  • Disconnect anytime from the app (More → Messenger AI Bot → Disconnect) — the stored Page token is deleted, the Page is unsubscribed, and the bot stops replying immediately
  • You can also revoke Bonik AI's access from your Facebook settings (Settings → Business Integrations)
  • Deleting your Bonik AI account also removes the Messenger integration data

We never sell Messenger-related data, and the bot sends no advertising or third-party promotional messages to your customers.


30. Website Purchases (bonikai.app)

Besides Google Play, you can buy a Bonik AI plan on our website, bonikai.app, and pay with bKash, Nagad, Rocket, internet banking, or a debit/credit card. This section explains what happens to your information when you do.

What We Collect
  • The name, mobile number, and email address you enter at checkout, and the plan, duration, and amount you choose
  • The payment result from EPS: whether the payment succeeded, the amount, an EPS transaction reference, and the payment method used (for example "bKash")
  • We do not receive your card number, bKash/Nagad/Rocket PIN, or OTP. You enter those only on EPS's secure payment page
How We Use It
  • Activate your plan: We check whether a Bonik AI account uses the email you entered. If one does, the plan is switched on for that account. If not, we issue a single-use redeem code and show it on screen and send it by email
  • Receipts and service emails: Payment confirmations, redeem codes, and messages about your order
  • Support and refunds: To find your order when you contact us, and to process refunds under our Refund Policy
  • Fraud prevention and accounting: To detect duplicate or suspicious payments and to keep the financial records the law requires
Payment Reminder Emails

If you start a payment but do not complete it, we may email you up to two reminders about that order in the following days. Each email contains a link that reopens the payment page with your details filled in. The second email may include a personal, time-limited discount for the same plan. We do not send these reminders if you have since completed a purchase, if you have turned off marketing emails in the Bonik AI app, or if you have unsubscribed.

Every reminder has an unsubscribe link, and email apps such as Gmail also show a one-click unsubscribe button. Unsubscribing stops these reminders permanently. You will still receive receipts and redeem codes for any purchase you complete.

Who We Share It With
  • EPS (Easy Payment System) — name, mobile number, email, amount, and order reference, to process the payment
  • Firebase (Google) — your email, to find the matching Bonik AI account and activate the plan
  • Email delivery providers — your email address, to deliver receipts, codes, and reminders

We never sell this information and never share it for anyone else's marketing.

Website Analytics

bonikai.app uses Google Analytics (through Google Tag Manager) and the Meta Pixel to understand visits and to measure whether our ads lead to purchases. When a payment succeeds, the Meta Pixel receives only the plan and the amount. Your name, mobile number, and email are never sent to these tools.

How Long We Keep It
  • Order and payment records are kept for as long as needed for accounting, tax, refund, and dispute purposes
  • Discount offers expire automatically after the period stated in the email and can be used only once
  • Unsubscribe requests are kept so that we can keep honouring them

To ask about or delete your website purchase data, email [email protected]. Records that the law requires us to keep are retained only for that purpose.

🚀 আজই শুরু করুন

আপনার F-Commerce বিজনেসকে
পরবর্তী স্তরে নিয়ে যান

হাজার হাজার বাংলাদেশি সেলার ইতিমধ্যে Bonik AI দিয়ে তাদের বিজনেস পরিচালনা করছেন। আজই যোগ দিন এবং পার্থক্যটা নিজে অনুভব করুন।