JimmaaSign in

Legal

Privacy Policy

Last updated 2 August 2026

Who we are

Jimmaa is an AI-assisted messaging tool operated by Lamp Solutions Private Limited, a company registered in Kathmandu, Nepal. Jimmaa connects to a business’s own Instagram, Messenger, WhatsApp and TikTok accounts to help that business reply to customer messages and comments, and to publish that business’s own content. This policy explains what data Jimmaa processes and how.

Jimmaa is currently sold only to businesses in Nepal. The people who message those businesses may be anywhere, and this policy applies to them wherever they are.

What we process

When you message or comment on a business that uses Jimmaa, we receive, through the official APIs of Meta and TikTok:

  • The content of your messages and comments.
  • Basic profile information the platform provides — your username, display name and profile picture.
  • Message metadata — timestamps and which platform the message came from.

On behalf of the connected business, Jimmaa also stores secure access tokens that let it send approved replies. Tokens are encrypted at rest.

Connected TikTok accounts

When a business connects its own TikTok account, Jimmaa requests only the permissions it uses: basic profile information, so the business can see which account it has connected, and permission to publish content to that account.

  • Profile information— the account’s nickname, username and avatar, shown so the business can confirm which account a post is going to.
  • Posting settings — the audience options and comment, Duet and Stitch settings the account currently allows. These are read fresh each time a post is prepared and are not stored.
  • Content the business chooses to publish — the photo or video and its caption, sent to TikTok only after someone at the business reviews it and presses Post.

Jimmaa never posts on its own. Nothing is sent to TikTok without a person at the business reviewing the content, choosing its audience, and confirming. A business can disconnect its TikTok account at any time from the Channels page, which removes the stored tokens.

How we use it

  • To generate suggested reply drafts using AI (see “AI processing” below).
  • To let the business’s team review, edit, approve and send replies.
  • To organize conversations — labels, notes and customer records — so the business can respond well.

We do not use your messages to build advertising profiles, and we do not sell personal data.

Product photos and screenshot matching

Customers usually ask about a product by sending a screenshot of a post rather than naming it. So when a business attaches a photo to a post, Jimmaa keeps a second copy of that photo carrying an invisible marker that identifies the product, and stores a visual fingerprint of the image. When a screenshot arrives later, Jimmaa reads the marker or matches the fingerprint to work out which product is being asked about.

The marker identifies a product in that business’s own catalogue and nothing else. It carries no customer information, and it is meaningless outside the workspace that created it. Where a business publishes a post through Jimmaa, the marked copy is normally what goes out — except to TikTok, which is always sent the business’s original file with nothing added to it.

Importing a business’s own message history

A business can ask Jimmaa to bring its existing message history into its workspace, so its team can see the history behind a conversation. On TikTok this uses TikTok’s Data Portability API: the account owner authorizes the request, TikTok prepares an archive of that account’s direct messages, and Jimmaa downloads and imports it. A business can also upload an archive it downloaded from TikTok itself.

Imported messages are used only to operate that business’s own workspace. They are never shared with another customer, never used for advertising, and never used to train AI models. They are deleted when the workspace is deleted or on request.

AI processing

To draft suggested replies, the text of incoming messages and relevant business information (for example product and policy details) is processed by a large language model, which returns a draft. Jimmaa uses more than one model, and which one handles a given draft may change as better models become available. Some run on infrastructure we control, in which case the content never leaves it; others are hosted APIs, and the ones in use today are named below.

Whichever model is used, the rule is the same: your content is never used to train it. We only send content to a hosted provider whose terms bar training on it, and we hold any provider we add to that same condition.

Every draft waits for a person to approve it, unless the business has explicitly granted Jimmaa autopilot for that kind of reply.

Who we share it with

We share data only with the service providers that operate Jimmaa, and only so each can provide its part of it. As of the last updated date above, they are:

  • Model providers — OpenAI, for AI draft generation (processor).
  • Meta Platforms — Instagram, Messenger and WhatsApp APIs, to receive and send messages.
  • TikTok — TikTok’s APIs, to receive messages, to publish content the business has approved, and to import a business’s own message history.
  • Hosting and database — Vercel, Railway and Neon, which store and serve data on our behalf.

Providers in the first and last categories change as the service grows. Each one is bound to process data only on our instructions and for no purpose of its own, and this list is updated when it changes.

We do not sell your data or share it for advertising.

Retention

We keep conversation data for as long as the connected business uses Jimmaa to manage that relationship. You can request deletion at any time — see our Data Deletion page.

Where data is stored

Jimmaa is operated from Nepal, but the providers above run in data centres outside it, in regions we select. Sending a message to a business that uses Jimmaa therefore involves that data being processed in another country. We choose providers that commit to protecting it wherever it is held, and the same terms in this policy apply to it there.

Security

Access tokens are encrypted at rest, all connections use TLS, and access to a workspace is restricted to that business’s authorized team members.

Your rights

You may request access to, correction of, or deletion of your data. To do so, or for any privacy question, email hello@lamp.solutions.

Changes

We may update this policy; material changes will be reflected by the “Last updated” date above.

Contact