AI Social Assistant

Privacy Policy

Last updated: August 25, 2026

1. Who we are

AI Social Assistant ("we", "us", "our") is a tool that helps small businesses connect a Facebook Page, generate content with AI, and manage scheduling and comment replies for that Page. This policy explains what data we collect, why, and how it's used — including how we use data obtained through the Facebook/Meta Platform.

2. Information we collect

  • Account information: the email address and name you sign up with.
  • Business information: whatever you tell us about your business (name, description, target audience, tone/language/writing-style preferences) so generated content matches your brand.
  • Facebook Page data: when you connect a Facebook Page, we receive and store the Page's name, ID, and a Page access token from Meta, so we can post content and read/reply to comments on your behalf. We only request the permissions needed to do that (viewing your Pages, reading engagement, publishing posts, and managing comments) — never your personal Facebook profile data, friends list, or anything beyond the connected Page.
  • Content you create: topics, generated captions/hashtags/calls-to- action, any text you paste in to be rewritten, and any images generated for your posts.
  • Comment data: for Pages with automatic comment replies enabled, we receive the comment text and commenter's public name from Facebook via a webhook, so we can generate and post a reply. We do not access private messages.

3. How we use Facebook Platform Data

In line with Meta's Platform Terms, data obtained through Facebook Login and the Graph API is used only to provide the features you've asked for:

  • Publishing posts you've created or approved to your connected Page.
  • Reading comments on your Page's posts to identify ones worth replying to.
  • Posting AI-generated replies to comments, only on posts where you've turned this on.

We do not sell Facebook Platform Data, share it with advertisers, or use it for any purpose beyond operating the features described in this policy.

4. Third-party services we use

  • Supabase — our database, authentication, and file storage provider. Your account data, business settings, generated content, and Facebook Page tokens are stored there, protected by row-level security so only you can access your own data.
  • Google Gemini API — used to generate post captions, comment replies, and images. The text/context you provide (e.g. your business description, a topic, or pasted content) is sent to Google to generate a response.
  • Meta Graph API — used to connect your Facebook Page, publish posts, and read/reply to comments, as described above.

5. Data retention and deletion

We keep your data for as long as your account is active. You can disconnect a Facebook Page at any time from your dashboard, which stops us from accessing it further. To request deletion of your account and associated data, contact us at the email below.

6. Security

Facebook Page access tokens and other sensitive data are stored server-side and are never exposed to your browser or to other users. Access to your data is restricted by database-level security rules tied to your account.

7. Changes to this policy

We may update this policy from time to time. We'll update the "last updated" date above when we do.

8. Contact us

Questions about this policy or your data? Contact us at [YOUR SUPPORT EMAIL].