Privacy Policy
Last updated: 2026-08-07
1. What we collect
SocialPilot processes the following categories of data on behalf of your business when you connect your social media accounts:
- Account credentials: Meta/Facebook App ID, App Secret (used to derive a Fernet encryption key for Page Access Tokens at rest), and OAuth tokens returned by Meta Graph API.
- Page / Account metadata: Page ID, Page name, Page profile picture URL, connected Instagram Business Account ID, WhatsApp Business Phone Number ID.
- Conversational data: messages received from your customers via Facebook Messenger, Instagram Direct, or WhatsApp Cloud API; AI-generated draft replies; human reviewer decisions (approve / reject / edit).
- Knowledge base content: PDF, DOCX, TXT, and CSV documents you upload for the AI to retrieve from. These are chunked, embedded via Google Gemini embeddings (
text-embedding-004/gemini-embedding-001), and stored in our database with multi-tenant isolation per Page/Account. - Operational telemetry: server logs (request paths, response codes, response times), Celery task success / failure rates, and SSE connection counts.
2. How we use it
We use the data above solely to provide the SocialPilot service to you and your customers:
- To send and receive messages on your behalf via Meta Graph API and WhatsApp Cloud API.
- To generate AI draft replies grounded in your uploaded knowledge base.
- To schedule, publish, and monitor your posts and ad campaigns.
- To send you real-time SSE/WebSocket notifications about new customer activity on your connected Pages/Accounts.
We do not sell your data to third parties. We do not use your customer messages or knowledge base content to train any AI model.
3. Third-party processors
- Meta Platforms, Inc. — Facebook Graph API v26.0 and Marketing API v26.0 for sending/receiving messages, publishing posts, and managing ad campaigns. Subject to Meta's Platform Terms.
- Google LLC — Gemini API (gemini-3.1-flash-lite, gemini-flash-lite-latest, gemini-flash-latest) for AI reply generation; Gemini embeddings API for knowledge base vector search. Subject to Google's Privacy Policy.
- Let's Encrypt — TLS certificate provisioning for
socialpilot.tech. - Hosting infrastructure — Docker containers running on the operator's self-hosted servers (no third-party cloud storage of customer messages).
4. Data retention
We retain messages, conversations, and knowledge base content for as long as your SocialPilot account is active. You can delete any individual conversation, knowledge base document, or your entire account at any time via the dashboard or by emailing privacy@socialpilot.tech. We back up the database nightly; backups older than 30 days are deleted automatically.
5. Security
Page Access Tokens are Fernet-encrypted (AES-128 in CBC mode + HMAC-SHA256) at rest, with the Fernet key derived from your Meta App Secret. All HTTP traffic uses TLS 1.2+ via Let's Encrypt certificates. We publish HSTS, X-Content-Type-Options, X-Frame-Options, and a security.txt at /.well-known/security.txt.
6. Your rights
You have the right to access, correct, port, or delete any personal data we hold about you or your customers. To exercise these rights, email privacy@socialpilot.tech. We respond to all verified requests within 30 days.
7. Contact
For any privacy-related question, reach out to privacy@socialpilot.tech. For security disclosures, see /.well-known/security.txt.