S
SocialPilot

Privacy Policy

Last updated: 2026-08-07

1. What we collect

SocialPilot processes the following categories of data on behalf of your business when you connect your social media accounts:

  • Account credentials: Meta/Facebook App ID, App Secret (used to derive a Fernet encryption key for Page Access Tokens at rest), and OAuth tokens returned by Meta Graph API.
  • Page / Account metadata: Page ID, Page name, Page profile picture URL, connected Instagram Business Account ID, WhatsApp Business Phone Number ID.
  • Conversational data: messages received from your customers via Facebook Messenger, Instagram Direct, or WhatsApp Cloud API; AI-generated draft replies; human reviewer decisions (approve / reject / edit).
  • Knowledge base content: PDF, DOCX, TXT, and CSV documents you upload for the AI to retrieve from. These are chunked, embedded via Google Gemini embeddings (text-embedding-004 / gemini-embedding-001), and stored in our database with multi-tenant isolation per Page/Account.
  • Operational telemetry: server logs (request paths, response codes, response times), Celery task success / failure rates, and SSE connection counts.

2. How we use it

We use the data above solely to provide the SocialPilot service to you and your customers:

  • To send and receive messages on your behalf via Meta Graph API and WhatsApp Cloud API.
  • To generate AI draft replies grounded in your uploaded knowledge base.
  • To schedule, publish, and monitor your posts and ad campaigns.
  • To send you real-time SSE/WebSocket notifications about new customer activity on your connected Pages/Accounts.

We do not sell your data to third parties. We do not use your customer messages or knowledge base content to train any AI model.

3. Third-party processors

  • Meta Platforms, Inc. — Facebook Graph API v26.0 and Marketing API v26.0 for sending/receiving messages, publishing posts, and managing ad campaigns. Subject to Meta's Platform Terms.
  • Google LLC — Gemini API (gemini-3.1-flash-lite, gemini-flash-lite-latest, gemini-flash-latest) for AI reply generation; Gemini embeddings API for knowledge base vector search. Subject to Google's Privacy Policy.
  • Let's Encrypt — TLS certificate provisioning for socialpilot.tech.
  • Hosting infrastructure — Docker containers running on the operator's self-hosted servers (no third-party cloud storage of customer messages).

4. Data retention

We retain messages, conversations, and knowledge base content for as long as your SocialPilot account is active. You can delete any individual conversation, knowledge base document, or your entire account at any time via the dashboard or by emailing privacy@socialpilot.tech. We back up the database nightly; backups older than 30 days are deleted automatically.

5. Security

Page Access Tokens are Fernet-encrypted (AES-128 in CBC mode + HMAC-SHA256) at rest, with the Fernet key derived from your Meta App Secret. All HTTP traffic uses TLS 1.2+ via Let's Encrypt certificates. We publish HSTS, X-Content-Type-Options, X-Frame-Options, and a security.txt at /.well-known/security.txt.

6. Your rights

You have the right to access, correct, port, or delete any personal data we hold about you or your customers. To exercise these rights, email privacy@socialpilot.tech. We respond to all verified requests within 30 days.

7. Contact

For any privacy-related question, reach out to privacy@socialpilot.tech. For security disclosures, see /.well-known/security.txt.