1. Information We Collect
When you register, we collect your name, email address, and a hashed password. This information is used solely to authenticate you and manage your account.
When you connect a Facebook Page or Instagram Business/Creator account, we collect and store your Meta access tokens, page IDs, Instagram account IDs, and page names. We use this data exclusively to receive webhooks and send automated direct messages on your behalf through the Meta Graph API.
We store keyword rules you create, message templates, and logs of direct messages sent through our platform. These logs include commenter IDs, timestamps, matched keywords, and delivery status.
Billing is handled by Stripe. We do not store your credit card details. We store only your Stripe customer ID, subscription status, and transaction history.
We collect basic usage metrics such as DM counts, rule trigger frequency, and campaign statistics to power your analytics dashboard.
2. How We Use Your Information
- ◆To operate and deliver the SpidyChat service — processing webhooks, matching keywords, and sending DMs via the Meta Graph API.
- ◆To manage your subscription and process payments through Stripe.
- ◆To display analytics, logs, and performance data within your dashboard.
- ◆To send transactional emails (account confirmations, billing receipts) via our email provider.
- ◆To troubleshoot technical issues and maintain platform security.
3. Meta Platform Data Usage
We request the following Meta permissions: pages_show_list, pages_read_engagement, pages_messaging, pages_manage_metadata, instagram_basic, instagram_manage_messages, instagram_manage_comments, and public_profile. These are the minimum permissions required to receive comment webhooks, subscribe pages to our app, and send direct messages through the Meta Graph API.
Meta access tokens are used only to subscribe to webhooks and send direct messages as instructed by you through your automation rules. We do not read, store, or analyze the content of private conversations beyond what is necessary to log DM delivery status.
Meta tokens are stored securely and associated with your account. You can disconnect your Meta accounts at any time from the Settings page, which immediately revokes our access.
We do not sell, share, or transfer your Meta platform data to any third party for advertising or analytics purposes.
If you remove our app from your Facebook account via Facebook Settings → Apps and Websites, Meta automatically notifies us via a data deletion callback. Upon receipt, all data associated with your Facebook account — including access tokens, rules, DM logs, contacts, and payment history — is immediately and permanently deleted from our systems. You can verify the status of a deletion request at any time by visiting /data-deletion?id=[confirmation-code] (the code is provided in the Facebook deletion confirmation).
4. Data Sharing
We do not sell your personal information. We share data only with the following service providers, strictly for operating the platform:
- ◆Meta (Facebook/Instagram) — to send direct messages via the Graph API.
- ◆Stripe — to process subscription payments.
- ◆Resend — to deliver transactional emails.
- ◆MongoDB Atlas — as our database provider (data stored at rest with encryption).
5. Data Security
We implement industry-standard security practices including HTTPS-only communication, hashed passwords (bcrypt), JWT-based authentication with short-lived tokens, HMAC signature verification on all incoming webhooks, and encrypted data storage. Despite these measures, no system is 100% secure. We encourage you to use a strong, unique password and to report any security concerns to us immediately.
6. Data Retention
We retain your account data for as long as your account is active. DM logs are retained for up to 12 months by default. If you delete your account, all associated data — including access tokens, rules, DM logs, contacts, and payment history — is permanently and immediately deleted from our systems.
7. Your Rights
To exercise any of these rights, or to check the status of a Facebook data deletion request, visit /data-deletion or contact us at the email below.
- ◆Access — request a copy of all data we hold about you.
- ◆Correction — update inaccurate information from your account settings.
- ◆Self-service deletion — delete your account and ALL associated data immediately from Settings → Danger zone → Delete account.
- ◆Facebook data deletion — if you connected via Facebook, you can request data deletion directly through Facebook. We process these requests automatically via our data deletion callback.
- ◆Disconnect — revoke Meta platform access at any time from the Settings page.
- ◆Export — download your DM logs as a CSV from your dashboard.
8. Cookies
SpidyChat uses only essential cookies and browser localStorage for session management (storing your JWT token locally). We do not use tracking, advertising, or third-party analytics cookies.
9. Children's Privacy
SpidyChat is a business tool intended for adults. We do not knowingly collect personal information from anyone under the age of 16. If we become aware that a minor has created an account, we will delete it promptly.
10. Changes to This Policy
We may update this Privacy Policy as the platform evolves. We will notify registered users by email of any material changes at least 14 days before they take effect. Continued use of the platform after changes constitutes acceptance of the revised policy.
11. Contact
For any privacy-related questions, data requests, or concerns, please contact us at: