Privacy Policy
Last updated: August 31, 2026
What we access
When a client (a website owner, or an agency acting on a website owner's behalf) connects a Facebook Page, Instagram professional account, or Threads account to WordsPost, Meta issues us an access token scoped to that account. Through it we can read:
- basic account identity — Page name, username, profile picture;
- the content we ourselves publish through the account;
- basic public engagement metrics on that content (likes, comments, shares, reach) for reporting purposes.
We do not request access to a client's personal Facebook profile, friends list, private messages, or any data belonging to the account's followers.
What we do with it
The access token is used for exactly one purpose: publishing a short announcement post — a link and a short text — to the connected Page, Instagram account, or Threads account whenever the client publishes a new article. We also read basic engagement counters back so the client can see how an announcement performed inside our own reporting.
We do not use Platform Data to build advertising audiences, to profile individual people, to train machine-learning models, or for any purpose beyond operating the publishing service the client signed up for.
What we never do
- We do not sell, rent, or trade Platform Data to any third party.
- We do not share access tokens or account data with anyone outside the WordsPost team, except infrastructure providers strictly necessary to run the service (hosting and database providers), who cannot see the data in readable form.
- We do not post, message, or take any action on a connected account other than publishing the announcements the client's own workflow generates.
Storage and security
Access tokens are stored encrypted at rest in our database. They are only decrypted, in memory, at the moment a post is published or a statistics reading is made, by our automated publishing service. Access to the database and to the decryption key is limited to the people operating WordsPost.
Retention and deletion
We keep an account's access token for as long as the client's connection stays active. A client can disconnect an account at any time — from their Meta Business settings (removing WordsPost's access there immediately invalidates the token on Meta's side), or by asking us directly. Once disconnected, we delete the stored token and stop making any further calls for that account. Published posts themselves remain on the client's own Page or account, exactly as any other post they've made — deleting the connection does not delete past posts.
Your rights
If you are a client, or represent one, and want to know exactly what we hold for your account, or want it deleted sooner than the automatic process above, write to us — we will confirm what's stored and delete it on request.
Changes to this policy
If how we handle Platform Data changes in a material way, we will update this page and change the date at the top.
Contact
Maksym Drovalov (WordsPost) — [email protected]