EngageShield AI ("we", "our", or "us") provides an automated Instagram and Facebook comment management service. This Privacy Policy explains how we collect, use, and protect your information when you use our platform.
1. Information We Collect
When you use EngageShield AI, we collect:
Account information: Your email address and hashed password when you register.
Meta credentials: Facebook Page access tokens, Page IDs, and Instagram User IDs that you connect via OAuth or manual configuration. These are stored encrypted and used solely to interact with the Meta Graph API on your behalf.
Comment and message data: Instagram comments and Facebook messages received via Meta webhooks, including sender names, message text, timestamps, comment IDs, post/media IDs, and source type (post, reel, story, or ad). This data is used to generate AI-suggested replies and apply moderation rules.
Team member data: If you invite team members, we collect their email addresses, assigned roles (owner, manager, or moderator), page access permissions, and invite tokens. Team member activity (who replied to, skipped, or deleted each message) is recorded for reporting purposes.
Configuration data: Your app settings, keyword filters, auto-reply rules, and brand voice preferences.
Usage data: Analytics including message counts, reply history, per-team-member contribution statistics, and response time metrics to provide your dashboard reports.
2. How We Use Your Information
We use the information we collect to:
Receive and display incoming Instagram comments and Facebook messages on your dashboard.
Classify comments using AI to detect spam, profanity, or negative sentiment, and apply your configured moderation rules (including hiding or deleting comments on Meta platforms).
Generate AI-powered reply suggestions using Anthropic's Claude API.
Send replies to Instagram and Facebook on your behalf via the Meta Graph API — either manually approved by you or automatically when auto-send is enabled.
Provide analytics and reporting on your comment activity, including per-team-member contribution stats.
Generate CSV exports of your message and reply history when you request them.
Send transactional emails (e.g. email verification, team member invitations) via Resend.
Operate, maintain, and improve the platform.
3. Data Sharing and Third Parties
We do not sell your data. We share information only with the following service providers to operate the platform:
Meta (Facebook/Instagram): To receive webhooks and send replies via the Graph API. Governed by Meta's Privacy Policy.
Anthropic: Comment text is sent to Claude AI to generate reply suggestions. Governed by Anthropic's Privacy Policy.
Neon (database hosting): Your account data and message history are stored in a Neon Postgres database hosted on AWS.
Resend: Used to send transactional emails such as email verification.
4. Data from Meta Platforms
EngageShield AI accesses Instagram and Facebook data through the Meta Graph API under the following permissions:
instagram_basic — Read basic Instagram account info
instagram_manage_comments — Read and reply to Instagram comments
instagram_manage_messages — Read and reply to Instagram direct messages
pages_show_list — View the list of Facebook Pages you manage
pages_read_engagement — Read engagement data on Facebook Pages
pages_read_user_content — Read user-generated content on Pages (required to retrieve and reply to comments)
pages_manage_metadata — Manage webhook subscriptions for Pages
pages_manage_engagement — Hide or delete comments on Facebook Pages
pages_messaging — Send and receive messages via Facebook Pages
Data obtained via Meta APIs is used only to provide the core comment management features described in this policy and is not used for advertising, profiling, or shared with third parties beyond those listed above.
5. Data Retention
Message and comment data is retained for as long as your account is active. You may delete individual messages from your history at any time. When you disconnect your Meta account, your access tokens are removed immediately. If you wish to delete your account and all associated data, contact us at the address below.
6. Security
We take reasonable measures to protect your information, including:
Passwords are hashed using bcrypt and never stored in plain text.
All data in transit is encrypted via HTTPS/TLS.
Access tokens are stored in a secure database with access controls.
Each customer's data is isolated by tenant ID.
7. Administrative Access
Authorized EngageShield AI administrators may access tenant account data for the purposes of support, troubleshooting, and platform operations. All such access is logged and limited to personnel who require it to perform their duties. Administrators do not access your data for commercial purposes.
8. Your Rights
You have the right to:
Access the personal data we hold about you.
Request correction or deletion of your data.
Disconnect your Meta account at any time from the Config page.
Close your account and request all data be deleted.
9. Children's Privacy
EngageShield AI is not intended for use by anyone under the age of 16. We do not knowingly collect personal information from children.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify registered users of any material changes by email. Continued use of the service after changes constitutes acceptance of the updated policy.
Contact Us
If you have any questions about this Privacy Policy or how we handle your data, please contact us at: [email protected]