Privacy Policy
Last updated: August 24, 2026
SKJ ENTERPRISES, operating the AutomatePage service ("AutomatePage", "we", "us"), is the operator and data controller for the information described in this policy. AutomatePage helps Page operators research, generate, review, export, and, when a Meta connection is enabled, publish branded content. The information we process depends on which mode you use.
1. Current service modes
- Public manual mode: the current public launch does not use Facebook Login, request Meta permissions, store Meta access tokens, read Page insights, or publish to Facebook. Users review and download content, then decide whether and where to post it themselves.
- Meta-connected and reviewer mode: a controlled mode used by authorized developers, testers, and Meta reviewers may connect a Facebook Page and exercise the permissions described below. It is not available to ordinary public accounts until the required Meta review and release controls are complete.
2. Information we collect
- AutomatePage account data: your name, email, password hash, session records, workspace role, and security or support events. We do not store plaintext passwords.
- Service content and activity: Page settings, brand assets, source URLs you submit, generated images and captions, review decisions, batches, published-post identifiers, and operational audit records needed to provide and secure the service.
- Public-source research in manual mode: AutomatePage may process public posts from URLs a user supplies to identify facts, topics, visible text, and content patterns. Every AI image is created anew from a text prompt: no competitor, source, stock, Wikimedia, or other external image is supplied to the image generator or placed in final output.
- Meta connection data, only in connected mode: Page ID, name, category, avatar URL, an encrypted Page access token, token health and expiry information, dated Page-insight snapshots, published-post IDs, and reactions, comments, and share counts for connected-Page posts. During an owner-triggered Meta review evidence refresh, AutomatePage also reads the text returned for up to 25 recent AutomatePage-published posts and shows at most three examples on screen; that Graph-returned text is not added to the dated insight snapshot.
- Free-sample abuse prevention: if you claim a free sample, we store a one-way email fingerprint and the time it was used. This pseudonymous record is used only for fraud prevention to enforce one free sample per person, including after account deletion.
3. Meta permissions and their exact purposes
When Meta-connected mode is enabled and you choose to connect a Page, Meta shows the permissions in its consent flow. AutomatePage uses them only as follows:
public_profile: a Facebook Login platform default that lets Meta identify the signed-in account during consent. AutomatePage does not separately fetch or maintain a Facebook profile record from this permission.pages_show_list: lists Pages the signed-in person is permitted to manage so they can select the correct Page.pages_read_engagement: reads connected-Page information, recent post text, and engagement on that Page and its posts so AutomatePage can show performance and evaluate content the user published through the service. The bounded reviewer refresh displays at most three Graph-returned post-text examples.read_insights: reads Page-level media-performance metrics for the connected Page and stores dated dashboard snapshots. Follower count is read under pages_read_engagement, not this permission.pages_manage_posts: creates a post on the connected Page only after an authenticated human has reviewed and approved that exact content. AutomatePage code does not approve a post on the user's behalf.
The connected/reviewer flow operates only on a Page the tester manages. It does not use Meta permissions to read, monitor, or source competitor Pages. We do not sell Meta data, use it for advertising, or publish content that has not passed the human approval gate.
4. How we use information
- Provide accounts, workspaces, content generation, review, and export.
- Connect and identify an authorized Page, show its performance, and publish the particular content a human approves in connected mode.
- Secure the service, prevent abuse, investigate failures, and provide support.
- Improve content planning from the connected customer's own Page data; Meta permissions are not used for competitor sourcing.
5. Storage, security, and retention
Meta Page access tokens are encrypted at rest using AES-256-GCM. The public manual mode stores no Meta token. In connected mode, the token is kept while the Page remains connected. When the owner uses Remove this page, AutomatePage clears every Page-connection Meta identifier, token, expiry, and health field: the Meta Page ID, category and avatar, encrypted token and IV, token and data-access expiry times, token-health state, and last health-check time.
Removing a Page stops future Page access, deletes that Page's Meta-derived insight snapshots and per-post engagement metrics, and clears the live performance profile used for future planning. It intentionally retains the inactive local Page record and display name, generated content, batch and slot history, historical published-post IDs and timestamps, and the planning snapshot frozen inside each retained batch contract. That snapshot may contain aggregate learned preferences such as top templates, hours, keywords, and average engagement; it is retained only to explain the historical batch and is not updated or used to authorize a Meta request after Page removal. Account deletion removes the retained batch contracts. Those published-post IDs likewise remain only as service history and cannot authorize a future Meta request. While a Page remains connected, its Meta performance records do not have an automatic fixed-age purge. Generated content also has no automatic fixed-age purge; in particular, we do not claim a 90-day deletion lifecycle. Data that is not erased by Page removal remains until account deletion or a verified deletion request is completed, unless limited retention is required for security, fraud prevention, dispute resolution, or law.
In-app account deletion removes account and connected-Page database records and starts immediate and queued cleanup of stored media. Because object cleanup can continue through retry jobs, we do not promise that every stored object disappears within 24 hours. The one-way free-sample fingerprint and sample-used time remain for fraud prevention and do not have an automatic expiry in the current implementation.
6. Service providers
We share only the information needed for each provider to perform its service:
- Meta Platforms provides Facebook Login, Page data, and Page publishing in connected mode.
- Railway hosts the application services.
- PlanetScale stores application and connected-Page database records.
- Cloudflare R2 stores generated and uploaded media.
- Upstash provides job-queue infrastructure.
- Apify processes user-supplied public source URLs in manual research flows. It does not receive Meta Page access tokens.
- Kie.ai processes text and image-generation prompts, generated outputs for quality checks, and, through its Gemini service, public source-post images to extract visible text and subject matter. Source-post pixels are not used as image-generation references. Every AI image is created anew from a text prompt, and the image generator receives no Wikimedia, stock, competitor, or other external image reference. Kie.ai does not receive Meta Page access tokens.
7. Your controls and deletion
You can use Remove this page in Page settings to stop future AutomatePage access, erase that Page's Meta-derived insights and post engagement metrics, and clear its Page-connection Meta fields. You may also remove AutomatePage from Facebook's Business Integrations settings, which revokes Meta access but does not by itself erase your AutomatePage account or retained local service history. For complete steps, see Data Deletion.
To request access, correction, export, restriction, objection, or deletion, email privacy@automatepage.com. We may need to verify that the request comes from the account owner.
8. Cookies and children
We use essential session cookies to keep users signed in and protect accounts. We do not use third-party advertising cookies. AutomatePage is for business use and is not directed at children under 16; we do not knowingly collect their data.
9. Contact
Privacy questions for SKJ ENTERPRISES operating AutomatePage may be sent to privacy@automatepage.com.