Privacy Policy
Last updated: 28 July 2026
CypherCrew is a work-management and social publishing tool used by a marketing agency and its staff. This policy explains what we collect, why, what we do with data obtained from Meta (Facebook and Instagram), and how to have it deleted.
1. Who we are
CypherCrew operates this application. We are the data controller for the account data of our own users, and we act on behalf of our clients — the businesses whose Facebook Pages and Instagram accounts are connected — when we publish and read engagement on their behalf.
2. What we collect
2.1 Account data of our users
- Name, work email address, phone number and job role.
- A password, stored only as a salted hash — never in readable form.
- Optional profile photo.
- Work records created in the app: tasks, comments, notes, files, leave and attendance entries.
2.2 Data obtained from Meta (Facebook & Instagram)
When someone connects a Facebook Page or Instagram Business account, we receive and store only what is needed to publish and report:
- Access tokens — encrypted at rest and never shown in the interface, exported, or sent anywhere other than Meta.
- Channel identity — the Page or Instagram account ID, username or Page name, and account type.
- The app-scoped user ID of the person who granted consent. This is what lets us honour a deletion request from Meta.
- Published content records — the post ID and permalink of content we published for that channel.
- Engagement — comments on posts we published, including the commenter's public display name and the comment text, so they can be read and replied to from the app.
- Insights — aggregate metrics such as impressions, reach, likes, comments and saves for posts we published.
We do not collect your Facebook or Instagram password, read your private messages, access your friends list, build advertising profiles, or use Meta data to train machine-learning models.
3. Why we use it
| Data | Purpose |
|---|---|
| Access tokens | Publish scheduled content and read engagement on the connected channel — nothing else. |
| Channel identity | Show which channel a post is going to, and stop content going to the wrong client. |
| App-scoped user ID | Match an incoming data-deletion request to the data it refers to. |
| Post IDs & permalinks | Link a published post back to the work record, and allow it to be removed later. |
| Comments | Let the team read and reply to audience comments from one inbox. |
| Insights | Report performance back to the client. |
4. Legal basis
We process our users' account data to perform our contract of employment or engagement with them. We process Meta data on the basis of the explicit consent given during the Facebook login flow, and on our clients' instructions. Consent can be withdrawn at any time by disconnecting the channel in the app or removing CypherCrew from your Facebook settings — see section 8.
5. Who we share it with
We do not sell data and we do not share it for advertising. Data is disclosed only to:
- Meta — when publishing content or reading engagement you have asked us to.
- Our infrastructure providers — the application host and database provider, and an object-storage provider used for media files. They process data on our instructions only.
- Authorities — where we are legally required to.
6. Where it is stored, and how it is protected
- Traffic is served over HTTPS.
- Platform access tokens are encrypted at rest with authenticated encryption; the key lives in the environment, not in the database or the codebase.
- Passwords are stored only as salted hashes.
- Access inside the app is permission-controlled: connecting channels and publishing are restricted to specific roles.
- Media files are held in private object storage and served through short-lived signed links.
7. How long we keep it
- Access tokens — until the channel is disconnected or the token is revoked, whichever comes first. They are erased immediately on disconnect.
- Channel identity, post records, comments and insights — for as long as the channel is connected, and deleted when a deletion request is honoured (section 8).
- User accounts — for the duration of the working relationship, plus any period we are legally required to keep records for.
- Deletion request records — kept after the deletion as proof it was carried out. They contain only the request, its confirmation code and counts of what was removed.
8. Your rights, and deleting your data
You may ask us for a copy of your data, ask us to correct it, or ask us to delete it. Two routes are available and both are honoured:
- Remove the app in Facebook — Settings → Apps and Websites → CypherCrew → Remove. Facebook notifies us automatically and we delete the associated data, then publish a confirmation code you can check.
- Ask us directly — use the data deletion page, which explains exactly what is deleted and what is kept.
9. Children
CypherCrew is a workplace tool and is not directed at children. We do not knowingly collect data from anyone under 16.
10. Changes
If this policy changes materially we will update the date at the top of this page and, where the change affects connected channels, notify the account holders in the app.
Questions about this document, or about the data we hold? Email dev.cypherms@gmail.com.