Facebook & Instagram Connected-Account Privacy Notice
Effective Date: September 25, 2026
Last Updated: September 25, 2026
About this Notice
This Notice describes how Stesso, Inc. ("Stesso," "we," "us") accesses, uses, stores, shares, and deletes information from a Facebook Page or Instagram professional account that a creator connects to Stesso. It supplements Stesso's general Privacy Policy. Where the two differ with respect to connected Facebook or Instagram accounts, this Notice controls.
Stesso's creator tools connect to Facebook and Instagram through the Meta Platform using Facebook Login. Meta's own handling of your information is described in the Meta Privacy Policy. Meta is not responsible for Stesso or for this Notice.
What Stesso Does with a Connected Account
Stesso helps a creator answer the people who comment on the creator's own posts. For the Facebook Pages and Instagram accounts the creator chooses to connect, Stesso reads the comments left on the creator's posts, drafts a suggested reply to each in the creator's voice, and posts a reply at the creator's direction. It also shows the creator their posts and basic engagement statistics alongside the comments, so they can see which post a comment is about.
A reply is posted only at the creator's direction: either the creator approved that specific reply, or the creator turned on automatic replies for that account within limits they set. Automatic replies are off by default, and those that no person reviewed carry a disclosure that the reply was drafted with AI unless the creator turns that disclosure off. Stesso never acts on a Page or account the creator has not connected.
Where a creator enables messaging features, Stesso also shows the creator the direct messages sent to the connected Page or Instagram account and lets the creator answer them. Replies to messages are written or approved by a person on the creator's team; Stesso does not send promotional or unsolicited messages, and does not message anyone who has not first messaged the creator.
Permissions We Request
When a creator connects, Facebook asks them to grant Stesso permissions. Each is used only for the purpose shown:
- Your Pages and linked Instagram accounts (
pages_show_list,instagram_basic,business_management) — to list the Pages and Instagram professional accounts you manage so you can choose which to connect, including those owned through a Meta Business portfolio. - Read your posts and their comments (
pages_read_engagement,pages_read_user_content,instagram_manage_comments) — to show you the comments on your own posts and the post each one is about. - Reply to comments (
pages_manage_engagement,instagram_manage_comments,instagram_manage_engagement) — to post the replies you approve or authorize. - Be notified of new comments (
pages_manage_metadata) — to subscribe your Page to comment notifications so new comments reach your inbox promptly. - Post statistics (
read_insights,instagram_manage_insights) — to show you view, like, and comment counts for your own posts next to their comments. - Messages (
pages_messaging,instagram_manage_messages) — only where you enable messaging features, to show you messages sent to your account and send the replies you or your team write. - Your identity (
public_profile,email) — to identify which Facebook account connected, and to contact you about the connection.
You can decline any permission in the Facebook dialog; features that depend on it will then be unavailable.
Information We Receive
- Connected-account data: your Facebook user ID, the connected Page's ID and name, the linked Instagram account's ID and username, the permissions you granted, and the access tokens needed to act on those accounts. If you grant
email, the email address on your Facebook account. - Your posts: captions and messages, thumbnails or images, permalinks, post dates, media type, and engagement statistics (likes, comments, views) for posts on the connected accounts.
- Comments on your posts: the comment text, the commenter's public name or Instagram username, the commenter's app-scoped ID, the like count, the timestamp, and the comment and post IDs.
- Messages (only where messaging features are enabled): the message text, the sender's name and app-scoped ID, and timestamps.
We do not receive or store profile photos of commenters, your friends list, or any data about Pages or accounts you have not connected.
How We Use It
We use the information above only to provide Stesso's creator tools to the creator who connected the account: to show them their comments and messages, to draft replies in their voice, to post the replies they direct, and to show them how their posts are performing. To draft a reply, the comment or message and the commenter's public name are sent to our AI providers (Google Vertex AI and OpenAI), which process it only to return the draft and do not use it to train their own models. We may use a creator's own published replies to learn that creator's voice. We do not use commenters' or message senders' information to train general-purpose models.
We do not, and will not:
- sell, license, or rent Facebook or Instagram data, or buy it from anyone;
- share it with data brokers or advertising networks, or use it for advertising or ad targeting;
- use it to make decisions about anyone's eligibility for housing, employment, credit, insurance, or any other opportunity, or for surveillance;
- combine it with data from other sources to identify a commenter or build a profile of them; or
- use one creator's Facebook or Instagram data for any other creator.
Information About Commenters
People who comment on a creator's posts are generally not Stesso users. We receive only what Meta makes available with the comment and use it for one purpose: helping the creator answer it. If you have commented on a creator's Facebook or Instagram post and want the copy we hold deleted, follow the steps on our Data Deletion Instructions page. Deleting your comment on Facebook or Instagram also removes it from our systems within 30 days, as described below.
How We Protect It
Access tokens are encrypted at rest using AES-256-GCM, are sent to Meta only in request headers, are never shown in the product or returned to the browser, and are redacted from our logs. All traffic to and from Stesso is encrypted in transit. Access to a connected account's data inside Stesso is limited to the members of that creator's channel and to Stesso staff who need it to operate and support the service. If we learn of unauthorized access to Facebook or Instagram data, we will notify affected creators and Meta as required.
Retention and Deletion
How long we keep it. Comment and message content, commenter names and IDs, and the content of your posts that we receive from Meta are either re-verified with Meta or deleted within 30 days. We re-read the comments on connected accounts on a rotating schedule; anything we cannot re-verify within 30 days — because the comment or post was deleted, or the account was disconnected — is erased automatically. What remains afterwards is the creator's own content: the replies they published, the record that they published them, and timestamps.
When a creator disconnects. Disconnecting a Page or Instagram account in Stesso immediately stops all reading and posting, removes Stesso's permissions with Meta, deletes the stored access tokens, and erases the comment and message content, commenter names and IDs, and post content we received for it. Replies the creator already published stay on Facebook or Instagram.
When access is removed in Facebook or Instagram. If you remove Stesso from your Facebook or Instagram settings instead, our next attempt to read the account fails and the data described above is erased within 30 days. To have it erased straight away, disconnect in Stesso or send a deletion request as described below.
On request. Any creator, and any person who has commented on or messaged a connected account, can ask us to delete the data we hold about them. How to do that is set out on our Data Deletion Instructions page. We complete verified requests within 30 days and confirm when they are done.
How to Remove Stesso's Access
Any one of these is enough:
- In Stesso: open Settings for the channel and choose Disconnect on the Facebook & Instagram card.
- In Facebook: go to Settings & privacy → Settings → Business integrations (or visit facebook.com/settings?tab=business_tools), find Stesso, and choose Remove.
- In Instagram: go to Settings → Apps and websites, find Stesso, and choose Remove.
Sharing
We disclose Facebook and Instagram data only to service providers that operate Stesso on our behalf — cloud hosting, database, and the AI model providers named above — under contracts that limit them to that purpose and require them to protect it; to Meta, when we post a reply you direct; and where the law requires disclosure. If Stesso is involved in a merger or acquisition, this data would remain subject to this Notice.
Changes to this Notice
If we change how we handle connected Facebook or Instagram data, we will update this Notice and its Last Updated date before the change takes effect, and tell connected creators in the product.
Contact
- Privacy and deletion requests: privacy@stesso.com
- General support: support@stesso.com
Stesso, Inc., a Delaware corporation, United States.