Our privacy commitment
Manual AI processes only the information needed to operate Page-scoped Messenger automation, provide account access, protect the service, and help authorized teams review their activity. We do not sell personal information or use Messenger content for advertising.
1. Who this policy applies to
This policy applies to visitors, account holders, Page administrators, and people whose interactions with a connected Facebook Page are processed through Manual AI. A business connecting its Facebook Page may also have its own privacy obligations and privacy notice.
2. Information we process
Account information
Name, email address, authentication information, account role, security settings, and activity required to manage access.
Facebook Page configuration
Page identifiers, Page names, protected access credentials, label configuration, approved questions and answers, and follow-up rules.
Messenger activity
Page-scoped sender identifiers, message text and metadata, timestamps, message direction, Meta labels, messaging-window information, and delivery status.
Operational and security data
Match results, unmatched messages, delivery attempts, error details, idempotency records, IP address, browser/session information, and diagnostic logs.
3. How we use information
- Authenticate users and enforce Page- and role-based access.
- Receive, match, send, and track Messenger replies and follow-up messages.
- Synchronize configured Meta labels and apply automation safeguards such as the Closed label.
- Maintain delivery reliability, prevent duplicate sends, retry temporary failures, and clean expired data.
- Protect the platform, investigate abuse, diagnose errors, and improve service performance.
- Comply with legal obligations and respond to valid privacy or security requests.
4. Facebook and Meta data
Connected Facebook Page data is processed to provide the automation requested by the Page owner. Use of information received from Meta is also subject to applicable Meta Platform Terms and policies. Manual AI does not request a Page credential for use outside the connected Page’s authorized workflows.
5. Legal bases
Depending on location and context, processing may rely on performance of a contract, legitimate interests in operating and securing the service, consent where required, and compliance with legal obligations. Businesses using the platform are responsible for establishing their own lawful basis for communicating with their customers.
6. Retention
We retain information only as long as needed for the purposes described above. Messenger history is configured to be locally retained for up to 30 days and capped at 50 messages per conversation. Failed follow-up records are eligible for cleanup after 24 hours. Some account, security, backup, and legal records may be retained longer where reasonably necessary.
7. Sharing and service providers
Information may be processed by infrastructure, hosting, database, email, security, and monitoring providers acting on our behalf. It may also be shared when directed by the authorized Page owner, required by law, necessary to protect rights or safety, or connected to a business reorganization. We do not sell personal information.
8. Security
We use safeguards designed for the sensitivity of the data, including encrypted Meta credentials, hashed Page API tokens, authenticated webhook validation, Page-scoped authorization, rate limiting, bounded local retention, and delivery idempotency. No internet service can guarantee absolute security.
9. Cookies
The authenticated application uses essential session, security, and preference cookies. These support sign-in, CSRF protection, and interface preferences. We do not use Messenger content for behavioral advertising.
10. Your choices and rights
Depending on applicable law, you may request access, correction, deletion, restriction, portability, or objection, and may withdraw consent where processing depends on consent. We may need to verify identity and authority before responding. If your request concerns a business’s Facebook Page, contacting that business directly may be the fastest route.
For deletion steps, visit our Data Deletion Instructions.
11. International processing and children
Service providers may process information in countries other than the country where it was collected, subject to appropriate safeguards where required. The service is intended for businesses and authorized adult users, not children under 13 or a higher minimum age required by local law.
12. Changes and contact
We may update this policy to reflect product, legal, or operational changes. The updated date above identifies the latest version. Questions or privacy requests can be sent to [email protected] or submitted through our contact page.