Last updated July 29, 2026
Privacy Policy
AttentionHub answers comments and messages on connected Instagram accounts and Facebook Pages, using the official Meta APIs.
Data About Our Customers
When someone signs up we store their email address and password hash for sign-in, the name of their workspace, who else they invited to it, their campaign settings, and, once billing is live, the subscription record and customer id held by our payment provider. We never store card numbers.
Data About Connected Accounts
For each connected Instagram account or Facebook Page we store the platform id, the handle or Page name, and an access token issued by Meta. Tokens are encrypted at rest with AES-256-GCM and are used only to do what the connected account has authorised: read comments on its own posts, and send messages from it. We never ask for, and cannot use, an Instagram or Facebook password.
Data About People Who Interact
When somebody comments on a connected post or sends the account a message, we store what is needed to answer them and to show the account owner what happened:
- their platform-scoped id and public display name, the comment or message id, and the text of a comment that matched a keyword
- a record that they sent the account a message, with the time. This is what lets a campaign follow up differently depending on whether somebody wrote back. The text of an ordinary direct message is not stored.
- whether they opened a tracked link, and which person the click belonged to, so a follow-up can be sent only to those who did or did not open it. Clicks also record a one-way hash of the IP address, the browser user agent, and the referring page.
- whether they follow the account, when Instagram discloses it. This is read at the moment they tap a button and is not stored.
- the delivery log of every message we sent them, and its outcome
This data belongs to the account owner who runs the campaign. They decide what is collected and for how long; we process it on their instructions to run the service.
What We Do Not Do
AttentionHub does not scrape Instagram or Facebook, does not use browser automation, and does not log in as anybody. Every action goes through Meta’s official APIs, under the permissions the account owner granted. We do not sell data, and we do not use it to train anything.
Who Else Processes It
Running the service means the following providers handle data on our behalf: Vercel (hosting), Neon (database), Upstash (queue), Railway (the background worker that sends messages), and Meta (the platform the messages are sent through). Each processes data only as needed to run the service.
Keeping And Deleting
Disconnecting an account from Settings removes its stored tokens and stops its campaigns immediately. Deleting a campaign deletes its scheduled messages, tracked links and click records with it. To have an entire account and everything in it deleted, use the Data Deletion page linked in the footer; we action those requests within 30 days.
Your Rights
If you are in the EU or the UK you have the right to ask what we hold about you, to have it corrected or deleted, to receive a copy, and to object to how it is used. If you commented on or messaged a business that uses AttentionHub, that business decides what happens to your data, so the fastest route is to contact them directly. Contact us and we will pass the request on and help.
Contact
For anything about privacy, or to make a request about your data, write to us at the address on the Data Deletion page.