LEGAL & COMPLIANCE

Privacy Policy

Last updated: September 6, 2026 • Effective date: September 6, 2026

1. Introduction & Overview

Gravliq (“we,” “our,” or “us”) operates the Gravliq Instagram automation and unified customer messaging platform. We are deeply committed to safeguarding your privacy, ensuring multi-tenant data isolation, and strictly complying with the Meta Platform Terms, Developer Policies, the General Data Protection Regulation (GDPR), and the California Consumer Privacy Act (CCPA).

This Privacy Policy describes what information we collect when you use our website, dashboard, and integration services, how we process and store that data, and your rights regarding your personal information.

2. Information We Collect

We collect information in the following categories:

  • Account & Profile Information: When you register for Gravliq, we collect your name, email address, hashed passwords (using bcrypt with work factor 12), and company or workspace details.
  • Connected Instagram Account Data: When you link your Instagram professional or business account via official Meta Facebook Login, we receive your Instagram business account ID, username, and token expiration data.
  • Engagement & Messaging Activity: To deliver keyword automation and unified inbox features, we receive real-time webhook events from the Meta Graph API containing comment IDs, public comment text, customer sender IDs (IGSID), customer usernames, and direct message text initiated by the customer.
  • Payment & Billing Data: Payment processing is handled by Stripe. We do not store full credit card numbers or banking credentials on our servers; we store Stripe customer IDs and subscription IDs.

3. How We Use Meta Graph API Permissions

Gravliq only requests the minimum Meta Graph API permissions necessary to operate our core services. We never use Meta API data for advertising, surveillance, data brokering, or selling to third parties:

  • instagram_basic: Used solely to verify your Instagram business account identity, display your handle in your workspace, and retrieve profile information.
  • instagram_manage_comments: Used to monitor incoming post comments for keyword triggers and dispatch user-defined public replies to your audience.
  • instagram_manage_messages: Used to send private direct messages triggered by comment keyword automations or customer inquiries, strictly adhering to Meta's 24-hour customer messaging window.
  • pages_show_list & pages_read_engagement: Used solely to discover Facebook pages linked to your Instagram professional account and subscribe to official webhook notifications.

4. Security, Encryption & Data Storage

Security is built into Gravliq's architecture from the ground up:

  • AES-256-GCM Token Encryption: All Meta OAuth access tokens are encrypted at rest using AES-256-GCM with unique cryptographic initialization vectors (IVs) and authentication tags before database persistence.
  • HMAC-SHA256 Webhook Verification: Every inbound webhook notification from Meta is verified using HMAC-SHA256 cryptographic signatures against our application secret before processing.
  • Multi-Tenant Isolation: Data between workspaces is strictly separated with database relational foreign keys and role-based access control (RBAC).
  • Rolling Activity Stream Expiry: Activity feeds and webhook event logs are capped at 50 rolling entries in memory with automated retention limits.

5. Compliance with Meta Messaging Policies

Gravliq strictly enforces Meta's standard messaging guidelines:

  • 24-Hour Messaging Window: Direct messages can only be sent within 24 hours of an incoming user interaction. Gravliq programmatically blocks outbound direct messages outside this window to ensure zero policy violations.
  • No Unsolicited Commercial Messaging: We do not support cold direct messaging or scraping customer lists. Messages are only sent in response to user-initiated actions.

6. User Data Deletion Instructions

In accordance with Meta Platform Terms and global privacy laws, users have the right to request deletion of all data associated with their account and connected Instagram profile:

  1. In-App Disconnection: Navigate to your Gravliq Workspace Dashboard → Instagram Connection → click Disconnect Instagram Account. This immediately revokes and purges your encrypted OAuth access token and webhook subscriptions.
  2. Facebook App Settings: Log in to your Facebook profile → go to Settings & Privacy → Settings → Apps and Websites → find Gravliq → click Remove.
  3. Workspace & Account Purge: Workspace Owners can delete their entire workspace and associated rules/logs under Workspace Settings → Danger Zone → Delete Workspace.
  4. Manual Deletion Request: You can submit a full data deletion request by visiting our Data Deletion Status Page or emailing privacy@gravliq.com with your account email. All user records, tokens, logs, and activity streams will be completely erased from our databases and backups within 30 days.

7. Contact Us & Data Protection Officer

If you have any questions about this Privacy Policy, your personal data, or Meta Platform compliance, please contact our Data Protection team:

Gravliq Legal & Data Protection Office
Email: privacy@gravliq.com
Website: https://gravliq.com