1. Introduction & Scope
ContentSignal ("we", "our", or "us") provides automated interval-based social scheduling and media publishing software for Facebook Pages. This Privacy Policy discloses our practices regarding the collection, encryption, storage, and deletion of user information and uploaded media when you use ContentSignal.
2. Data We Collect & How We Use It
- Facebook Account & Page Information: When connecting through Facebook Login or Business Manager, we retrieve your user ID and list of owned Facebook Pages (
pages_show_list, pages_read_engagement). - Access Tokens: Page Access Tokens required to schedule and publish posts (
pages_manage_posts) are immediately encrypted at rest using AES-256-GCM. Decryption keys are stored strictly in server-side Cloudflare Worker secrets and are never exposed in browser bundles or client requests. - Uploaded Media (Images & Videos): Files you select for upload are transferred directly from your browser to private Cloudflare R2 storage buckets using short-lived signed URLs. Media is used strictly to publish scheduled posts to your designated Facebook Pages.
🛡️ 3. Ephemeral 7-Day Storage Lifecycle (Privacy by Design)
We practice strict data minimization. In accordance with our storage lifecycle policies:
- All uploaded media objects in Cloudflare R2 expire and are physically deleted after 7 days via automated native bucket lifecycle rules.
- Unpublished items remaining in the queue beyond 7 days are automatically marked as expired, and raw media is purged.
- Published items retain their title, caption, and Facebook Post ID for reporting, but their underlying storage object keys are scrubbed.
4. Data Sharing & Third Parties
ContentSignal does not sell, rent, monetize, or disclose your personal data or uploaded media to any third-party advertisers or data brokers. Data is transferred strictly to:
- Meta Graph API: For fetching authorized Pages and publishing approved posts.
- Cloudflare R2 & Workers: For encrypted media storage and serverless scheduling workers.
- Supabase: For PostgreSQL database storage with Row-Level Security (RLS) ensuring strict cross-account isolation.
5. Meta Data Deletion Instructions
Under Meta Platform Terms and GDPR/CCPA regulations, you have the right to request deletion of all personal data and content associated with your Facebook account at any time:
- Automated Deletion via Facebook: Go to your Facebook Profile > Settings & Privacy > Settings > Apps and Websites > Select ContentSignal > Click Remove. Facebook will automatically dispatch a signed Data Deletion Request to our callback endpoint (
/api/fb/data-deletion). - Immediate Purge: Our servers will immediately delete your connected Pages, encrypted tokens, scheduled posts, log history, and purge all associated Cloudflare R2 media files.
- Verification Code: You will receive a confirmation code and URL to track the deletion status at /data-deletion-status.
6. Contact Information
If you have any questions, privacy inquiries, or data deletion requests, please contact our privacy officer at:
Email: privacy@contentsignal.app
Legal: ContentSignal Security & Compliance Team
Website: https://contentsignal.vercel.app
© 2026 ContentSignal. All rights reserved.