Last updated: 18 September 2026
Privacy policy
Afterpost is a comment-to-DM service for Facebook Pages. This page explains what we store, why, and how you can remove it. It is written for Meta App Review and for people using the product.
Data we collect
Account data: name, email, hashed password, locale cookie, and session cookies. Facebook data you authorize: Facebook user id, Page ids and names, encrypted Page tokens, comments that match an automation, and delivery status. We do not sell this data.
How we use it
We use it to sign you in, send verification and password-reset email, subscribe Pages to webhooks, match comments, send one private reply within Meta’s 7-day window, optionally post a public reply after the DM succeeds, and show Activity. Tokens stay on the server, encrypted.
Processors
Hosting and PostgreSQL (provisionally Railway), transactional email (Resend), and Meta/Facebook Graph and webhooks. Error reports may go to an optional operator webhook or Sentry if configured. Logs are structured JSON and never include access tokens.
Retention
Comments, delivery attempts, and history scan cursors stay until you delete the related Page connection or request deletion. Sessions expire. Encrypted Facebook tokens are removed when you disconnect or when Meta asks us to delete the Facebook user.
Your rights
You can verify or change your email, deactivate Pages, and request deletion (see Data deletion). Contact the operator using the From address on Afterpost emails if you need an export or a full account wipe.