Afterpost
How it worksSign inGet started

Last updated: 18 September 2026

Privacy policy

Afterpost is a comment-to-DM service for Facebook Pages. This page explains what we store, why, and how you can remove it. It is written for Meta App Review and for people using the product.

Data we collect

Account data: name, email, hashed password, locale cookie, and session cookies. Facebook data you authorize: Facebook user id, Page ids and names, encrypted Page tokens, comments that match an automation, and delivery status. We do not sell this data.

How we use it

We use it to sign you in, send verification and password-reset email, subscribe Pages to webhooks, match comments, send one private reply within Meta’s 7-day window, optionally post a public reply after the DM succeeds, and show Activity. Tokens stay on the server, encrypted.

Processors

Hosting and PostgreSQL (provisionally Railway), transactional email (Resend), and Meta/Facebook Graph and webhooks. Error reports may go to an optional operator webhook or Sentry if configured. Logs are structured JSON and never include access tokens.

Retention

Comments, delivery attempts, and history scan cursors stay until you delete the related Page connection or request deletion. Sessions expire. Encrypted Facebook tokens are removed when you disconnect or when Meta asks us to delete the Facebook user.

Your rights

You can verify or change your email, deactivate Pages, and request deletion (see Data deletion). Contact the operator using the From address on Afterpost emails if you need an export or a full account wipe.

Afterpost
PrivacyTermsData deletion

© 2026 Afterpost