Privacy Policy
Last updated September 27, 2026
PostCrafter (https://contentaimanager.world) is a private tool operated by PostCrafter ("we"). It is used by a small team to prepare, schedule and publish content on Facebook Pages that we own or manage. There is no public sign-up: accounts are created by our administrators. This policy explains what data the tool handles, why, and your rights.
1. Data we collect
- Team accounts: name, email address, a hashed password, and sign-in times.
- When a Page administrator connects with Facebook Login: the Facebook user ID and name of the connecting profile, the permissions granted, and for each Page they choose to connect: its ID, name, category, profile picture link and a Page access token. Tokens are stored encrypted and are never shown in the browser.
- Posts we publish on our connected Pages: the post ID and the total number of reactions, comments and shares. We do not collect the names, profiles or messages of people who react to or comment on posts.
- Content we create: captions, comments and images prepared in the tool.
- Technical data: server logs (IP address, browser, time of request) kept for security, and a session cookie that keeps team members signed in.
2. How we use it
- To publish scheduled posts, and their first comment, on the Pages that were connected.
- To show how our own posts perform, so we can plan better content.
- To keep the service secure and working: sign-in, alerts, backups.
We do not sell data, show advertising, or build profiles of Facebook users. Data obtained from Facebook is used only for the purposes above, in line with Meta's Platform Terms.
3. Who processes it for us
- Meta Platforms: to publish on and read from our Facebook Pages.
- Contabo: hosting, on servers in the European Union.
- Cloudflare: secure delivery of the website.
- Google Cloud (Vertex AI): generates recipe texts and images from our own instructions. No Facebook data is sent to Google.
We share data with no one else, unless the law requires it.
4. Security and retention
- Traffic is encrypted (HTTPS); access tokens and other secrets are encrypted in the database; access is limited to authorised team members.
- Page access tokens are deleted as soon as a Page or the Facebook app is disconnected.
- Post records are kept while the Page is managed with the tool. Encrypted backups are kept for 14 days, then deleted. Server logs are kept for a limited period for security.
5. Cookies
Only what the service needs: a session cookie and a security (CSRF) cookie. Your light/dark display choice is kept in your own browser. No advertising or tracking cookies.
6. Your rights
Under the GDPR you may ask to access, correct or delete your data, or object to its use. Contact the administrator who gave you access; we answer within 30 days. You can also complain to your data protection authority (in France, the CNIL: cnil.fr). To remove data obtained through Facebook, see Data Deletion.
7. Changes
If this policy changes, the new version is published on this page with its date.