Trust and privacy
Privacy Policy
Last updated: July 27, 2026
Scope
This beta privacy notice explains how Fama Socials handles data when a merchant requests access, creates an authorized account, connects a public storefront, connects Instagram, prepares content, or publishes through the service. It requires owner and legal review before broad external launch and is not legal advice.
Data we handle
- Account email and Supabase authentication records.
- Store name, public storefront URL, content preferences, and public product facts and image URLs extracted at the merchant's request.
- Encrypted Instagram credentials, account connection status, approved drafts, schedules, publication outcomes, and minimal media metadata.
- Private-beta requests, invitations, activation milestones, support context, and data-deletion requests.
How data is used
Data is used to provide the storefront analysis, queue, publishing, scheduling, automation, account security, troubleshooting and private-beta administration requested by the merchant. Activation events contain minimal metadata and do not store captions, complete product descriptions, tokens, OAuth codes or raw provider responses.
Service providers
The current service uses Supabase for authentication and application data, Vercel for hosting, Meta's Instagram APIs for connected publishing, and OpenAI for optional grounded draft generation. Public storefronts are fetched only as needed for the requested workflow. Provider terms and platform policies also apply.
Retention and deletion
Application data is retained while the beta account is active and as needed for publishing safety, audit and support. Authenticated users can submit a controlled deletion request from Settings. The beta operator reviews ownership, active automation and any justified retention before confirming completion.
Contact
The project owner must configure NEXT_PUBLIC_LEGAL_CONTACT_EMAIL before inviting external merchants.