Handled Social

How to have your data deleted

Last updated 12 September 2026.

Handled Social is operated by F3 Strategy. When this page says "we", it means F3 Strategy.

This page explains how to have us delete or correct data about you or your business. Handled Social has no "delete my account" button. Closing an account, and any deletion without a button in the service, starts with an email to us and is carried out by a person on our team following a written internal procedure. This page tells you exactly how that works, what we delete, and what we keep.

The short version

  1. Email ryan@f3strategy.com from the email address on your account, or from an address tied to the Instagram account or Facebook Page in question.
  2. Tell us which of the two cases below applies and what you want deleted or corrected.
  3. A person replies to acknowledge your request, does the work, and emails you again when it is done. We acknowledge deletion requests within 5 business days and complete them within 30 days.

Status of your request

The acknowledgement email is how you know we received your request. The completion email is your confirmation. If we cannot delete something, the completion email says what was kept and why. The only things we refuse to delete are the integrity records listed under "What we keep", for the reasons given there.

Correcting data

You can ask us to correct as well as delete. Using the same mailbox, tell us what is wrong. We can correct by hand: your email address, your name, your business name, your brand profile and intake answers, and the Instagram username or Page name on a connection. We cannot correct the append-only history records listed under "What we keep", except an audit-log entry when a specific request requires it.

Case A: you are a Handled Social client and want your account closed and deleted

Handled Social is a subscription service for businesses. If you signed up, you have an account with a login, a brand profile, and possibly drafts, messages, and copied Instagram and Facebook posts.

What to send us

  • The email address you log in with.
  • Your business name as it appears in Handled Social.
  • Whether you want everything deleted, or only certain things (for example, only the posts we copied from Instagram or Facebook).

What we do

  1. If your subscription is still active, we cancel it in Stripe so you are not billed again. There is no cancel button in the product, or on the Stripe billing page it opens when the billing portal is switched on.
  2. We turn off any Instagram or Facebook Page connection on your account. That stops further reads, deletes every post we copied from those accounts, and starts the deletion of any photos and videos copied from them, which we wait to see finished before the next step.
  3. We remove your login. Your password is stored only as a scrambled hash, which we invalidate, and we replace your email address and name in our database with placeholder values so they can no longer identify you.
  4. We delete your brand profile and intake answers, what we learned about your brand and the record of what each thing we learned came from, the posts we copied or you pasted, generated drafts, and messages you sent us through the product. Any files you uploaded, including anything uploaded to your library, are deleted from storage as part of the same procedure. Brand source material that you pasted or that was fetched from a link during onboarding keeps a copy of its text in an unchangeable history record; that is covered under "What we keep" below.

Deleting an upload yourself

When the influence library is switched on, you can delete anything uploaded to your library yourself. It stops guiding your posts at once, its files are deleted from storage, and what remains is a record that an item existed: who uploaded it and when, what kind of item it was, and its rights class, with none of its words, pictures, or source. A file still uploading when you delete the item is deleted within a day. Anything already sent to Anthropic is deleted there within its 30 days.

What we keep, and why

Our database is built so that certain records cannot be deleted and can be edited only in the narrow ways described under "Things we cannot do". They exist so we can show what happened to an account, resolve a dispute, and keep billing reconcilable. Deleting them would require changing the database itself, which we do for an individual request only to correct or remove an audit-log entry. They are:

  • Audit logs. An append-only record of who did what and when (for example "connected Instagram", "removed a team member"). Some entries contain your email address, Instagram username, or Page name, the public link of a post marked as published, or, for drafts made before 12 September 2026, the occasion they were written for.
  • Usage logs and job history. Records of each generation, each Instagram or Facebook sync, and each run of the jobs that copy and delete photos and videos: when it ran and what it did, as counts and sizes, never the captions or the files themselves.
  • Draft history and source-material history. A log of what happened to each draft (with a fingerprint of its content), and every version of brand source material you pasted or we fetched from a link, is kept as a history record we do not otherwise change. When we close your account, we empty the text in the draft log and keep each entry's fingerprint; source-material history keeps its text. For posts read from Instagram or Facebook, the history records only that a read happened; the caption text is held only in the per-post records, which we delete. When the newer voice engine or learning controls are switched on, each draft also keeps a record of which of your posts it was shown as examples; disconnecting or closing your account clears which posts they were, and a fingerprint of each caption, never its words, stays with the draft.
  • Billing records. Our own append-only ledger of billing events, so invoices and charges stay reconcilable. Stripe, our payment processor, also holds its own record of your subscription and payments under its own terms.
  • Password-reset records. If you ever requested a password reset, a record of that request (containing only a scrambled token, not the link itself) stays in our database.

Copies held by our vendors

  • Supabase hosts our database and file storage. Everything described on this page lives there, so deleting from our database deletes from Supabase. Our database provider keeps short-term backups for disaster recovery, which age out on their own.
  • Anthropic (our AI provider) receives your brand profile, any text you pasted as brand material, and up to six of your copied posts as examples of your voice, each time we generate a draft. When the influence library is switched on it also receives up to four photos or video stills from your library with each draft, and, once, anything uploaded as someone else's, so its style can be described. When the look engine is switched on and our team asks it to describe your look, it also receives up to twelve photos or video stills from your library, the tags on them, which are words chosen from a fixed list, and the short description of the look we keep for anything uploaded as someone else's, never its pictures or words; while the look engine is on, each draft also carries your approved look. Anthropic deletes it from its systems within 30 days under its standard terms (material Anthropic flags for a policy violation can be held longer, up to two years), and does not train its models on it. We have not enabled Anthropic's zero-retention option, so the 30-day window applies to every account; if we enable it, this page will say so.
  • Resend (our email provider) received your email address, and your first name if we had it, when we sent you a password-reset email.
  • Stripe holds your email, card, and billing details, which it collects on its own checkout page and, when the billing portal is switched on, on its own billing page when you update your card. We never see your card number.
  • Vercel hosts the product. Two things reach Vercel. First, page-view analytics, which set no cookies and carry no personal identifiers: before a page view is sent, we strip the query string and fragment from the address, drop any visit to the password-reset page, and replace the account identifier in operator-only admin routes with a placeholder. Second, ordinary hosting logs, which like any host's logs can contain your IP address, browser, and the page address requested; our hosting provider keeps request logs briefly for operations.

Case B: your Instagram or Facebook data was read because a client connected their account

Handled Social can, for a client that has asked us to, read that client's own already-published Instagram posts, and the posts their own Facebook Page published, so that drafts we write sound like that business. This is read-only. We never publish, schedule, comment, message, or read anything about other people's accounts. Reading happens only for an account a client has had us connect.

An account gets connected one of two ways. Usually the client does it: on their Settings page they confirm their business may reuse its own posts, press Connect Instagram, and choose their Page and Instagram professional account in Meta's login dialog; the service then saves the one account that belongs to their brand. Or a member of our team links it from our admin tools, using access the client's business has already given ours in Meta; in that case our team sees the Pages and Instagram accounts our agency access can reach, and only the account they explicitly connect is recorded. If the Facebook Page an Instagram account belongs to is connected as well, that happens after Instagram, with the same confirmation made again for the Page's posts and the same access; nothing new is asked of Meta.

For each connected Instagram business account we store: the account's numeric ID and username, the linked Facebook Page ID, who confirmed the business had the right to reuse the posts (the client who connected, or the member of our team who linked it) and when, and for accounts the client connected, the access token Meta issued, encrypted, with its type, its expiry if any, and the ID of the client's Meta business portfolio. For each post we store the caption text, the public link to the post, the date it was posted, whether it was an image, video, or carousel, and Instagram's ID for the post. When photo and video copying is switched on, we also store a copy of each Instagram post's photos and videos, one small preview image we make from each photo, and the thumbnail Instagram gives for each video, in private storage, with each file's size, type, a fingerprint of its contents, the address it was copied from, and Instagram's ID for it, and a photo's or video's dimensions and a video's length; for a file we could not copy, we store why. For a connected Facebook Page we store the Page's ID and name, who confirmed the business had the right to reuse the Page's posts and when, and for Pages the client connected, a copy of the same encrypted token; for each post the Page itself published we store its text, its link, the date, what kind of post it was, and Facebook's ID for it. Meta requires the Page's own access token to read those posts; we ask Meta for it each time we read and do not store it. The caption text lives only in those per-post records, and the photos and videos only in those copies; each sync, and each run of the jobs that copy and delete them, writes a history entry saying what ran, without the captions or the files. The connect and disconnect events, including the Instagram username or the Page's name, are written to our permanent audit log. We download no photos or videos while that copying is off, and never those of a Page's posts, and we do not read the words of comments or who wrote them, direct messages, follower lists, or posts other people write on a Page. When performance measurement is switched on for the service and the account has been reconnected to grant it, we also store the numbers Instagram and Facebook give for each post and for the account (counts and daily totals, and follower totals by age range, gender and country, never who anyone is) and the comparisons we work out from them; they are deleted with the posts when the account is disconnected.

If you own the Instagram business account or the Facebook Page

If you are the Handled Social client, press Disconnect next to Instagram, or next to your Page, on your Settings page. That stops all further reads of that account, erases our copy of its token, and deletes every post we copied from it, immediately. Any photos and videos we copied from it are deleted from storage by a background job, usually within six hours, and it keeps going until none is left. When you disconnect, we delete the posts we copied; there is no separate copy of the captions left behind.

Otherwise, or if you would rather we did it, email us with the Instagram username or the Page's name. We will:

  1. Turn off the connection, which does exactly what the Disconnect button does.
  2. Confirm by email when done. The connect and disconnect entries in our audit log, which include the username or Page name, remain.

If you are also a Handled Social client, tell us whether you want only the Instagram or Facebook data removed or the whole account closed (see Case A).

Deleting or forgetting one post yourself

When learning controls are switched on, you can also act on one post at a time from your library. Delete our copy deletes our copy of that post's caption, and the voice example made from it, at once, and any photos and videos we copied from it usually within six hours. What remains is a record that the post existed: its link, when it was posted, what kind of post it was, Instagram's or Facebook's ID for it, when we first and last read it, and who confirmed the business may reuse its posts, with none of its caption, photos, or videos. Later reads leave that record as it is rather than copying the post again, and disconnecting the account deletes it with the rest. Forget for learning deletes nothing: it keeps the post but stops us learning from it, even when later reads find it again, until you undo it, whether for all learning or for one kind only, such as its words or its look. Both work on anything uploaded to your library too, where Delete our copy is the upload's own delete. Either way, what we had learned from that post (or, after a Forget of one kind of learning, what that kind had learned) is marked out of date at once; what we learned is written in our own words, never copied from the post. Neither can recall what was already sent to Anthropic, which deletes it within its 30 days.

Removing our access yourself

You can also cut off our access inside Meta. If you connected the account yourself, our app ("Handled Social Reader") is listed in your business portfolio: in Meta Business Suite, open Settings, then Integrations, then Connected apps, and remove it; on Facebook, the same list is under Settings, then Business integrations. If our team linked the account using access your business gave ours, remove that access instead: in Meta Business Suite, open Settings, then Partners (or the Page's assigned people), and remove our business. Either stops all further reads immediately. Press Disconnect on Settings, or email us, as well, so the posts already copied are deleted on our side.

When we delete copied posts without being asked

We delete copied posts, and any copies of their photos and videos, when a connection is removed or an account closes. You do not need to ask separately in either case.

If you are a person, staff member, customer, or business mentioned in one of those captions, or shown in a copied photo or video

Captions sometimes name people or other businesses, and photos and videos can show them. If a caption we copied mentions you, or a photo or video we copied shows you, and you want it removed, email us with a link to the post (or the Instagram account or Facebook Page it came from). We will delete the per-post record, and any photos and videos copied from that post, by hand and confirm by email; no other copy of that caption remains in our database. The original post on Instagram or Facebook is controlled by the account that published it, not by us.

How our Meta access works

When a client connects Instagram from their Settings page, Meta's login dialog issues our app ("Handled Social Reader") an access token for that client's business. We store it encrypted in our database, use it only to read, and erase our copy the moment the client presses Disconnect or asks us to; a Page connected alongside keeps its own copy, erased when the Page is disconnected. To read a Page we ask Meta for the Page's own token each time and never store it. Erasing our copy does not by itself revoke the app inside Meta; the section above says how to do that. When our team connects an account on a client's behalf instead, we read with our own agency access token, which is held in our hosting configuration and never written to the database.

Things we cannot do

  • We cannot delete data held by Meta, Stripe, Anthropic, Resend, Supabase, or Vercel. Each keeps its own records under its own terms. Our database itself is hosted by Supabase, so deleting from our database deletes from Supabase, subject to its short-term disaster-recovery backups, which age out on their own. Anthropic's copy of what we sent it, including any photos and stills, expires under the retention terms above; switching an item off or deleting an upload stops further sending but cannot recall what was already sent.
  • We cannot delete the integrity records listed under "What we keep": audit logs, usage logs and job history, draft history, source-material history for pasted and fetched material, billing ledger records, and password-reset records. The one exception is an audit-log entry that a specific request requires us to correct or remove, which a person on our team does by a written internal procedure. Otherwise we edit them only in these ways: closing an account empties the text in its draft history and job history, and draft history keeps a fingerprint of each entry; and a password-reset link is marked used when it is redeemed, when your password changes, or when your account is closed.

How to log out or clear a session

Handled Social sets one cookie, used only to keep you logged in. It expires after 14 days on its own. Logging out deletes it immediately. Changing your password invalidates every existing session.

Questions

Write to ryan@f3strategy.com. A person will reply to you directly from that address. Automated messages from the product (for example password resets) come from Handled Social <no-reply@handled.social>, which does not accept replies. Our Privacy policy and Terms of Service describe the rest of what we collect and why.