Handled Social

Privacy policy

Effective 12 September 2026. This is the privacy policy for Handled Social, the service at https://www.handled.social. It takes about five minutes to read. Every sentence describes what the service actually does today.

Who we are and how to reach us

Handled Social is a done-for-you social media service for small businesses. A person on our team writes and reviews every post; software helps with drafts.

Handled Social is operated by F3 Strategy.

Privacy questions, deletion requests, corrections, and security reports: ryan@f3strategy.com. That is a monitored mailbox, and it is the address meant everywhere this policy says "email us".

The short version

  • We collect what you type into the service (your email, password, business name, and the answers you give us about your brand) plus the drafts and messages created while we work together.
  • If we connect your Instagram business account, or the Facebook Page it belongs to, we read only your own already-published posts. We never post, schedule, comment, message, or read your inbox, and we never read anything about other Instagram or Facebook users. When you disconnect an account, we delete the posts we copied from it, and any copies of their photos and videos.
  • We send your brand profile and any material you paste to Anthropic to help draft posts. When the influence library or the look engine is switched on, we also send photos and video stills from your library. When the influence library is switched on, anything uploaded to it as someone else's is also sent once so its style can be described. Anthropic keeps that data for 30 days by default and does not train on it.
  • We do not sell your data and do not use it for advertising.
  • We set one cookie, which keeps you signed in.
  • There is no self-serve button to delete your account. Closing an account is a request you email us, and a person on our team carries it out following a written internal procedure. Details are at /legal/data-deletion.

What we collect when you sign up and use the service

Account details. Your email address, a password, and your business name. Passwords are stored only as a salted hash (scrypt); we never store or log the plain text. If you reset your password, we store a hashed reset token that expires after one hour.

Brand profile. The answers you give in our intake: what your business does, locations, hours, prices, website, social handles, who your customers are, how you like to sound, and anything you do not want said. You may also paste in existing material (menus, past posts, web copy). If you type customer or staff names into these answers, they are stored with them. We also keep the social handles and any notes our team records about access to each of your platforms, and suggested profile values the software proposes before you confirm them.

Other uploads. Other file uploads are not currently enabled. If we enable them, we will store the images or PDFs you upload, their filenames, and any caption, alt text, or tags you add, in a private storage bucket, and any files you uploaded are deleted from storage when your account is deleted.

Your library's influences. When the influence library is switched on for the service, you or our team can upload photos, videos with a still you choose, and words to your library to guide your posts. For each upload we keep who uploaded it, the source they named, and their answer to one question: whether it is your own content, which may guide your posts and be reused in them, or someone else's work you admire, which is kept for reference only. Whoever uploads someone else's work is responsible for having the right to keep it and have it described for that purpose. We check each file from its own contents (a photo in JPEG, PNG, or WebP up to 20 MB, or a video in MP4 or QuickTime up to 100 MB), keep it in the same private storage area as copied photos and videos with one small preview we make of each photo, and keep a video's still as a new copy we make of it. Anything uploaded as someone else's is never reproduced in a draft, word for word or as a picture, and never attached to a post: our software refuses a draft that repeats one of its sentences. Each item in your library, uploaded or read from Instagram or Facebook, can be set to guide your words, your look, both, or neither, for all your posts or for one; set to neither, it is kept and not used.

Working data. Draft and published posts and their review history; when post plans are switched on for the service, the plans our team makes before drafting (each plan's goal, platforms, posting window, occasion, and angle); messages you send our team through the service; monthly reports; and a record of who did what and when (an audit log). The audit log and post history are append-only. When your account is closed, the text in your post history is emptied; each entry keeps only what kind of change it was, who made it, when, and a fingerprint of its content. An audit-log entry is corrected or removed only when a specific request requires it, following a written internal procedure. Neither is otherwise edited after the fact.

Sign-in activity. While you are signed in, the service records the time you were last active. Our own code does not record your IP address, device, or location.

Who on our side can see it. Our team members are operators on the whole service and can see the data of every client account, including yours.

What we receive from Instagram and Facebook, how, why, and how to have it deleted

This section is written to be unmistakable because it covers data we read from Meta.

Reading applies only to an Instagram account, or a Facebook Page, that we have connected. If we have not connected one, none of this section applies to you yet.

What we read. Only your brand's own published Instagram posts and, if you also connect it, the posts your Facebook Page itself published, and, when performance measurement is switched on, the numbers about them and your account described under Performance numbers. For an Instagram post we read the caption, the post's permalink, when it was posted, whether it is an image, video, or carousel, and the post's Instagram ID (so we do not import the same post twice). The response also carries your account username against each post; we do not keep that per-post copy. For a Page post we read the same things: its text, its link, when it was posted, what kind of post it is (a photo, a video, an album, or words alone), and Facebook's ID for it. We also record your Instagram business account's ID and username and the connected Facebook Page's ID, and the Page's name if you connect the Page, so we know which account the posts belong to. When copying photos and videos is switched on for the service, we also read, for each Instagram post, the temporary web addresses Instagram gives for its photo or video, for a video's thumbnail, and for each photo or video in a carousel, with each one's Instagram ID and type, and we copy those files as described under Photos and videos below. While it is off we read none of those addresses and download no photos or videos, and we never download the photos or videos of Facebook Page posts. We do not read the words of comments or who wrote them, direct messages, stories, follower lists, posts other people write on your Page, or anything about any other person or account, and while performance measurement is off we read no likes, follower counts or other insights either (see Performance numbers below). The first read after you connect goes back through your most recent posts, up to 1,000, and so does every read until one finds a post, or until a read at least a day after one that found none finds none either; after that, each read asks only for posts published since the day before the last successful read. A post without a caption is recorded too, with its link, date, media type, and ID, so our record of what you have published includes it; only captions are used as examples of your voice. Our team may also paste past posts that you send us into the same store; those are kept and treated exactly like posts read from Instagram or Facebook.

Photos and videos. Copying them is a setting our team switches on for the whole service. When it is on, a background job copies the photos and videos of your Instagram posts into a private storage area at Supabase, our file-storage provider. Just before it copies a file, the job asks Instagram for the file's address again, because those addresses expire. It copies only from Instagram's and Facebook's own servers, checks from the file's own contents that it is a photo (JPEG, PNG, or WebP) or a video (MP4 or QuickTime), and does not copy a photo larger than 20 MB or a video larger than 100 MB. For each photo it keeps one small preview image it makes itself; for each video it keeps the thumbnail Instagram provides. Nothing is edited or converted. When a file cannot be copied (Instagram withholds it, for example for a copyright reason, or its address has expired, or it is too large, is not a photo or video, or would come from a server other than Instagram's or Facebook's), we record why instead, and the post's link still leads to it on Instagram. For each file we also keep its size, type, a fingerprint of its contents, Instagram's ID for it, and the address it was copied from, and for a photo or video its dimensions, and for a video its length. The service shows a file only through a link it signs for that moment, which expires after ten minutes. When the influence library or the look engine is switched on, small copies of the photos and video thumbnails may be sent to the AI model, as described under What we send to Anthropic; while both are off, none is.

Performance numbers. Reading them is a setting our team switches on for the whole service, and it needs two more permissions from you (see below), so a connection made before it was on reads none until you reconnect. While it is on, a background job that runs with the six-hourly reads asks Instagram and Facebook for the numbers they report about your own posts and account. For each Instagram post: views, accounts reached, likes, comments, saves, shares and total interactions, as counts, with profile visits for photos and carousels and average watch time for videos; a carousel is read as one post, never photo by photo. For each post your Page published: views, people reached, reactions of every kind added together, and clicks. For your Instagram account, each day: its follower count, accounts reached (split into followers and non-followers, as two totals), views, accounts engaged and interactions, and your followers over the last 30 days by age range, gender and country, as a total for each group; the number for a group of fewer than ten people is not kept. For your Page, each day: followers, people reached, views and interactions with its posts. These are totals: we never learn who liked, commented, followed or saw anything. A post is read every day for its first 14 days, every week until it is 90 days old, and every month after that, until it is two years old. When Instagram or Facebook gives no number, we record that there is none and why, never a zero. We use the numbers to compare each post with how your posts usually did before Handled, as plain arithmetic shown with how many posts it was compared with. They are deleted with the posts when you disconnect or your account is closed.

How we read it. You connect it yourself. On your Settings page you tick a confirmation that your business may reuse its own posts, including anyone named or pictured in them, press Connect Instagram, and Meta's own login dialog asks you to choose the Facebook Page and Instagram professional account to share with our app ("Handled Social Reader"). We record who confirmed the reuse and when. Someone on our team can also do the connecting for you from our admin tools, with the same confirmation, using access you have already given our business in Meta. If the Facebook Page it belongs to is connected too, that happens after Instagram, with the same confirmation made again for the Page's posts; it uses the access already given, and Meta is not asked for anything new.

What Meta gives our app is an access token for your business. Our login configuration asks for the pages_show_list, pages_read_engagement, and instagram_basic permissions; Meta may add the basic profile permissions it grants every app. When performance measurement is switched on for the service, Connect uses a second login configuration that also asks for the instagram_manage_insights and read_insights permissions, which let us read the numbers described under Performance numbers; neither can post, comment, or message, and we record which permissions each token carries. Before we keep the token we ask Meta what it can do, and we refuse and discard any token that could post, comment, or message. We store the token encrypted in our database, along with its type, its expiry if it has one, and the ID of your Meta business portfolio, and we use it only to read your account. If you connect your Page, the Page connection keeps its own encrypted copy of the same token. To read the Page's posts, Meta requires the Page's own access token; the service asks Meta for it with your business's token each time it reads, uses it for that read only, and does not store it. You never give us your Facebook or Instagram password, and we never see it. To find your account, the service lists the Pages and Instagram accounts the token can see; only the Instagram account that belongs to your brand is saved, and its Page only if you connect the Page. The connection is read-only. The service reads your posts when you connect, every six hours after that, and when our team asks it to. Copying photos and videos, when it is on, and deleting copies after a disconnect happen in background jobs that run with each of those six-hourly reads, deletions both before and after the read. Nothing the service does writes to Instagram or Facebook: it never publishes, schedules, edits, deletes, comments, or messages.

Why. Your past posts are examples of your voice. We keep them so that the drafts we write for you sound like you. When photo and video copying is on, we keep copies of their photos and videos so that our record of what you have published includes them and, when the influence library or the look engine is also switched on, so that the AI model can see your look. Up to six of your imported captions may be shown to the AI model as examples of your voice when we draft a post; when they are, the Anthropic terms below apply to those captions. When the newer voice engine or learning controls are switched on, each draft also records which of your posts it was shown as examples: their IDs, which a disconnect or deletion clears, and a fingerprint of each caption, never its words, which stays with the draft. When learning controls are switched on, we also keep a record of what we learn about your brand, written in our own words rather than copied from any post or upload, and of which posts, photos and videos, uploads, edits, choices between caption options and drafts each thing we learned came from. When one of those is deleted, removed by a disconnect, or forgotten for learning or switched off in your library, what was learned from it is marked out of date at once; forgetting or switching off one kind of learning only, such as its words or its look, marks only what that kind learned. When the look engine is switched on, what we learn about your look comes from your photos and videos, the tags you or our team give them, and the looks you admire, and becomes part of your brand profile only once a person on our team approves it. When the timing engine is switched on, it suggests a posting window for each planned post from your time zone, your opening hours, and when your own posts went out; a suggestion never schedules or publishes anything. When the context engine is switched on, it notes the public holidays where your business is, from a calendar kept inside the service (nothing about you is sent anywhere to look them up), and the promotions and events our team plans. When performance measurement is switched on for the service, we also count the posts you published before Handled's first post (how many, how often, and in which formats) and keep that count fixed, so later results can be compared with how you usually posted; the count is deleted with the posts when you disconnect or your account is closed. When the performance engine learns, with learning controls on, what it learns comes from how the posts we made for you compared with your usual, and each thing it learns names the posts it came from. When the audience engine is also switched on, it learns from your Instagram account's follower groups and reach totals described under Performance numbers, only once the account has at least 100 followers; each thing it learns is about a group, never a person, and names the account's numbers it came from, which a disconnect deletes. Either way, a person on our team reviews every draft before anything is published, and publishing is done by hand.

Who can see it. Our team can see how many posts have been imported for your brand, and can read the posts themselves, and open any copied photos and videos, through direct database and storage access. They are not shown to any other client. You can ask us for a copy at any time.

Our role. We act as a technology provider to your business under Meta's Platform Terms: we read your posts only for you and at your direction, we keep your data separate from every other client's, and if Meta contacts us about a request concerning your data we will tell you promptly.

How to have it deleted. Press Disconnect on your Settings page, next to Instagram or next to your Page. That stops all further reading of that account, erases that connection's copy of the token, and deletes every post we copied from that account, immediately; disconnecting one leaves the other connected. Any photos and videos we copied from that account are deleted from storage by a background job at the next scheduled run, usually within six hours; if storage fails part-way, the job carries on from where it stopped until none is left. When you disconnect, we delete the posts we copied; you do not need to ask separately. Disconnecting deletes what we hold; it does not by itself revoke the app inside Meta, which you can do under Connected apps in Meta Business settings. You can also email us and we will disconnect for you and confirm by email. When learning controls are switched on, you can also delete our copy of a single post, or forget one for learning, from your library (see Deleting your data). Your Instagram handle, your Page's name, and their IDs also appear in our append-only audit log; those entries are kept. Full instructions are at /legal/data-deletion.

What we receive from X, and how to have it deleted

This section applies only when reading X is switched on for the service and your brand's own X account is connected.

What we read. Only your brand's own posts on X, never your reposts of other people's posts or your replies: for each, its text, when it was posted, whether it has photos or video, and its X ID, from your most recent posts up to a limit we set (200 unless we change it, and never more than 3,200), then only what is new. We also record your X account's ID and username. X's answers include each post's public counts and, for posts from the last thirty days, its private counts such as impressions; we do not keep them. We do not download photos or videos from X, and we do not read your likes, followers, bookmarks, direct messages, or anything about any other account. Your X posts are used exactly as your Instagram posts are: kept in your library and shown to the AI model as examples of your voice.

How we read it. You connect it yourself from Settings: you tick the same confirmation that your business may reuse its own posts, press Connect X, and X's own screen asks you to let our app read your posts and profile and stay connected (the tweet.read, users.read, and offline.access permissions; we refuse and discard access that carries any other). We record who confirmed and when. X gives our app an access token that lasts two hours and a refresh token; both are stored encrypted, and a read that finds the access token expired uses the refresh token to get a fresh one. The service reads your posts when you connect, every six hours after that, and when our team asks it to, and never posts, replies, likes, follows, or messages on X. X charges us for each post it sends, so each brand has a monthly spending limit on reading X, and reading stops when it is reached.

How long we keep it. For as long as the account is connected, and only while X confirms it. Before each read, the service asks X again about each of your posts we hold that X has not confirmed in the last seventeen hours; a post you deleted or edited on X is deleted from our copy then, within a day of the change. If X has not confirmed a post for a day (for example, because the spending limit was reached or the connection stopped working), we delete our copy of it until X confirms it again. If X, or you as the owner of the account, asks us to delete content read from X, we do it within twenty-four hours of the request. A deleted copy keeps only the post's ID, link, date, and kind, so a post deleted on X is not imported again. Pressing Disconnect next to X stops all reading, erases both tokens, and deletes every post we copied from X at once. Your X username also appears in our append-only audit log; those entries are kept.

What we send to Anthropic

To draft posts, we send Anthropic (the maker of the Claude models) a request containing your brand profile as text (business name, description, locations, hours, prices, website, handles, audience, voice rules, including the edits to earlier drafts that our team has folded into your voice, facts, and hard no's), any material you pasted in, up to six of your imported posts or words you uploaded as your own as examples of your voice, and the task for that post. We do not send your email address, account identifiers, or payment details. The record of what we learned about your brand, and of what each thing we learned came from, stays with us and is never sent to Anthropic, except that the look our team approves becomes part of your brand profile, which is sent as described below.

When the influence library is switched on, each draft's request may also carry up to four photos or video stills from your library (from your own posts, or uploaded as your own), which we make into small new images first so that nothing written inside the files goes with them, and a short description of the style of anything uploaded as someone else's. To write that description, we send that item's words and pictures to Anthropic once, and only the parts set to guide your posts. Text that appears inside a picture is treated as part of the picture, never as an instruction. While the influence library and the look engine are both off, we send no photos or videos. Switching an item off, or deleting an upload, stops it being sent from the next draft on; Anthropic keeps what it already received for its stated retention, 30 days by default. Forgetting an item for all learning, or deleting our copy of it, does the same; forgetting it for one kind of learning only, such as its words or its look, stops sending only what that kind uses.

When the look engine is switched on and our team asks it to describe your look, we send Anthropic up to twelve photos or video stills from your library (from your own posts, or uploaded as your own, and only those set to guide your look), made into small new images first; the tags you or our team gave them, which are words chosen from a fixed list; and, for anything uploaded as someone else's and set to guide your look, the short description of its look we already keep, never its pictures or words. What comes back is only a proposal: it changes nothing until a person on our team approves it, and our software refuses one that quotes words or names a price. Once approved, your look is part of your brand profile, and while the look engine is on, each draft's request carries it and asks for a brief for the post's picture that follows it. While the look engine is off, none of this is sent.

Anthropic's terms, which we checked on 13 August 2026: it keeps request data for 30 days by default (longer, up to two years, for content its safety systems flag); we have not enabled its zero-retention option; it does not train models on customer content; it assigns the rights in its output to us, and what you receive from us is governed by our Terms of Service; and a data processing agreement is in place. Anthropic uses its own subprocessors, listed at https://trust.anthropic.com/subprocessors.

Other companies that process your data

  • Vercel hosts the website and runs the scheduled jobs. Our hosting provider keeps request logs briefly for operations.
  • Supabase hosts our database and file storage. Our database provider keeps short-term backups for disaster recovery, which age out on their own.
  • Resend delivers our transactional email. Today the only email the service sends you is the password-reset message, which contains your email address, your first name if we have it, and a one-hour reset link. When email updates are switched on, you can also choose to be emailed when a post is waiting for your decision, when a connection needs reconnecting, or when a report is ready. Each is off until you turn it on, contains your email address and a link but never your posts' words, and has a link that stops them all.
  • Stripe handles billing. When you subscribe, we send Stripe your account ID and plan; Stripe collects your card details and billing email on its own checkout page. We store only Stripe's customer and subscription IDs, your plan, and its status, and on the new plans how many posts you have used and each extra post we bill. We never see or store card numbers.
  • Meta is the source of your Instagram and Facebook posts, as described above. When you connect Instagram, the only thing we send Meta is a random one-time code that lets us match its reply to your Connect click; your name, email, and answers never go to Meta.
  • X is the source of your X posts, as described above. When you connect X, the only things we send X are a random one-time code and a check value derived from a second one; your name, email, and answers never go to X.

Of these, Supabase, Vercel, and Anthropic are the only companies that would handle your Instagram and Facebook posts, and each processes them only to run our service for you.

We do not sell your data, share it with data brokers, or use it for advertising.

Analytics

We use Vercel Web Analytics to count page views. It sets no cookies and we send it no personal identifiers. Before a page view is sent, our code strips the query string and fragment from the URL, replaces the account identifier in operator-only admin routes with a placeholder, and drops password-reset pages entirely. We do not use Google Analytics, advertising pixels, or session recording.

Cookies

Our code sets one cookie, named sw_session, which keeps you signed in. It is HTTP-only, sent only to our site, marked secure in production, and expires after 14 days or when you sign out. While you connect Instagram, a second cookie named hs_meta_connect ties Meta's reply back to the Connect button you pressed; it lasts ten minutes and is deleted when you return. While you connect X, a cookie named hs_x_connect does the same for X's reply, holding the one-time codes that prove the reply answers your request; it too lasts ten minutes and is deleted when you return. We do not set advertising or tracking cookies.

How we protect your data

  • All traffic to the service is over HTTPS.
  • The Meta access token for your business is stored encrypted in our database, under a key that lives only in our hosting configuration on Vercel, once for each connection, and each copy is deleted the moment you disconnect that connection. Our own agency access token, used when our team connects an account for you, is held only as a server-side environment variable and is never written to the database.
  • Our requests to Meta are signed with our app secret.
  • Your imported posts and every other record are tied to your account in the database, and every query is scoped to that account.
  • Copied photos and videos, and uploads to your library, are kept in a private storage area, filed under your account, and are shown only through links our service signs for ten minutes at a time.
  • Only members of our team with operator access can open the admin tools.
  • To report a security problem, email ryan@f3strategy.com.
  • If we learn that your data was accessed without authorisation we will tell you, and Meta where the data came from Meta, as soon as practicable and as the law requires.

How long we keep data

Your account data, brand profile, drafts, and messages stay for as long as you have an account and until you ask us to delete them. We delete copied posts, and any copies of their photos and videos, when a connection is removed or an account closes. Disconnecting deletes the posts on the spot and the photos and videos usually within six hours; closing an account is done by a person on our team following a written internal procedure, and we confirm to you by email. When learning controls are switched on, Delete our copy on one post deletes its caption at once and its photos and videos usually within six hours; a record that the post existed, with none of its caption, photos, or videos, stays until the connection is removed or the account closes, so that later reads do not copy it again.

Uploads to your library stay until you delete them or your account is closed; deleting one stops its use at once and deletes its files. A file still uploading when you delete the item is deleted within a day.

Some records are kept longer by design:

  • The audit log, usage log, job history, and post history are append-only and are retained for accountability and billing integrity. The audit log can include the email address of a person who was removed from an account, and it records when an Instagram account or a Facebook Page was connected, synced, or disconnected, including the handle or Page name. It also keeps the public link of each post marked as published and, for drafts made before 12 September 2026, the occasion they were written for.
  • Material you pasted or exported to us keeps a copy of its text in an append-only history record. Posts read from Instagram or Facebook do not; for those, the only copies are the per-post records and any copied photos and videos, all of which we delete.
  • Used password-reset tokens are kept (as hashes) rather than deleted.
  • Billing records tied to Stripe are retained for accounting.
  • Stripe and Anthropic keep their own copies under their own retention (Anthropic: 30 days by default). Our database provider's short-term backups age out on their own.

Deleting your data

Disconnect on your Settings page deletes the posts we copied from that account and that connection's copy of the token at once, and the photos and videos copied from it usually within six hours. When the influence library is switched on, each upload in your library also has a delete button, which stops its use at once and deletes its files. When learning controls are switched on, each post in your library copied from Instagram or Facebook also has a Delete our copy button, which deletes its caption and the voice example made from it at once, and its copied photos and videos usually within six hours, keeping only a record that the post existed so that later reads do not copy it again; and anything in your library can be forgotten for learning, which keeps it but stops us learning from it until you undo it, whether for all learning or for one kind only, such as its words or its look. There is no delete button for your account. To delete your account, or anything without a button, email ryan@f3strategy.com. We follow a written internal procedure: our team disconnects any Instagram or Facebook connection, which deletes the copied posts and their copied photos and videos, then cancels billing, removes your login, and removes or overwrites your data. Any files you uploaded are deleted from storage as part of the same procedure. Records in the append-only lists above are retained. We acknowledge deletion requests within 5 business days and complete them within 30 days, and we confirm by email when the deletion is done, listing anything we kept and why. The full procedure is described at /legal/data-deletion.

Children

Handled Social is a business service and is not directed at anyone under 18. We do not knowingly collect information from children. If you believe a child has given us personal information, email us and we will delete it by the same process described under Deleting your data.

Changes to this policy

When we change this policy, we post the new version here with a new effective date. We do not email about changes.

Contact

ryan@f3strategy.com. Automated messages from the service (for example password resets) come from no-reply@handled.social, which does not accept replies.