Privacy Policy
Multitool ("we", "us") is an advertising operations tool for Meta (Facebook and Instagram). It connects to the Meta Business assets you give it access to — Business Managers, ad accounts, Pages and linked Instagram accounts — and lets you review, edit, duplicate and report on the advertising in those accounts, and publish advertising into them at your instruction.
This policy states what we collect, why, how long we keep it, and how it is deleted.
1. Data we store
The Meta data you connect is stored on servers and storage we control. Performance history, campaign structure, creative files, posts and comments are retained so the Service can show history and compare periods. This data is used only to operate the Service for the account that granted access.
A small number of providers help us run it: Cloudflare carries and protects traffic to and from the Service, an object storage provider holds creative files, and Telegram delivers the notifications you switch on. Each processes this data only to provide that service to us, under written terms, and never for purposes of their own.
2. Data collected
Collected after Facebook Login, for the assets you select:
| Category | What it includes |
|---|---|
| Facebook profile | Your user ID, name and the email address on the account |
| Businesses and ad accounts | IDs, names, currency, time zone, status and spend limits |
| Billing activity | The payment events Meta reports for your ad accounts: charges, refunds, declined payments, the payment method as Meta describes it, and who made the change |
| Account activity | The change history Meta keeps for your ad accounts: what changed, when, and the name of the person who made the change |
| People in your Business Manager | Name, role and, where Meta reports one, the email address of each member |
| Campaigns, ad sets and ads | Names, objectives, budgets, schedules, targeting, bids, statuses, and the review and delivery status Meta reports |
| Ad creatives | Headlines, texts, links, call-to-action, and the image and video files |
| Datasets and audiences | Pixels and datasets in your Business Managers, custom conversions, and the audiences saved in your ad accounts — names, IDs and status |
| Performance metrics | Impressions, reach, clicks, spend, conversions and derived rates for advertising, and Page statistics — page views, post engagement, new followers, actions on the Page and video views — kept as history |
| Pages and Instagram | Page IDs and names, status, the linked Instagram business account, and the content on them — posts, photos, videos, albums and lead forms |
| Comments | The comment text, and the commenter's name and platform-scoped ID |
| Access tokens | Issued by Meta for the profiles and Pages you connect. Stored encrypted, never displayed or shared |
We do not request or store card numbers, bank credentials, the content of lead forms, private messages, friend lists, or any Meta data outside the permissions you granted.
3. Permissions requested
The Service requests these permissions and no others:
| Permission | Why we need it |
|---|---|
ads_management |
To show your campaigns, ad sets and ads and to change them at your instruction — statuses, budgets, schedules, targeting and creative fields — including duplicating an existing ad and uploading creative images and videos into your own ad account |
ads_read |
To read the performance figures for those objects: impressions, reach, clicks, spend and conversions |
business_management |
To list the Business Managers you belong to, the ad accounts, Pages and datasets inside them, and the people who have access to them — and to change that access at your instruction |
pages_show_list |
To list the Pages you manage, so you can choose which of them the Service works with |
pages_read_engagement |
To read comments and reactions on your Page posts and on the posts used in your advertising |
read_insights |
To read the statistics of the Pages you connect and their posts: page views, post engagement, new followers, actions on the Page and video views |
pages_read_user_content |
To read comments left by other people, which is what the moderation features act on |
pages_manage_engagement |
To reply to, hide, unhide and delete comments, at your instruction or through moderation rules you configure |
pages_manage_metadata |
To receive Meta's real-time updates for your Pages, so new comments and changes reach the Service promptly |
pages_manage_posts |
To publish a post to a connected Page at your instruction |
pages_manage_ads |
To work with advertising associated with a Page, including ads that promote a Page post |
instagram_basic |
To find the Instagram business account linked to a connected Page and identify its media |
instagram_manage_comments |
To read and moderate comments on that Instagram account's media |
public_profile |
To know which Meta identity is connected: your user ID and name |
email |
To contact you about the Facebook account you connected, and to tell your connected profiles apart |
4. Purposes
To display your advertising and its results; to make the changes you ask for; to run the automated rules you configure; to moderate comments; to send the notifications you switch on, which are delivered through Telegram; and for security and troubleshooting.
We never sell, rent or license your data, and never share it with advertising networks, data brokers or other customers, except where the law requires disclosure. We never use it for advertising targeting, or to build or augment profiles of people. We never change anything in your Meta assets on our own initiative: every change is one you asked for, or one your own automated rules produced.
5. AI connections
If you connect an AI assistant to Multitool, it reads the Meta data in your workspace on your behalf, under the access you grant it. You choose whether to connect one, and you can disconnect it at any time. We never send your data to an AI provider on our own initiative, and we never use your data to train AI models.
6. Retention and deletion
You may request deletion at any time by writing to [email protected]. We delete it promptly.
Full instructions: Data Deletion.
7. Contact
Multitool — [email protected]
Use the same address to request support or to report a security vulnerability in the Service. We address reported issues promptly.