Privacy Policy
Last updated: September 23, 2026 · This policy applies to the "BetaCode" Facebook comment auto-reply platform, available at https://connect.beta-code.org. اقرأ بالعربية
- 1. Who we are and the scope of this policy
- 2. Information we collect
- 3. How we use information
- 4. Legal basis for processing
- 5. How we share information
- 6. Data retention
- 7. Data security
- 8. Your rights as an account holder
- 9. Rights of people who comment on your posts
- 10. Children's privacy
- 11. Cookies
- 12. Where data is hosted
- 13. Changes to this policy
- 14. Contact us
1. Who we are and the scope of this policy
This platform is operated by BetaCode (https://beta-code.org). The platform lets owners of Facebook business Pages connect their Pages and configure "campaigns": a specific post paired with a set of pre-written reply texts. The platform then monitors new comments on that post and sends one of the reply texts, chosen at random, as a private Messenger reply to each commenter, using Facebook's official Private Replies API.
This Privacy Policy explains what information we collect, from whom, why we collect it, and how we use, protect, and retain it — whether you are a subscriber who uses the platform directly, or a person who comments on a post managed by a Page connected to the platform.
2. Information we collect
a. Information you provide directly when creating an account:
- Your full name and email address, used to sign in and to contact you about your account.
- Your password, which is never stored in plain text — it is hashed with the bcrypt algorithm before being saved to the database.
- Your payment history (payment method, transaction reference number, amount where available, and verification status), used to prove that your subscription was activated.
b. Information we receive from Facebook when you connect your Page (Facebook Login):
- The ID and name of the Page or Pages you choose to connect to the platform.
- A Page Access Token for each connected Page, used exclusively to read comments on that Page's posts and to send private replies on its behalf.
We never request or receive your Facebook account password. Logging in and granting permissions happen entirely through Facebook's own official login window.
c. Information about people who comment on your posts:
- The Facebook User ID of the person who left the comment.
- The comment ID, the comment text itself, and its posting date.
We collect this information only to the extent necessary to identify who should receive the private reply, and to prevent sending more than one reply to the same comment. We do not collect phone numbers, prior private messages, or any other data from the commenter's account.
3. How we use information
- To operate the auto-reply service itself: reading new comments on the posts you specify, selecting a random reply text from your list, and sending it as a private Messenger reply to the commenter.
- To manage your account: authentication, and displaying your campaigns, connected Pages, and subscription status.
- To verify payments and activate or renew your subscription.
- To contact you about your account or our service when necessary.
- To protect the platform from abuse and fraud, and to validate incoming requests (such as verifying webhook signatures).
We do not use Facebook data for any advertising purpose, and we do not sell or rent any personal data to any third party, consistent with Meta's Platform Terms.
4. Legal basis for processing
We process account holders' data to perform the contract between us (providing the auto-reply service in exchange for a subscription fee) and based on the explicit consent you grant through Facebook's own permission window when connecting a Page. Data about commenters is processed on the basis of the Page owner's legitimate interest in responding to engagement with their own posts, and only to the minimum extent necessary to do so.
5. How we share information
We do not share your data with any party, except in the following cases:
- Facebook/Meta: to the extent necessary to operate the platform's features (reading comments and sending replies through Facebook's official APIs).
- Our payment gateway provider: we send it only the transfer reference number and the amount, in order to verify a payment. We do not share any of your other personal data with it. The identity of our payment gateway provider is confidential and is not disclosed publicly.
- Hosting and infrastructure providers that the platform runs on, who are bound to keep data confidential.
- When required to comply with a valid, binding legal request from a competent authority.
6. Data retention
- Your account data is kept for as long as your account remains active on the platform.
- The log of processed comments (kept to prevent duplicate replies) is automatically deleted when the related campaign or account is deleted.
- Page access tokens are deleted immediately when a Page is disconnected from the platform.
- When you delete your account (see Data Deletion Instructions), all associated data is deleted within a maximum of 30 days, except where retention is required for accounting or legal purposes.
7. Data security
- Passwords are hashed with bcrypt and are never stored as plain text.
- Access to Facebook and payment gateway settings is restricted to the general manager account only; no other account, including other administrator accounts, can view it.
- Every incoming Facebook webhook request is verified against its digital signature (HMAC SHA-256) before it is processed, to prevent spoofing.
- Sessions are managed using a signed access token (JWT) stored in an HttpOnly cookie that cannot be read by any script running in the browser.
8. Your rights as an account holder
You have the right, at any time, to:
- Access the data associated with your account.
- Disconnect any Facebook Page or delete any campaign directly from your dashboard.
- Request correction of your data if it is inaccurate.
- Request permanent deletion of your account and all its data — see Data Deletion Instructions for details.
9. Rights of people who comment on your posts
If you comment on a post managed by a Page connected to this platform, the data we process about you (your Facebook account ID and your comment text) is used for one purpose only: sending a single private reply via Messenger. We do not retain any reply you may send back, and we do not use your data for any other purpose. If you would prefer not to receive an automated reply in the future, you can contact the Page owner directly, or reach us at privacy@beta-code.org.
10. Children's privacy
This platform is intended for business owners and is not directed at children. We do not knowingly collect data from anyone under the age of 13. If we become aware that we have inadvertently collected such data, we will delete it promptly.
11. Cookies
We use a single cookie that is strictly necessary for the platform to function (your login session). It is protected and cannot be read by JavaScript, and we do not use any tracking or third-party advertising cookies.
12. Where data is hosted
Platform data is stored on servers operated by BetaCode or by trusted hosting providers it works with, using reasonable measures to protect data in transit and at rest.
13. Changes to this policy
We may update this policy from time to time to reflect a material change in the service or in legal requirements. Any update will be posted on this page along with the "last updated" date above, and we will notify you of any material change via the email address registered to your account.
14. Contact us
If you have any question about this policy or your data, you can reach us at:
BetaCode
Email: privacy@beta-code.org
Website: https://beta-code.org