Skip to content

Data and privacy

MissLess acts on behalf of your product and, through it, on behalf of your customers. This page states what is stored and what happens to it, so you can write your own privacy documentation and choose a legal basis for the data you take from the inbox.

Data Stored Notes
Partner and workspace records Yes Names, external_id, timezone, settings, key hashes
Meta access tokens Yes, encrypted AES-256-GCM at rest, keys held separately from the database. Never returned by the API
Account metadata Yes Platform ids, usernames, display names, avatar URLs, scopes, status
Media Yes The file you uploaded, its dimensions and mime type
Posts Yes Captions, options, targets, results, permalinks, errors
Conversations and messages Yes Contact id, name and handle as exposed by Meta, message text, attachment URLs (hosted by Meta), timestamps
Events Yes The webhook payloads, for delivery, retries and GET /v1/events
API keys Hashed SHA-256. The plain key exists only in the creation response
Webhook secrets Yes, encrypted Shown once
Request logs Yes, short retention Key id, endpoint, status, timing. No bodies

Data is processed in the European Union.

  • Tokens, accounts, media, posts and inbox data are kept for as long as the workspace exists.
  • Events are kept long enough for the retry horizon and for catch-up polling.
  • Request logs are kept for operational troubleshooting and then discarded.
  • DELETE /v1/workspaces/:id disconnects every account, removes the tokens, and deletes the workspace’s posts, media, conversations, messages and embed sessions. It is not reversible.
  • DELETE /v1/accounts/:id removes that account’s token and metadata. Posts and conversations that referenced it keep their history.
  • DELETE /v1/media/:id removes the file.
  • Deleting a partner removes all of the above for all of its workspaces.

Meta-initiated deauthorization and deletion

Section titled “Meta-initiated deauthorization and deletion”

When a user removes the MissLess app from their Facebook settings, Meta notifies MissLess. The affected accounts move to revoked, their tokens are discarded, and you receive account.disconnected for each. When a user files a data deletion request through Meta, MissLess deletes the tokens and account records tied to that Facebook user and reports the deletion back to Meta as required.

Content already published on Facebook or Instagram is never deleted by MissLess. Nothing in this API deletes on the network.

Messages and comments are written by people. They carry names, handles, and whatever those people chose to type, which can include contact details, health information or anything else. By reading the inbox through the API, the widget or MCP, and by receiving message.received and comment.received webhooks, your product processes that data.

You are responsible for your own legal basis and your own obligations toward those people: informing them where required, honouring access and deletion requests for copies you hold, and not using the content for purposes they would not expect. MissLess processes it on your instructions to provide the service and does not use it for anything else.

If you do not need the inbox, do not subscribe to its events and do not mint sessions with the inbox surface. Less data is easier.

  • Keep partner keys and webhook secrets server-side and rotate them when staff changes.
  • Only mint embed sessions and workspace keys for workspaces the signed-in user is entitled to.
  • Delete workspaces when customers leave.
  • Show your users, in your own terms and privacy policy, that Facebook and Instagram features are provided through MissLess, and what data flows where.
  • Comply with Meta’s platform terms for the features you expose. Publishing and messaging on a user’s behalf is what those terms govern.

Questions about data handling, a processing agreement, or an incident: reach MissLess through the contact details on social.missless.tel.