Privacy Policy
Last updated: September 8, 2026 · Effective immediately (Version 2026-09-08.1)
Our Core Privacy Commitments
- ✓Facebook-only collection scope: Scans are initiated locally by your browser strictly for Facebook groups configured in your campaigns.
- ✓Explicit user consent is required before any browser-directed post ingestion or processing begins.
- ✓Human-in-the-loop: AI generates qualification scores and draft replies for your review; we never post autonomously or send unattended messages.
- ✓We never request, store, or transmit your Facebook login credentials or passwords.
- ✓Full workspace control: You retain complete ownership and can delete campaigns, leads, or request a total account data purge at any time.
1. Overview & Service Scope
Group Watcher (“we”, “our”, or “us”) provides social lead intelligence software. This Privacy Policy describes how we collect, use, store, and share your personal and operational information when you visit our website, use our SaaS dashboard, or install and operate our Chrome browser extension (collectively, the “Service”).
Exclusive Facebook Scope: This beta release of the Service operates strictly and exclusively with Facebook. Other social networks (such as Reddit or Nextdoor) are not active, supported, or scanned by the Service.
User-Initiated Operation: The Service does not deploy autonomous cloud bots to scrape the web independently. Scanning is directed and executed locally by your browser extension under your explicit authorization, utilizing your browser session only for groups you explicitly designate.
2. Explicit User Consent
We require your explicit consent before enabling browser-driven post ingestion or AI evaluation. When you accept our terms, configure campaigns, and connect the Chrome extension, we record your consent version and timestamp alongside your account profile. You may revoke consent at any time by pausing your campaigns, disabling the browser extension, or requesting account deletion.
3. Information We Collect
We collect and process information in the following distinct categories:
- Account & Authentication Information: Name, email address, profile avatar, and secure authentication tokens managed through our authentication partner, Clerk.
- Workspace & Campaign Configuration: User-configured Facebook group URLs and identifiers, target keywords, negative filters, business descriptions, and AI qualification instructions.
- Ingested Post Metadata: When the extension scans groups you configured, it captures visible post metadata—including post text, author display names, publication timestamps, and canonical post permalinks. This metadata is transmitted over encrypted channels to our backend for keyword matching and AI relevance scoring.
- Operational Receipts & Diagnostics: Cryptographic scan receipts (request IDs, payload hashes, post counts), extension heartbeat signals, batch ingestion statuses, error logs, and billing snapshot records.
4. Browser Extension Operation & Permissions
Our Chrome extension operates directly in your local browser instance. It uses your active Facebook session to view and extract posts from groups you have explicitly added to active campaigns. The extension:
- Never reads or logs passwords: We never inspect or store your login passwords, private credentials, or payment details entered on third-party sites.
- No access to private personal data: The extension does not access your personal timeline, friends lists, direct messages (Messenger), or groups outside your active campaign configuration.
- Enforces minimal necessary permissions: Required permissions (such as
storage,cookies,activeTab,scripting, andalarms) are strictly restricted to validating your session, scheduling scan intervals, and reading post feeds on user-selected Facebook groups.
5. How We Use Your Information & Human-in-the-Loop AI
We process your data for the following specific purposes:
- Matching ingested group posts against your campaign criteria and presenting qualified opportunities in your unified lead dashboard.
- Executing server-side AI evaluation to assess lead relevance, intent, and sentiment.
- Draft Suggestions Only (No Autonomous Posting): The Service generates AI-assisted reply drafts to help you respond quickly. The Service never posts comments, sends direct messages, or takes any autonomous action on social platforms. All communication requires your manual review, customization, and explicit submission.
- Providing idempotent scan receipts, run audit logs, and watcher health diagnostics.
- Managing subscription entitlements, authenticating sessions, and preventing fraudulent or abusive activity.
6. Data Retention Parameters & User Control
We retain data only as long as necessary to fulfill the Service and your workspace needs:
- Campaign Posts & Leads: Ingested posts and qualified leads remain accessible in your workspace for as long as your account is active, or until you explicitly delete them using dashboard tools.
- Scan Receipts & Run Execution Logs: Cryptographic scan receipts and batch run logs are retained for 30 days to verify delivery idempotency and quota accounting, after which they are systematically expired.
- Account Deletion & Data Purge: You may request full workspace deletion at any time via your account settings or by contacting our privacy team. When an account deletion is initiated, all campaigns, scraped posts, leads, AI drafts, and associated identifiers are permanently and irreversibly wiped from our production database within 30 days.
7. Third-Party Service Providers
We work with select third-party sub-processors to deliver core infrastructure and capabilities:
- Clerk: Identity management, user authentication, and session verification.
- Convex: Cloud database, serverless business logic, and real-time data sync with TLS/SSL in-transit encryption and AES-256 at-rest encryption.
- AI Model Providers: Commercial LLM APIs (such as Anthropic and OpenAI) used for evaluating relevance and generating reply suggestions. Data transmitted to AI providers via enterprise APIs is not used to train public foundation models.
- Polar.sh: Merchant of record and subscription billing management.
- Brevo: Transactional email delivery for real-time lead notifications.
8. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy, your consent settings, or your data rights, please contact:
Group Watcher Privacy & Data Protection
Email: privacy@groupleadsai.com