This is the plain-English version of our data-handling posture. It pairs with 'What Merge can and can't do' (which covers access) and our full Privacy Policy.
What we read from Meta
- Post insights — views, reach, retention, watch time — for your Instagram and Facebook posts.
- Post metadata — caption, media type, timestamp, likes, comments count, permalink.
- Community activity — comments and replies (to surface questions and possible leads).
- Message activity — DM/unread counts for your keyword-to-DM funnel (we read activity, not private message content beyond what's needed for that count).
- Follower and media counts for your Page and Instagram profile.
What we store
- The metrics above, so your reports and trends work over time (in our Supabase database).
- Your account profile and the advice Merge has given you (to prove it's working and improve next week's slate).
- Your login and a one-way hash of your access code — never the code itself, never your Meta password.
What we never store
- Your Meta password or login — access comes through Meta's partner system, not your credentials.
- Your full card number — payments are handled by Stripe; we only see the last four and the status.
How long we keep it
We keep your data while your subscription is active. If you cancel, we retain it for up to 90 days in case you return, then delete it — except records we're legally required to keep, like invoices.
How to get it deleted
- 1Email us to request deletion at any time — we'll remove your data.
- 2Or follow the steps on our Data Deletion page.
- 3To also cut off future access, remove Merge as a partner in Meta Business settings (see 'What Merge can and can't do').
Note · Full details are in our Privacy Policy and Data Deletion pages, linked in the site footer.