Meta Compliance Statement
Last updated: July 17, 2026
Our Commitment
AIworX is built to comply with Meta's platform policies and terms. We understand that maintaining compliance is essential to protecting our users and ensuring the continued availability of our service on Meta's platforms.
This page describes how AIworX complies with the Meta Platform Terms, Instagram Platform Policy, and Facebook Developer Policies.
Meta Platform Terms Compliance
Data Protection
- We collect and process data only as described in our Privacy Policy
- We obtain explicit user consent before accessing Facebook and Instagram data
- We implement appropriate technical and organizational measures to protect user data
- We do not sell user data to third parties
- We support user data access, portability, and deletion requests
Transparency
- Our Privacy Policy clearly describes what data we collect and how we use it
- We provide clear information about our data practices to users
- We maintain a public-facing data deletion page and callback endpoint
- We respond to Meta's data deletion requests within the required timeframe
Security Requirements
- All data is transmitted over HTTPS with TLS 1.2+
- Access tokens are encrypted before storage
- Passwords are hashed using bcrypt
- We maintain appropriate access controls
- We conduct regular security assessments
Instagram Platform Policy
Permitted Use
- AIworX is used to manage Instagram Business accounts on behalf of account owners
- We access only the data and permissions explicitly granted by the user
- Our features are designed to enhance business communication, not to spam users
- We comply with Instagram's Community Guidelines and Terms of Use
Data Usage
- We only use Instagram data to provide the features requested by the user
- We do not use Instagram data for advertising, marketing, or profiling purposes
- We do not transfer Instagram data to third parties except as required for service delivery
- We do not combine Instagram data with data from other sources
Automation Practices
- We do not post content to Instagram without explicit user configuration
- We do not send bulk unsolicited messages
- We respect rate limits imposed by the Instagram Graph API
- All messages sent through AIworX are sent on behalf of the account owner
- Users have full control over what messages are sent and when
Facebook Developer Policies
Platform Integrity
- We do not misrepresent our identity or purpose
- We do not create fake or misleading user experiences
- We do not artificially inflate engagement metrics
- We do not facilitate deceptive behavior
Content Policies
- We do not allow user-generated content that violates Facebook Community Standards
- We do not generate or distribute spam
- We do not facilitate the distribution of misinformation
- We do not allow hate speech, violence, or harassment through our platform
Data Protection
- We only request permissions necessary for our features to function
- We provide clear descriptions of why we need each permission
- We support the Facebook data deletion callback
- We maintain accurate privacy and data deletion documentation
No Spam
AIworX has strict anti-spam policies:
- We do not send bulk unsolicited messages
- All messages sent through AIworX are triggered by user-initiated conversations or configured automation rules
- Users can configure frequency limits and quiet hours for automated responses
- We monitor message delivery patterns and flag potential spam behavior
- Accounts identified as sending spam may be suspended or terminated
- We comply with all applicable anti-spam laws and regulations
No Unauthorized Automation
AIworX is designed to automate only with proper authorization:
- All automation requires explicit user configuration and approval
- We do not automate actions that the user has not specifically requested
- We do not create fake engagement or interactions
- We do not circumvent Instagram's rate limits or platform restrictions
- Users can disable automation features at any time
- We respect the 24-hour messaging window for Instagram
No Scraping
AIworX does not engage in data scraping:
- We access Instagram data only through official Meta APIs
- We do not use web scraping, crawling, or any unauthorized data collection methods
- We do not store or aggregate public Instagram data beyond what is needed for service delivery
- We do not provide data aggregation or analytics services on Instagram data
- All data access is conducted within Meta's API rate limits and terms
No Credential Collection
AIworX does not collect or store user credentials:
- We do not ask for or store Instagram or Facebook passwords
- Authentication is handled exclusively through Facebook's OAuth flow
- We only receive and store access tokens with user consent
- Access tokens are encrypted and can be revoked at any time
- We do not have the ability to access user accounts without proper authorization
Permissions We Request
AIworX requests only the permissions necessary for its features to function:
| Permission | Purpose |
|---|---|
| instagram_basic | Read Instagram account profile information |
| instagram_manage_messages | Read and send Direct Messages on behalf of the user |
| instagram_manage_comments | Read and reply to comments on user's posts |
| pages_show_list | Access Facebook Pages connected to the Instagram account |
| pages_messaging | Send and receive messages through connected Facebook Pages |
All permissions are requested during the Facebook Login flow and can be reviewed by the user before granting access.
Data Deletion Compliance
AIworX supports Meta's data deletion requirements:
- We implement the User Data Deletion Callback endpoint as required by Meta
- We process deletion requests within 30 days
- We provide a confirmation code for each deletion request
- Users can request deletion through their dashboard, by email, or through Facebook's interface
- Deleted data is permanently removed from all systems, including backups
For technical details about our deletion callback, see our Data Deletion Callback Documentation.
App Review Submission
AIworX has been designed and built to meet Meta's App Review requirements. Our submission includes:
- Complete and accurate app description
- Detailed permission justification for each requested permission
- Privacy Policy URL: /privacy
- Data Deletion Instructions URL: /delete-data
- Data Deletion Callback URL:
/api/meta/delete-user-data - Demonstration of all requested permissions in use
- Explanation of how each permission is used in the user experience
Compliance Monitoring
We continuously monitor and update our compliance practices:
- Regular review of Meta's platform policy updates
- Monitoring of API changes and deprecations
- Internal audits of data handling practices
- Training for development and operations teams on platform policies
- Proactive identification and resolution of potential compliance issues
Contact
If you have questions about our Meta compliance practices, please contact us: