Privacy Policy
Last updated: May 2026
MediaTree (“we”, “our”, “us”) respects your privacy. This policy explains how we collect, use, and protect your personal data when you use our app or website.
1. Information We Collect
We collect the following types of information:
- Email address and display name (for account creation)
- Profile photo (optional)
- Campaign content you create (stored in Firebase)
- Anonymous usage analytics to improve the app
- Device information (OS version, device type) for crash reporting
We do NOT collect:
- Your AI API keys (stored locally on your device only)
- Payment card details (handled by Razorpay)
2. Facebook & Instagram Data
Permissions We Request
When you connect your Facebook account, we request only the permissions needed to post content on your behalf:
- pages_manage_posts — To publish posts to your Facebook Pages
- pages_read_engagement — To read basic page info
- instagram_basic — To access your Instagram account info
- instagram_content_publish — To publish posts to Instagram
- pages_show_list — To show your connected pages
What Data We Access
- Your Facebook Page name, ID, and profile picture
- Instagram Business account info
- Access tokens to publish content (encrypted and stored securely)
We do NOT access:
- Your personal Facebook profile posts or feed
- Friends list or contacts
- Private messages
- Any data beyond what is needed for posting
How We Use Facebook Data
- To publish social media posts, reels, and stories that YOU create and approve
- To display your connected pages/accounts in the app
- We NEVER post anything without your explicit action
- We NEVER share your Facebook data with third parties
Token Storage & Security
- Access tokens are stored encrypted in Firebase Firestore
- Tokens are linked only to your account
- Tokens are automatically refreshed to maintain connection
- Tokens are permanently deleted when you disconnect your account
Disconnecting Facebook
You can disconnect Facebook / Instagram at any time:
- 1. Open the app → Profile → Connected Accounts → Disconnect Facebook
- 2. Or visit: Facebook Settings → Apps and Websites → MediaTree → Remove
3. How We Use Your Data
- Provide, operate, and improve our services
- Publish social media content on your behalf (only when you authorize)
- Send important account and campaign notifications
- Process payments through Razorpay
- Enable campaign history and sync across your devices
- Analyze app usage to fix bugs and improve features
4. AI API Keys
Your API keys (Gemini, OpenAI, Groq, Claude, Grok, etc.) are stored ONLY on your device using secure local storage.
- They are NEVER transmitted to our servers
- All AI requests go directly from your device to the AI provider
- We have no access to your API keys at any time
5. Data Sharing & Third-Party Services
We work with the following third-party services:
- Firebase (Google) — Authentication & secure database
- Razorpay — Payment processing
- Meta (Facebook/Instagram) — For social media posting (only with your permission)
- Pollinations.ai — Image generation (no personal data shared)
- SerpAPI — Web research (only search queries, no personal data)
- AI Providers you select — Your prompts are sent to their APIs
Each third-party service has its own privacy policy. We do not sell your data to any third party.
6. Data Security
- Firebase Authentication for secure login
- Firestore security rules to protect your data
- HTTPS encryption for all network communications
- No storage of sensitive payment information on our servers
- Access tokens are encrypted and stored securely
7. Data Retention
- Account data: Retained until you delete your account
- Campaign data: Retained until you manually delete campaigns
- Facebook/Instagram tokens: Deleted immediately when you disconnect
- Analytics data: Retained for 12 months in anonymized form
You can request full data deletion by emailing: support@mediatree.ai
8. Your Rights
- Access your personal data at any time
- Correct inaccurate or incomplete data
- Delete your account and all associated data
- Disconnect Facebook/Instagram and revoke all permissions
- Export your campaign data
- Opt out of analytics tracking
To exercise any of these rights, contact us at support@mediatree.ai
9. Data Deletion Request
As required by Facebook's Platform Policy, you can request deletion of all your data associated with MediaTree.
To delete your data:
Open the app → Profile → Settings → Delete Account
Or email us at support@mediatree.ai with subject "Data Deletion Request"
Or revoke access via Facebook Settings → Apps and Websites
Upon receiving a deletion request, we will permanently delete all your personal data, campaigns, connected account tokens, and any Facebook/Instagram data within 30 days.
10. Children's Privacy
MediaTree is not intended for use by children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us immediately.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any significant changes via:
- In-app notification
- Email to your registered address
Continued use of the app after changes means you accept the updated policy.
12. Contact Us
For any privacy-related questions, requests, or concerns:
We aim to respond to all requests within 48 hours.