CommunityDesk

Privacy Policy

Last updated: August 2026

CommunityDesk (“we,” “us”) is an AI community manager that helps creators and brands read, understand, and respond to the comments on their connected accounts. This policy explains what we collect, how we use it, and the control you have over it. We built CommunityDesk around a simple principle: your community’s data is yours.

Information we collect

  • Account information. Your email address and a securely hashed password when you create an account.
  • Instagram and Facebook data. Through Meta’s official APIs, and only with your authorization: the comments on your posts, the commenters’ public usernames, your posts’ captions and metadata, your account and post insights, and, where you run a keyword campaign, the direct messages CommunityDesk sends on your behalf and the replies people send back.
  • X data. If you connect X, the replies and mentions directed at your account, and the public handles that wrote them. Read-only.
  • Steam data. If you connect a game, its public Steam reviews. Read-only, and we do not store any Steam identity.
  • Content you provide. Brand-voice settings, saved knowledge-base answers, campaign messages you write, and example replies you add to train the drafting.
  • Usage data. Basic logs needed to operate and secure the service.

The permissions we request

When you connect Instagram, CommunityDesk asks Meta for four permissions. Each one maps to something the product does:

  • instagram_business_basic — your account and post details, so CommunityDesk knows whose comments it is reading.
  • instagram_business_manage_comments — reading comments, and posting the replies and hides you approve.
  • instagram_business_manage_messages — sending the direct message in a keyword campaign you set up, and reading the replies to it. CommunityDesk does not read your other conversations.
  • instagram_business_manage_insights — reach, views and similar figures, so a discussion can be measured against how many people actually saw the post.

Connecting X requests read-only scopes, and CommunityDesk refuses a connection if X returns a write scope it did not ask for.

How we use your information

We use the data above only to provide the service, specifically to:

  • Filter spam and sort comments by type and priority.
  • Group related comments into discussions and track them over time.
  • Draft reply suggestions in your voice for your approval.
  • Help you moderate approved hides and understand your community (sentiment, supporters, trends).
  • Post ordinary replies and perform one-off hides only when you approve them.
  • Apply a blocklist rule you configure. A rule set to remove deletes a matching comment from the connected platform automatically, and that platform action may be irreversible.
  • Send the message you wrote in a keyword campaign to people who comment the keyword you chose.

AI processing

To classify comments, group them into discussions, and draft replies, comment text and your brand-voice settings are sent to our AI providers (OpenAI and Anthropic) through their APIs. We do not sell your data, and we do not use your community’s content to train third-party AI models. Our AI providers process this content to return your result and do not use API content to train their models.

Ordinary replies are not published without your approval. The single exception is a keyword campaign, where you configure the keyword and message in advance. If you enable its public confirmation or personalization, CommunityDesk can publish that configured campaign response automatically when somebody asks for it.

Service providers

We use these companies to run CommunityDesk, and they may process your data on our behalf:

  • Vercel hosts the application and its servers.
  • Neon hosts the database where your posts, comments and settings are stored.
  • OpenAI and Anthropic process comment text as described above.
  • Stripe processes payments. Stripe never receives your community’s content.

Platforms and their policies

CommunityDesk’s use of information received from Meta’s APIs follows Meta’s Platform Terms and Developer Policies, and its use of X and Steam data follows theirs. We use the data from a connected platform solely to provide the features you connected it for. You can disconnect any platform at any time, which stops all further access to it.

Data retention and deletion

While a source remains connected, its history stays. It is not trimmed when you change plans, because a community you have been building for two years is not improved by forgetting the first eighteen months of it. If you reach your plan’s monthly reading limit, CommunityDesk pauses reading new comments; it does not delete old ones.

Disconnecting a platform removes CommunityDesk’s access immediately and hides its stored history. CommunityDesk retains that source’s imported posts, comments, and derived analysis for 90 days so you can reconnect without importing the same history again. After 90 days, that source data is deleted automatically. You can permanently delete it sooner from Settings. An explicit platform data-deletion request is handled immediately rather than waiting for the retention window.

You can delete individual items (comments, drafts, knowledge entries) in the app at any time. You can delete your whole account from Settings, which removes the account and its data across our database and cancels any subscription. You can also request deletion by email at privacy@tendco.app, and we will act on a verified request within 30 days.

If a commenter asks us to erase their information, we may ask them to prove control of the relevant platform handle. Once verified, we remove their comments, derived discussion membership, and quoted evidence across CommunityDesk, and prevent that handle from being ingested again.

A creator-configured blocklist can also remove a matching comment from Instagram or Facebook as it arrives. Removal happens on the connected platform, not only inside CommunityDesk, and may not be reversible. CommunityDesk keeps a limited activity record so the creator can see which rule acted.

Two honest caveats. Encrypted backups roll off on their own schedule rather than being edited, so deleted data can persist in a backup for a short period after it is gone from the live service. And we keep the minimum records we are legally required to keep, such as billing records for tax purposes.

Your rights

You can access, export, or delete your data. Leads and activity are exportable as CSV from within the app, account deletion is in Settings, and you can request a full export at the email above. Depending on where you live, you may have additional rights over your personal information; write to us and we will honour them.

Children

CommunityDesk is for business use and is not intended for anyone under 18. We do not knowingly collect personal information from children. CommunityDesk does read whatever public comments appear on your posts, and it has no way to know a commenter’s age; we treat that content as your community’s content and use it only as described here.

Cookies and sessions

We use a single secure, httpOnly session cookie to keep you logged in. We do not use third-party advertising or tracking cookies.

Security

Passwords are hashed, sessions are signed, and data is transmitted over encrypted connections. No system is perfectly secure, but we work to protect your data and to disclose incidents responsibly.

Changes

We may update this policy as the product evolves. Material changes will be reflected here with a new date at the top.

Contact

Questions or requests: privacy@tendco.app.