Privacy policy

This explains what Keyward reads from your Instagram and Facebook accounts, why, how long we keep it and how you delete it. We wrote it to be read, so it's plain English.

Last updated September 25, 2026

Who we are

Keyward is a web app at getkeyward.pages.dev. It sends an automatic private message to people who comment a chosen keyword on an Instagram professional account or a Facebook Page. In this policy, "we" means the team that runs Keyward, and "you" means the person who connects an account.

Keyward is an independent product. It isn't made by or affiliated with Meta.

What we collect

From you, the account owner

  • Account details from Meta. When you log in, Meta gives us your Instagram or Facebook user ID, username or name, and profile picture link. For Facebook, it also gives us the list of Pages you chose to share with us.
  • Access tokens. Meta gives us a token that lets Keyward act on the accounts you approved. We encrypt it before we store it.
  • Your campaigns. The keywords, messages, links and post choices you set up.
  • Contact form messages. Your name, email and message if you write to us.

About the people who comment on your posts

  • Comments that come in through Meta's webhook. We check each new comment on your connected account for your keyword. We don't store the text of comments that don't match.
  • A message log for matching comments. For each comment that matches, we store the commenter's ID and username as Meta provides them, the comment ID, the comment text, which campaign matched, and whether the message was sent. This is the DM log you see in the app.
  • Replies to your messages. If a campaign uses reply first, we note that the person replied so we can send the follow-up link. We don't keep the text of their reply.

We don't collect passwords, payment details, contact lists, or anything from accounts you haven't connected. We don't use advertising trackers or analytics cookies.

Meta permissions

Keyward only asks for the permissions it needs. Here's each one and what we do with it.

PermissionWhat we use it for
instagram_business_basicShow your Instagram username, profile picture and recent posts in the app, so you can pick which post a campaign runs on.
instagram_business_manage_commentsReceive new comments on your posts so we can check them for your keyword, and post the optional public reply you wrote under a matching comment.
instagram_business_manage_messagesSend the private reply you wrote to the person who commented your keyword, and the follow-up link when they reply.
pages_show_listShow the Facebook Pages you manage so you can choose which ones to connect.
pages_manage_metadataSubscribe your Page to comment and message notifications, and remove that subscription when you disconnect.
pages_read_engagementShow your Page's recent posts and read new comments so we can check them for your keyword.
pages_messagingSend the private reply you wrote in Messenger to the person who commented your keyword, and the follow-up link when they reply.

How we use it

  • To run the campaigns you create: check comments for your keyword and send the message you wrote.
  • To show you your campaigns, your connected accounts and your DM log.
  • To tell you when something needs fixing, like an expired connection.
  • To answer you when you contact us.
  • To keep the service safe, for example by checking that webhook requests really come from Meta.

We don't sell your data or the data of people who comment on your posts. We don't use it for advertising, and we don't use it to train AI models. We only message people who commented your keyword, and only with the message you set up.

Who we share it with

We don't share personal data with anyone except the providers we need to run Keyward:

  • Meta Platforms. Messages and replies are sent through Meta's APIs, so Meta receives them.
  • Cloudflare. Keyward's website, app and database run on Cloudflare, which stores the data for us.

We'll also disclose data if the law requires it, and we'll tell you first when the law lets us.

How long we keep it

  • DM log entries: deleted automatically after 90 days.
  • Pending reply-first follow-ups: deleted after 7 days if the person never replies.
  • Access tokens: deleted the moment you disconnect the account, delete your workspace, or remove Keyward in Meta's settings.
  • Campaigns and account details: kept while your workspace exists, deleted when you delete it.
  • Contact form messages: kept up to 12 months so we can follow up, then deleted.
  • Deletion confirmations: we keep the confirmation code and date (no personal data) so you can check the status of a deletion request.

Security

Access tokens are encrypted with AES-256-GCM before they're stored. All traffic uses HTTPS. We check the signature on every notification Meta sends, and sign-in sessions use secure, HTTP-only cookies. Only the people who run Keyward can reach the database, and only to keep the service working.

Deleting your data

You can delete your data in any of these ways:

  • In Keyward: go to Settings and choose Delete workspace. We delete your tokens, accounts, campaigns and logs right away. To remove just one account, choose Disconnect next to it.
  • In Instagram or Facebook: remove Keyward from your connected apps. Meta tells us, and we delete that account's data automatically.
  • By asking us: use the contact form and pick "Delete my data."

The data deletion page has step-by-step instructions.

If you commented on a post from an account that uses Keyward and want your entry removed from that account's log, contact us and we'll delete it.

Your rights

Depending on where you live, you may have the right to see, correct, export or delete your personal data, or to object to how it's used. Contact us and we'll respond within 30 days. You can also complain to your local data protection authority.

Children

Keyward is for businesses and creators. It isn't meant for anyone under 18, and you need to meet Instagram's and Facebook's own age rules to connect an account.

Changes to this policy

If we change this policy, we'll update the date at the top. If a change affects how we use data you already gave us, we'll tell you in the app before it takes effect.

Contact

Questions about privacy go through our contact form. Pick "Privacy question" and we'll get back to you.