Klaro DataУкраїнська

Privacy Policy

Effective from 2026-08-12

Klaro Data is an Instagram and Facebook analytics service. We show account owners how their content performs and keep a history of metrics that Meta eventually deletes. Below, in plain language: what data we take, why, where we keep it, and how to delete it.

1. Who processes your data

The data controller is GOVERLO MEDIA SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ, Aleje Jerozolimskie 89/43, 02-001 Warszawa, Polska.

NIP: [NIP], KRS: [KRS].

The service runs at app.klarodata.com. For any data-related question write to goverlofounder@gmail.com — this is the primary and fastest channel.

If you are a client of an agency that uses the service on your behalf, we act as a processor for your account data and your agency is the controller. In that case a data processing agreement applies between us.

2. What data we receive from Meta

When you click “Connect Facebook” and grant permissions, we receive through the official Meta Graph API only what analytics requires:

  • Account metrics: reach, views, interactions, follower count and its changes, profile visits, website clicks.
  • Posts and Reels: caption text, thumbnail, permalink, publish date and their metrics — reach, views, likes, comments, saves, shares, and for Reels watch time.
  • Stories: reach, views, replies, exits, taps forward and back. We capture these before a story expires, because after 24 hours Meta no longer provides them at all.
  • Audience demographics — AGGREGATED ONLY: how many people are in an age group, by gender, by city or country. These are counts per group. We do not and cannot receive a list of your followers, their names, profiles, or anything identifying an individual person.
  • Technical connection data: identifiers of your Facebook Page and Instagram business profile, your app-scoped user ID, and the access token.

3. What we do NOT collect

  • Private messages — neither Instagram Direct nor Messenger. We do not request such permissions.
  • Personal data of your followers: names, profiles, emails, phone numbers, lists of who liked or followed.
  • Payment data: card numbers, bank details. We neither accept nor store them.
  • Your Facebook or Instagram password. Connection goes through Meta’s official dialog — the password is entered on Meta’s side and we never see it.
  • Ad accounts and advertising spend — the service works with organic analytics only.

4. Why we need this data (legal basis)

One purpose: to show you clear analytics of your own account and to preserve its history.

  • Displaying dashboards, reports and charts to the account owner and people they grant access to.
  • Metric history. This is the core reason the service exists: Meta keeps metrics for a limited period, and stories for only 24 hours. Miss the window and the data is gone forever. We take our own daily snapshots so you can look back a year.
  • Technical operation: sync logs, alerts about failures and expired tokens.

Legal basis: Art. 6(1)(b) GDPR (performance of a contract with you) and Art. 6(1)(f) GDPR (our legitimate interest in operating and securing the service).

We do not sell your data, do not share it with ad networks, data brokers or any third parties for their own purposes, and do not use it to profile individuals.

5. Artificial intelligence

The service has a separate AI post-analysis feature. It runs ONLY when you press the button — there are no background calls.

If you use it, the post’s caption, metrics and thumbnail are sent to an Anthropic (Claude) model to produce the analysis. No follower personal data goes there, because we do not hold any.

If you prefer not to send post content to an external service, simply do not use this feature; the rest of the analytics works without it.

6. Where and how data is stored

Data lives in our own PostgreSQL database on a server in the European Union — in Germany (Hetzner data centre, Nuremberg). We do not transfer data outside the EEA, except for the AI analysis described above, which you trigger yourself.

Access tokens are stored encrypted only — AES-256-GCM, with the encryption key held separately from the database. Tokens are never displayed in any interface or written to any log.

Only authorised staff of the controller can access the database, and only to the extent needed to operate the service.

7. How long we keep data

For as long as you use the service — that is the whole point of metric history.

After an account is disconnected (you removed the app in Facebook or stopped using the service) we stop collection immediately and delete the access token; the remaining data is deleted within 30 days.

Those 30 days are deliberate: disconnections are often accidental or temporary, and deleting history immediately would make it unrecoverable — Meta no longer has it either.

Want it deleted sooner? Write to us and we will do it right away.

8. Your rights under GDPR

  • Access — find out what data we process about you and get a copy.
  • Rectification — correct inaccurate data.
  • Erasure (“right to be forgotten”) — have your data deleted.
  • Restriction of processing.
  • Portability — receive your data in a machine-readable format (JSON/CSV) or have it transferred to another controller.
  • Object to processing based on legitimate interest.
  • Withdraw consent at any time — this does not affect the lawfulness of processing before withdrawal.

To exercise any right, write to goverlofounder@gmail.com. We respond within 30 days at the latest.

If you believe we are infringing your rights, you may lodge a complaint with the supervisory authority: President of the Personal Data Protection Office (PUODO), ul. Stawki 2, 00-193 Warsaw, Poland, uodo.gov.pl.

9. How to delete your data

Option 1 — via Facebook. Settings & Privacy → Settings → Business Integrations → find Klaro Data → Remove. Facebook automatically sends us a deletion request; we execute it and return a confirmation code.

Option 2 — email goverlofounder@gmail.com with the subject “Data deletion”. Completed within 30 days, usually sooner.

You can check the status of a request sent via Facebook on our deletion status page, using the confirmation code you received: /data-deletion?code=…

Deletion is irreversible: the metric history we accumulated will be gone for good, because Meta no longer has it.

10. Cookies

We set only strictly necessary cookies: the login session and a short-lived security token during the Facebook connection flow (CSRF protection).

There are no advertising, analytics or tracking cookies. We do not use Google Analytics, Meta Pixel or similar tools. That is also why there is no cookie consent banner here — there is nothing to consent to.

11. Security and incident notification

Channel encryption (HTTPS), token encryption, restricted database access, access logs.

If a data breach occurs that poses a risk to your rights, we will notify PUODO within 72 hours and inform you, as GDPR requires.

Absolute security does not exist — but we deliberately collect as little as possible so that an incident has little to expose.

12. Children

The service is intended for businesses and social media professionals and is not directed at persons under 16. We do not knowingly collect children’s data.

13. Changes to this policy

If the policy changes materially, we will notify you in the service interface or by email at least 14 days before it takes effect. The date of the latest revision is always shown at the top of this page.