Skip to content
BossYou

Privacy Policy

This policy explains what personal data BossYou Media processes in BossYou Manager, why we process each kind, who we share it with, and how you can request deletion of your data.

Last updated: 19 August 2026 Effective from: 19 August 2026 Version: 1.0

Who we are

BossYou Manager is a social media management and agency delivery platform. The company responsible for the processing described here — the controller, in the language of Brazil's General Data Protection Law (LGPD, Law 13.709/2018) — is:

Legal name
BOSSYOU MEDIA AGENCIA DE MARKETING LTDA
Trade name
BOSSYOU MEDIA
Company ID (CNPJ)
63.457.122/0001-21
Address
Est. Doutor Cícero Borges de Morais, 1850, Andar 1, Vila Universal, Barueri/SP, ZIP 06.407-000, Brazil
Privacy email
itacontabilidade@terra.com.br
Phone
+55 11 4688-1953
Meta app
BossYou Manager · App ID 1371849647985190

Wherever this policy says “we”, “BossYou” or “the platform”, it refers to the company above and to BossYou Manager.

About this translation

The Portuguese version at bossyoumedia.com/privacidade is the canonical one. This English version is provided for convenience; in case of any discrepancy, the Portuguese text prevails.

The short version

A summary of what follows. Each point is detailed in its own section.

  • What we collect. Account details of the people who use the platform, service usage data, and data from the Facebook and Instagram accounts you connect — posts, performance metrics and comments.
  • Why we collect it. To deliver the service you hired us for: publishing, measuring results, responding to comments and producing reports. We do not sell personal data and we do not use it for advertising.
  • What we do with comments. We automatically classify the sentiment and topic of public comments. This runs on a local model inside our own infrastructure: comment text is not sent to any third-party AI service.
  • How to delete. Email itacontabilidade@terra.com.br. The step-by-step, what we erase and how long it takes are in How to request deletion of your data.
  • Cookies. This page uses no cookies and carries no trackers. The platform uses only what is needed to keep you signed in and to remember your interface preferences.

Who this policy covers

Three different groups of people have data processed by us, for different reasons. It is worth knowing which one you belong to, because your rights and how you exercise them differ slightly in each case.

1. The BossYou team
Employees and contractors who use the platform to produce client work.
2. Clients and their teams
People from client companies invited into a workspace — to follow the work, comment and approve deliverables.
3. The public interacting with our clients' pages
People who commented on or mentioned a Facebook Page or Instagram profile we manage. This group has no account with us and has likely never heard of BossYou — but their username and the text of their public comment reach us through Meta's APIs when the page is managed on the platform. We explain exactly what we store in What data we collect, on what legal basis in Why we process it, and how to request deletion in How to request deletion of your data.

What data we collect

a) Data you give us

  • Account and sign-up: name, work email, password (stored only as a hash, never in readable form), job title or role, and the organization you belong to.
  • Client company data: legal name, contacts, industry, notes and the relationship history recorded by the team.
  • Work content: projects, tasks, internal comments, approval requests and attached files (design pieces, videos, documents).
  • Content you publish: text, images and video you compose on the platform to be published to the connected networks.
  • Billing data: what is needed to invoice your plan. Payment itself is processed by Asaas — see Who we share it with.
  • What you write to us: support messages and requests sent by email or through our service channels.

b) Data collected automatically

  • Application access logs: IP address, date and time of requests, and the action performed. Keeping these for six months is a legal obligation under Brazil's Internet Civil Framework (Law 12.965/2014, art. 15).
  • Technical device data: browser type and version, operating system and language — sent by your own browser on every request on the internet.
  • Interface preferences: stored in your browser's local storage, on your own device. They are not sent to our servers. See Cookies and local storage.
  • Collection run records: date, time, outcome and row count of each sync with Meta, for troubleshooting.

We do not use third-party analytics tools, advertising pixels, tracking networks, or any profiling technology for advertising.

c) Data received from Meta (Facebook and Instagram)

When an authorized user connects a Facebook Page, an Instagram professional account or an ad account, we begin accessing data from those accounts through Meta's Graph API, within the permissions granted on the authorization screen. Specifically, we store:

Data obtained from Meta and stored by us.
Category What is stored
Connected account Page or profile ID, name, username and follower count.
Posts ID, date and time, permalink, caption, media type and post thumbnail.
Metrics Reach, interactions, follower change, profile visits and contact-button taps — as daily series, and per post.
Comments and mentions Comment ID, the commenter's ID and username, the comment text, date and time, like count, and whether the comment came from the account itself.
Comment classification The sentiment label (positive, neutral or negative), topic, confidence score and the model version that produced the label. See the section on classification.
Competitors Public follower, post and interaction counts of professional profiles nominated by the client for benchmarking. This is public data, obtained through Instagram's business discovery feature.
Access token The credential authorizing our calls to Meta on behalf of the connected account. See Security.
What we do not collect from Meta

We do not collect anyone's friend or follower lists, profile data about people who interact with the pages beyond their public username, private messages outside the authorized scope, or any sensitive data as defined in art. 5, II of the LGPD (racial or ethnic origin, religious belief, political opinion, union membership, health data, sex life, genetic or biometric data).

Meta permissions, one by one

When you connect an account, Meta shows the permissions we are requesting. The table below translates each of them: what it lets us read or do, and what for. We only request what the contracted functionality requires.

Permissions requested by BossYou Manager (App ID 1371849647985190).
Permission In plain language Type
pages_read_engagement Read your Facebook Page's content and engagement: posts, comments, reactions and Page information. This is what lets us build the performance report and show comments in the inbox. Read
pages_manage_posts Create, edit and delete posts on your Page. This is what lets us publish and schedule posts from the platform. Write
instagram_basic Read the linked Instagram professional account's profile — username, picture, follower and post counts — and the media published on it. Read
instagram_content_publish Publish photos, videos and reels to the Instagram professional account. Write
ads_read Read ad accounts, campaigns, ad sets and their results — spend, impressions, clicks and conversions — for paid media reporting. Read
ads_management Create and edit campaigns, ad sets and ads; pause and resume delivery; change budgets. Write
business_management See the assets in your Business Manager — Pages, Instagram accounts and ad accounts — so you can choose which ones to connect, and maintain those links. Read and manage

A write permission means the platform can act on your behalf within that scope — not that it acts on its own. Every publication, campaign change or deletion originates from an action by someone on your team or ours, and is recorded in the audit log with author and timestamp.

You can revoke these permissions at any time, directly with Meta, without going through us: on Facebook, under Settings & privacy → Settings → Apps and websites; on Instagram, under Settings → Apps and websites. Revoking stops our access immediately. It does not, by itself, erase data already collected — for that, see How to request deletion of your data.

Why we process it, and on what legal basis

The LGPD requires every processing activity to have a specific purpose and a legal basis (art. 7). One row per purpose, with the data involved and the basis that supports it.

Purposes, data processed and the corresponding legal basis.
What for Which data Legal basis (LGPD)
Create and maintain your account and access to the platform Sign-up details, credentials, organization and permissions Performance of a contract — art. 7, V
Deliver the contracted work: publishing, scheduling, ad management Post content, connected accounts, access tokens Performance of a contract — art. 7, V
Measure performance and produce client reports Page and post metrics, ad data Performance of a contract — art. 7, V
Read, organize and respond to comments and mentions on managed pages Comments, mentions, commenter username Legitimate interest — art. 7, IX (managing the page's public communication, over content voluntarily posted in a public setting)
Classify comment sentiment and topic Comment text Legitimate interest — art. 7, IX
Benchmark performance against competitor profiles Public metrics of professional profiles nominated by the client Legitimate interest — art. 7, IX
Bill the contracted plan and issue tax documents Billing and invoicing data Performance of a contract — art. 7, V; and compliance with a legal or regulatory obligation — art. 7, II
Keep access and audit records; prevent fraud and abuse Access logs, IP, date and time, action performed, author Compliance with a legal obligation — art. 7, II (Internet Civil Framework, art. 15); and legitimate interest in security — art. 7, IX
Provide support and answer requests Messages exchanged and contact details Performance of a contract — art. 7, V
Defend our rights in judicial or administrative proceedings Strictly what the case requires Regular exercise of rights — art. 7, VI

What we do not do. We do not sell, rent or trade personal data. We do not use client or public data for our own or anyone else's advertising. We do not build behavioural profiles of individuals for ad targeting. We do not use data collected through Meta's APIs to train general-purpose artificial intelligence models.

Automated classification of comments

So that reports show not just how many comments arrived but what the mood was, we automatically classify each public comment as positive, neutral or negative and assign it a topic (for example, price, delivery time or customer service).

Three things matter about how this works:

  • It runs locally. Classification is performed by a language model running on our own infrastructure. Comment text is not sent to any third-party AI service, is not used to train models, and does not leave our environment for this purpose.
  • It decides nothing about anyone. The label feeds an aggregate chart in a marketing report. It is not used to block, hide or moderate comments automatically, it does not set anyone's price or commercial terms, and it produces no legal effect or significant impact on the person who commented.
  • It makes mistakes, and we know it. No classifier is perfect, especially with irony and with comments mixing praise and complaint. That is why the label is always treated as an aggregate estimate, never as a judgement about a specific person.

Even so, art. 20 of the LGPD gives you the right to request review of decisions made solely on the basis of automated processing. If a comment of yours was classified and you want to contest it, write to itacontabilidade@terra.com.br: we will review the case and, if you prefer, remove the classification.

Who we share it with

We do not sell personal data. We share only what is necessary, with parties who need it for the service to work, and always under a contractual duty of confidentiality and purpose limitation.

Third parties that process data on our behalf or alongside us.
Who Role What they receive, and why
Meta Platforms Source of the data and independent controller Receives the requests we make on behalf of the connected account — including the content you publish through the platform. Meta's own processing is governed by its privacy policy, not by this one.
Asaas Processor Handles billing and payment for contracted plans (Pix, bank slip and card). Receives the data needed to issue and settle the charge.
Google Fonts Processor Delivers the typefaces used on this page and in the platform. When loading the font, your browser tells Google your IP address and technical request data — as with any resource loaded from another domain.
The contracting client company Recipient The reports, metrics and comments relating to its own accounts. This is the point of the service: the work is delivered to the client.
Public authorities Recipients Only on a court order, a request from a competent authority, or another legal obligation. In those cases we require the request to be formal and reasoned, and we comply strictly within its limits.

If BossYou ever goes through a merger, acquisition or corporate reorganization, data may be transferred as part of the business. In that case we will give prior notice, and the receiving party will be bound by the same commitments set out in this policy.

International transfers

Our operation and our data are in Brazil. There are, however, two unavoidable international transfers, both arising from third-party services:

  • Meta Platforms — calls to the Facebook and Instagram APIs are processed on Meta's infrastructure, mostly in the United States. This transfer is necessary for the performance of the contract you entered into with us (LGPD, art. 33, VI): without it, there is no social network integration.
  • Google Fonts — loading the typefaces sends technical request data to Google servers outside Brazil.

In both cases the transfer is limited to what is strictly necessary for the purpose. If we later start using cloud providers based abroad, we will update this section before the change takes effect and adopt the safeguards required by art. 33 of the LGPD.

How long we keep it

We keep each kind of data for as long as the purpose that justified it requires. After that it is deleted or anonymized — and anonymized data, which no longer identifies anyone, ceases to be personal data (LGPD, art. 12), so aggregate historical indicators may remain in reports.

Retention periods by category.
Category Period Why
Account and sign-up data While the account exists, and up to 6 months after closure To allow reactivation and settle outstanding matters
Meta access token While the connection exists Destroyed on disconnection, on revocation by Meta, or on a deletion request — whichever comes first
Collected posts and metrics 24 months To allow year-over-year comparison in reports
Comments, mentions and their classifications 24 months To track sentiment over time. The classification is deleted together with the comment
Projects, tasks, approvals and attachments For the term of the contract, and up to 12 months after it ends To evidence what was delivered and approved
Application access logs 6 months Legal obligation — Internet Civil Framework, art. 15
Audit records 5 years Accountability and incident investigation
Tax, accounting and contractual documents 5 years Legal obligation and tax limitation periods. These documents are not deleted on request

Security

No system is immune, and promising absolute security would be dishonest. What we can describe precisely are the measures we actually take:

  • Encrypted traffic. All communication with the platform and with Meta's APIs happens exclusively over HTTPS.
  • Credentials kept out of the codebase. Meta access tokens live in protected configuration files, outside the code repository and version control, readable only by the process that makes the calls.
  • Tokens never appear in logs. The API client automatically strips any token from log text and error messages before writing them. When a token fails, the error identifies the affected client — never the credential.
  • Per-client isolation. Every stored record mandatorily carries the identifier of the client it belongs to, and an automated check fails if any record is ownerless or points to a client that does not exist. Ownership of a record is never inferred from which credential fetched it.
  • Comment text processed locally. Sentiment classification runs on our own infrastructure, with no transmission to external services.
  • Restricted access. Only the team members who need to operate a client's account can access that client's data, and significant actions are recorded with author and timestamp.
  • Passwords. Stored only as a cryptographic hash. Not even we can read them.
If an incident happens

In the event of a security incident that may create relevant risk or harm to data subjects, we will notify Brazil's National Data Protection Authority (ANPD) and the affected people within a reasonable time, describing what happened, which data was involved and the measures taken — as required by art. 48 of the LGPD.

Found a vulnerability? Write to itacontabilidade@terra.com.br. We welcome responsible disclosure and take no action against anyone who reports in good faith.

Your rights

Art. 18 of the LGPD gives you the right, at any time and free of charge, to request:

  1. Confirmation that we process data about you;
  2. Access to the data we hold about you;
  3. Correction of incomplete, inaccurate or outdated data;
  4. Anonymization, blocking or deletion of unnecessary or excessive data, or data processed in breach of the law;
  5. Portability to another provider, upon express request;
  6. Deletion of data processed on the basis of your consent;
  7. Information about who we share your data with;
  8. Information about the option not to give consent and what follows from that;
  9. Withdrawal of consent, where consent is the basis for the processing.

On top of that, you may object to processing grounded in legitimate interest (art. 18, § 2) and request review of automated decisions (art. 20) — see Automated classification of comments.

How to exercise them

Write to itacontabilidade@terra.com.br with the subject “LGPD — [the right you want to exercise]”. Say what you are asking for and include the information that lets us locate your data (same list as the next section).

We will acknowledge within 5 business days and respond within 15 days of the request. If the case is complex and needs more time, we will explain why and give a new deadline before the first one expires.

We may ask for additional information to confirm your identity before acting. This is not bureaucracy: it is what stops someone else from accessing or erasing your data by pretending to be you.

How to request deletion of your data

Anyone can request deletion of their data — with or without an account with us, including people who only commented on a page we manage.

Here is how

Send an email to itacontabilidade@terra.com.br with the subject “Data deletion — BossYou Manager”.

What to include in the request

The more precise it is, the faster and more safely we can locate exactly your data.

  • Always: your full name and an email address for our reply.
  • If you use the platform: the email on your account and the name of the workspace or organization.
  • If you connected Meta accounts: which Facebook Pages, Instagram profiles or ad accounts are involved.
  • If you only commented on one of our pages: your Facebook or Instagram username and, if possible, the link to the post. Without it we cannot tell which comments are yours — it is the only key we hold.
  • Optional: tell us whether you want everything deleted or only part of it (for example, just the comments).

Timeline

We acknowledge within 5 business days and complete the deletion within 30 calendar days of the request, or explain in writing, within that window, why we cannot delete something — and which legal basis requires us to keep it.

What we erase

  • Your account, profile, credentials and workspace memberships;
  • Meta access tokens: we revoke the credential with Meta and destroy the copy we hold;
  • The asset connection: we disconnect the linked Pages, Instagram accounts and ad accounts, ending any future access;
  • The posts, metrics and comments we collected through that connection, and the sentiment classifications derived from them;
  • The comments and mentions attributed to your username, where the request comes from a member of the public who interacted with a page;
  • Projects, tasks, internal comments and attachments you authored;
  • Your support messages.

What we must keep, and why

The LGPD permits — and sometimes requires — retention of certain data even after a deletion request (art. 16). In our case:

  • Tax, accounting and contractual documents, for 5 years, as a legal obligation (art. 16, I);
  • Application access logs, for 6 months, as required by the Internet Civil Framework, art. 15 (art. 16, I);
  • Audit records of what was done on the platform, for as long as needed for accountability and the regular exercise of rights (art. 16, II and III);
  • Aggregate, anonymized indicators already incorporated into historical reports — figures that identify no one and therefore are no longer personal data (art. 12).

Outside those cases, deletion is permanent: data is removed from our active databases and from backup copies on the following backup rotation cycles.

Important: removing the app on Facebook is not enough

You can remove BossYou Manager at any time under Settings & privacy → Settings → Apps and websites on Facebook. That immediately stops our access to your accounts — and we recommend doing it.

But that removal alone does not erase the data we have already collected. To have it actually deleted, also send the email described above. That is what this page is: our app's data deletion instructions.

Cookies and local storage

This policy page uses no cookies and loads no trackers. The only request to another domain is the typeface loading — see Who we share it with.

On the platform, usage is equally restricted:

  • Strictly necessary cookies: keep you authenticated during the session and protect forms against forged requests. Without them, signing in is impossible. Because they are indispensable to the service you asked for, they do not depend on prior consent.
  • Local storage (localStorage): holds interface preferences — visual theme, active workspace and display settings. It stays on your device and is not sent to our servers. Clearing site data in your browser erases all of it.

We do not use advertising cookies, cross-site tracking, or third-party analytics tools. There is therefore nothing to decline in a consent banner — which is also why this page does not show one.

Children and teenagers

BossYou Manager is a professional tool intended for companies and for people over 18. We do not direct the service at children or teenagers and do not knowingly collect their data.

Public comments collected from client pages may occasionally have been written by a minor, without any way for us to know. If we identify, or are informed by a guardian, that we hold data of a child or teenager without the legal grounds required by art. 14 of the LGPD, we will delete that data as soon as possible. Parents and guardians can request deletion through the same channel described in How to request deletion of your data.

Changes to this policy

This policy may change when we launch new features, switch a supplier, or when the law requires it. When that happens:

  • We update the “Last updated” date and the version number at the top of this page;
  • For material changes — a new purpose, a new category of data, a new recipient or a longer retention period — we give notice by email and in-app at least 15 days before it takes effect;
  • Where a change requires consent, we will ask for fresh consent — earlier processing is not retroactively expanded.

The version in force is always the one published on this page, at https://bossyoumedia.com/privacy.

Data Protection Officer and contact

The Data Protection Officer (in Brazilian law, the encarregado) is the channel of communication between you, BossYou and the National Data Protection Authority, under art. 41 of the LGPD.

Data Protection Officer
BOSSYOU MEDIA AGENCIA DE MARKETING LTDA
Email
itacontabilidade@terra.com.br
Phone
+55 11 4688-1953
Address
Est. Doutor Cícero Borges de Morais, 1850, Andar 1, Vila Universal, Barueri/SP, ZIP 06.407-000, Brazil

Use this same channel for questions about this policy, to exercise any right under art. 18, to request deletion of your data, or to report a security issue.

If you are not satisfied with our response, you may lodge a complaint with Brazil's National Data Protection Authority (ANPD) at gov.br/anpd.