Spark Media Automation Privacy Policy
Last updated: August 25, 2026
This Privacy Policy describes how Spark Media Automation (“Spark Media Automation”, “SMA”, “we”, “us”, or “our”) collects, uses, stores, and protects information when you use the Spark Media Automation platform at http://localhost:3000. Spark Media Automation is a private operations console used by authorized administrators to connect social accounts and publish content.
1. Who this policy applies to
This policy applies to authorized administrators who sign in to SMA, and to individuals whose social account data is connected to SMA through Meta (Facebook, Instagram, Threads) or Postiz OAuth flows initiated by an administrator.
SMA is not a public consumer social network. Access is restricted to personnel authorized by the organization operating the deployment.
2. Information we collect
Administrator account information
- Email address and display name
- Hashed password and optional two-factor authentication data
- Session identifiers and login activity (including IP address and user agent where logged)
- Profile and notification preferences
Connected social account data
When an administrator connects Facebook, Instagram, Threads, or Postiz accounts, we may receive and store:
- OAuth access tokens and related credentials (stored encrypted)
- Account, Page, profile, or channel identifiers and display names
- Usernames, profile images, and granted or declined permissions
- Connection health and synchronization status
Content and publishing data
- Images, videos, captions, titles, and descriptions uploaded for publishing
- Campaign configuration, schedules, and destination selections
- Publishing job status, external post identifiers, and error messages
Technical and security data
- Audit logs of administrative actions
- System health and integration check results
- Server and application logs needed for security, debugging, and compliance
3. How we use information
We use collected information to:
- Authenticate administrators and maintain secure sessions
- Connect to and manage Meta and Postiz integrations
- Store media, prepare content, and publish to selected destinations
- Schedule posts, run background publishing jobs, and retry failed operations
- Monitor token expiry, permissions, and integration health
- Send in-app and email notifications configured by administrators
- Maintain audit trails and comply with platform requirements (including Meta data-deletion callbacks)
- Protect the service against unauthorized access, abuse, and fraud
We do not sell personal information. We do not use connected social account data for advertising unrelated to the operation of this platform.
4. How information is shared
Information is shared only as needed to operate SMA and only with the services below:
- Meta platforms (Facebook, Instagram, Threads) — when publishing content or synchronizing connected assets, according to the permissions granted during OAuth authorization
- Postiz — when publishing to channels connected through Postiz OAuth
- Infrastructure providers — such as database hosting (Supabase/PostgreSQL), object storage (e.g. Cloudflare R2), Redis/queue services, and email delivery (SMTP), under contractual safeguards appropriate to the deployment
We may also disclose information if required by law, regulation, legal process, or to protect the rights, safety, and security of the platform and its users.
5. Data retention
We retain information for as long as needed to provide SMA, comply with legal obligations, resolve disputes, and enforce agreements. Specific retention depends on how your organization uses the platform:
- Administrator sessions expire according to configured session limits
- OAuth tokens remain until disconnected, revoked, or deleted
- Uploaded media and campaign records remain until deleted by an administrator
- Audit logs may be retained for security and compliance purposes
When Meta sends a data deletion request to our callback endpoint, we process the request and provide a confirmation code. Status is available at /privacy/data-deletion.
6. Security
SMA is designed with security controls including password hashing, encrypted storage of OAuth tokens and application secrets, HTTP-only session cookies, CSRF protection for mutating requests, login rate limiting, and audit logging. Access tokens and app secrets are not exposed in browser responses or routine application logs.
No method of transmission or storage is completely secure. Operators of this deployment are responsible for securing server access, environment secrets, and administrator accounts.
7. Cookies and similar technologies
SMA uses essential cookies to:
- Maintain authenticated administrator sessions
- Protect forms and API requests with CSRF tokens
These cookies are necessary for the platform to function. SMA does not use third-party advertising cookies on the administrator console.
8. Your choices and rights
Depending on your role and applicable law, you may have the right to:
- Access or update your administrator profile within SMA
- Disconnect social accounts from Meta or Postiz integrations
- Request deletion of data connected through Meta via Meta's data deletion flow
- Contact the organization operating this SMA deployment regarding other requests
Because SMA is operated as a private administrative tool, privacy requests from social platform users should generally be initiated through the relevant platform (Meta or Postiz) or directed to the organization that connected the account.
9. International transfers
Data may be processed and stored on servers located in regions chosen by the operator of this deployment and its infrastructure providers. By using SMA, authorized administrators acknowledge that data may be transferred to and processed in those locations.
10. Children
SMA is intended for authorized business or organizational use and is not directed at children under 13 (or the minimum age required in your jurisdiction). We do not knowingly collect personal information from children.
11. Changes to this policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top of this page will reflect the most recent revision. Continued use of SMA after changes become effective constitutes acceptance of the updated policy where permitted by law.
12. Contact
For questions about this Privacy Policy or data handled by this SMA deployment, contact the administrator or organization responsible for operating http://localhost:3000.
Meta-related data deletion status: Data deletion