Privacy Policy
Last updated: August 2026
This Privacy Policy explains what information MetaMCP collects, how we use it, and what choices you have. If anything is unclear, email us.
This policy applies to our online service at metamcp.net and covers how we handle data received through our Meta (Facebook) integration.
Information we collect
When you create an account, we collect:
- Your email address
- A one-time login code (never a stored password)
- Optional account settings you choose to save
When you connect MetaMCP to your Meta account via OAuth, we store:
- A Meta user access token, encrypted at rest using AES-256, used to make Marketing API calls on your behalf
- Your Meta user ID (a numeric Facebook user identifier), used to process deauthorization and data deletion requests from Meta
- A personal connector token we generate for you, which authenticates requests from your AI assistant to our service
- Any API keys you choose to add (such as an OpenRouter key), stored encrypted
We do not store campaign data, ad creative content, audience data, performance metrics, or any other content fetched from Meta's API. This data is retrieved live on each request and returned to you — it is never persisted on our side.
How we use your information
- To provide and maintain the service
- To make Meta Marketing API calls on your behalf, when you ask us to through your AI assistant
- To communicate with you about your account
- To detect and prevent fraud or abuse
- To process deauthorization and data deletion requests from Meta on your behalf
We do not sell your information, share it with advertisers, or use it to train AI models.
Meta platform data
MetaMCP uses Meta's Marketing API under Meta's Platform Terms. The data we receive via this integration (your Meta access token and user ID) is used solely to operate the service on your behalf. We do not use Meta user data for advertising, profiling, or any purpose beyond making the API calls you request.
If you remove MetaMCP from your Facebook account (via Facebook Settings → Apps and Websites), we receive an automatic deauthorization callback and immediately invalidate your stored Meta access token. If you request deletion of your data through Facebook, we receive a data deletion callback and wipe all personal data associated with your account within 24 hours.
You can also disconnect and delete your data at any time directly in your MetaMCP dashboard without going through Facebook.
Third-party services
The service connects to:
- Meta Platforms, Inc. — via the Meta Marketing API, on your behalf and with your authorization
- Anthropic — your AI assistant (Claude). We do not send your Meta data to Anthropic; the AI assistant calls our MCP server, which calls Meta's API and returns results
- OpenRouter — optionally, for AI image generation. Your OpenRouter API key is used only when you request image generation
You always control this access. You can revoke Meta access at any time from Facebook Settings → Apps and Websites, or from your MetaMCP dashboard. Regenerating your connector URL in MCP Settings immediately invalidates the previous one.
"Meta", "Facebook", and "Instagram" are registered trademarks of Meta Platforms, Inc. MetaMCP is an independent third-party tool and is not affiliated with, endorsed by, or sponsored by Meta Platforms, Inc. MetaMCP uses Meta's Marketing API under Meta's Platform Terms solely to provide the service described in this policy.
Data retention and deletion
When you delete your account from the MetaMCP dashboard, we immediately wipe your Meta access token, Meta user ID, connector URL, and all API keys. Your email address is anonymized. Operational logs are purged on a 90-day cycle.
If Meta sends us a data deletion request on your behalf (via their data deletion callback), we process it within 24 hours and return a confirmation code to Meta. You can verify the deletion was processed by contacting us with your Facebook user ID.
Cookies and sessions
We use strictly necessary cookies to keep you logged in to the dashboard. We do not use advertising cookies or third-party tracking pixels on our own pages.
Data security
We host data in encrypted databases. All connections use HTTPS with TLS 1.2 or higher. Your Meta access token is encrypted at rest using AES-256. Access to production systems is limited to authorized personnel.
Your rights
If you're in the EU/EEA, you have rights under the GDPR including access, correction, deletion, and portability. Email us to exercise these rights. We typically respond within a few business days.
Children
Our service is intended for business use by advertising professionals and is not directed at children under 16.
Changes to this policy
We may update this policy occasionally. The "Last updated" date reflects when changes were made. Material changes will be communicated to active users by email.
Contact