Skip to content

Social Response Agent

Privacy Policy

Updated October 1, 2026

About this service

Social Response Agent helps businesses review, moderate and reply to Facebook and Instagram comments, and manually handle supported direct messages where the required access is enabled. It is operated by Ricky Forbes Enterprises Ltd. A separate YouTube integration is used for Ricky Forbes’s own channel. TikTok support is under development and awaits approval and account setup. Test workspaces are separate from connected social accounts.

Customer accounts and email choices

When email registration is activated, Auth0 handles your password, email verification and recovery. We store your verified email, display name, an opaque identity identifier and hashed session identifiers. Customer sessions last up to 12 hours; you can sign out all devices from your account. Connecting Facebook is a separate authorization step.

A workspace owner can invite a teammate by verified email. An accepted teammate can see connected channel comments and insights, write notes, save drafts and send manual replies. The owner can remove access at any time. Invitation links expire after seven days, and stored invitation tokens are hashed. We keep the invited email and membership record to administer access.

Weekly comment summaries and marketing emails are separate optional choices, off by default. We record the choice, consent text version and time. Resend processes report delivery when enabled. Reports contain aggregate counts from saved records, not private messages. Recipient-bearing queued report payloads are cleared after 30 days when the email worker runs. Unsubscribe links change only the selected email purpose. Delivery failures or complaints can pause email.

Deleting a customer account revokes app sessions and erases its email, preferences and queued reports. Minimal opaque identity and workspace identifiers remain to prevent deleted accounts and old sessions from returning and to track deletion. Hosted identity erasure and retained billing records require provider review; the deletion receipt remains under review until resolved.

Google Reviews and LinkedIn

These integrations are in development. If enabled for an approved account, the following handling applies. Connections require platform approval and your authorization. Google Business Profile reviews can be imported for review, sent to OpenAI to draft a response when you request it, and answered after you approve the text. Review content and drafts are temporary, with a maximum 30-day cache. We keep encrypted access credentials until you disconnect or delete your account.

LinkedIn Company Page comments are displayed for manual replies. Incoming LinkedIn comments are not used for AI reply generation or voice training. Cached comment text expires after 48 hours. Opaque identifiers may remain to prevent duplicate replies. You can disconnect either platform from its channel controls.

Test workspaces

The test workspace stores the sample business name, business facts, draft edits, selected plan and simulated billing state you enter on our server. Please use sample information only. A secure browser cookie allows this browser to reopen the workspace; it does not verify your identity or sign you into a real social account. We do not collect card details or send test content to Meta, Stripe or an AI service.

Access expires 45 days after creation or the last saved change. Expired test records are deleted when a new test workspace is created. You can delete your workspace immediately using Start over. Hourly request counts and a rotating hash derived from the client IP limit automated creation; raw IP addresses are not saved in these records. Old test rate-limit records are removed on subsequent creation requests.

Previous pilot applications

The application form is closed. Previously submitted contact details and consent records remain available only to the project owner for the original application purpose. Request correction or deletion at ricky@rickyforbes.com. An application did not create a subscription or newsletter signup.

Information processed

When a connected platform returns a comment or sends a comment event, the service may process the comment text, platform-provided comment and post identifiers, limited public author information made available by the platform, the related post context, timestamps, and the reply decision. It does not request passwords or information outside the permissions granted through the connected platform. When you explicitly enable messaging, we also store incoming message text, participant and message identifiers, timestamps, your reply drafts and delivery status. Private message replies are manually reviewed and sent; message text is not sent to OpenAI in this workflow. With ads access, we read ad identifiers and linked post comments to build your review queue. Payment card details are handled by Stripe when test checkout is configured, not stored by this app.

How information is used

Information is used to understand comments, draft or publish appropriate replies, prevent duplicate responses, enforce safety rules and rate limits, troubleshoot the service, and maintain an audit record. Information is not sold or used for third-party advertising.

Service providers

The service relies on Meta, TikTok and YouTube to provide comments and post context, OpenAI to help classify comments and draft replies, and secure cloud infrastructure to run the application and store operational records. These providers process data only as needed to deliver their services and under their own applicable terms and privacy commitments.

Retention and security

Operational records, including enabled messaging conversations, remain until you request deletion or an applicable retention process removes them. Deleting your workspace removes attributable records and revokes stored access. Minimal deletion receipts and revocation markers remain to prevent data from being recreated. We also retain your platform account identifier and an eligibility timestamp to prevent repeated free trials after deletion; this record contains no comments, messages or access tokens. Unresolved historical records or billing reconciliation are clearly reported for review. Operational records are used to run, review, secure, and improve the comment assistant. Access credentials are stored as protected secrets, and reasonable technical measures are used to limit unauthorized access. No internet service can guarantee absolute security.

Your choices and deletion

You may delete your comment directly on the original platform. To ask whether the service holds information connected to your comment, or to request its deletion, email ricky@rickyforbes.com. Please include the Page post or comment link so the request can be located.

YouTube and Google data

This app uses YouTube API Services. YouTube video titles, descriptions, comment text and public author information are sent to OpenAI only to create the reply drafts requested by the channel owner. AI drafts and confidence judgments are generated by this app, not YouTube. Google access tokens are encrypted and used only to manage the authorized channel’s comments.

Saved YouTube comment data is deleted after 30 days. You can disconnect YouTube and delete the app’s saved channel data from the YouTube page. This revokes access with Google and does not remove comments already published on YouTube. You can also revoke access through Google security settings. Data is removed when revoked access is detected; inactive connection records expire within 30 days.

See the Google Privacy Policy and YouTube Terms of Service.

Updates and contact

This policy may be updated as the service changes. Questions about this policy or the service can be sent to ricky@rickyforbes.com.

Return to Social Response Agent