Public privacy notice
Privacy Policy
This policy explains how Pulse processes information about the person operating a connected account and people who comment publicly on monitored Facebook or Instagram posts.
1. Controller and contact
Pulse (the “App”) is operated by Massimiliano Petrucci, who is the data controller for the processing described in this policy.
Via della Giustizia 6E
61032 Fano (PU), Italy
Privacy contact: dpo@massimilianopetrucci.it
2. Who and what this policy covers
This notice covers:
- the authorized operator who signs in to Pulse and connects a Facebook Page or Instagram professional account;
- people whose public comments or replies appear on a post selected for monitoring; and
- visitors to this public policy website.
This page also serves as the public notice for comment data that Pulse receives indirectly through Meta’s APIs and webhooks.
3. Personal data we process
Connected Facebook and Instagram data
- Facebook Page and Instagram professional-account identifiers, names, usernames and the identifiers needed to associate the authorized Meta user with those accounts;
- Meta access tokens, token issue and expiry information, granted permissions, Page tasks and webhook-subscription status;
- for posts selected for monitoring: post or media ID, permalink, caption, thumbnail URL, publication time and monitoring settings;
- for public comments and replies: comment ID, author ID when Meta provides it, username, profile-picture URL, text, timestamps, reply relationship, and edit or deletion state; and
- information derived by Pulse, including spam indicators, sentiment score and label, aggregate trends, alert state and operational synchronization data.
Comment authors provide their comments to Meta, not directly to Pulse. Pulse receives this information from Meta because the comment was made publicly on a monitored post.
App account and security data
- the authorized operator’s verified Google email address and Google account identifier;
- encrypted authenticator (TOTP) secrets, passkey public keys and related technical information, passkey nicknames, and hashed recovery codes;
- hashed session tokens, session state, sign-in method, timestamps, IP address and browser or device user-agent; and
- login and security-event records, including attempted identity when known, result and limited diagnostic detail.
Technical request data
Pulse and Cloudflare may process IP address, request headers, timestamps, routing and security information when a person accesses the App, a Meta webhook reaches the backend, or someone visits this policy website.
Data we do not intentionally request
Pulse does not request private messages, commenter email addresses, advertising data, payment data or demographic profiles. Public comment text is free-form and may incidentally contain personal or sensitive information chosen by the commenter. Pulse does not intentionally infer sensitive traits from that text.
4. Purposes and legal bases
| Purpose | Legal basis where GDPR applies |
|---|---|
| Connect an authorized account, retrieve selected posts and display their comments. | Taking requested steps and providing the App, where Article 6(1)(b) applies; otherwise the controller’s legitimate interest in operating the requested service, Article 6(1)(f). |
| Classify spam and sentiment, show aggregate trends, and alert the account operator to negative public feedback. | Legitimate interests in understanding, managing and responding to public engagement on accounts operated by the controller, Article 6(1)(f). |
| Authenticate the operator, protect accounts, verify Meta requests, prevent replay and investigate failures or abuse. | Legitimate interests in security, reliability and fraud prevention, Article 6(1)(f), and compliance with legal obligations where applicable, Article 6(1)(c). |
| Answer privacy requests and carry out deletion. | Compliance with legal obligations, Article 6(1)(c), and legitimate interests in documenting that a request was completed, Article 6(1)(f). |
For comment data, the legitimate-interest assessment takes account of the public context, the limited purpose, the operator’s relationship to the monitored account, data minimization, short technical retention periods and the right to object or request deletion.
5. Automated sentiment analysis
Pulse automatically checks comment text for spam and assigns a sentiment score and label, such as positive, neutral or negative. The result is used to organize the operator’s dashboard, calculate trends and trigger operator-configured alerts.
Sentiment analysis runs locally on the controller’s computer during App Review. It is an estimate and can be inaccurate. Pulse does not use it to make decisions that produce legal or similarly significant effects about a commenter, for advertising, or to train a model on their comments.
7. Storage, transfers and security
The Pulse backend and its SQLite databases run on a controller-operated computer in Fano, Italy. Cloudflare carries encrypted traffic to that backend and hosts these policy pages. Google, Meta and Cloudflare may process some information outside the European Economic Area. Where a restricted international transfer occurs, the relevant provider’s lawful transfer safeguards apply, such as an adequacy decision or Standard Contractual Clauses.
Measures used to reduce risk include TLS in transit, restricted local file access, encryption of Meta tokens and TOTP secrets, hashing of session tokens and recovery codes, signed Meta-webhook verification, callback freshness checks, replay protection, limited login access and two-factor authentication. No method of storage or transmission can be guaranteed completely secure.
8. Retention
| Data | Retention |
|---|---|
| Meta access token and active connection record | Until disconnection, expiry, revocation, account replacement, Meta deauthorization or verified deletion. |
| Monitored posts, comments, sentiment results and alerts | While retained by the operator for monitoring history. An ordinary in-App disconnect stops collection and removes the token but retains this history until the post is deleted, a verified deletion is requested, or Meta deauthorizes the App. |
| Webhook payload content | Normally erased no later than 7 days after receipt. Content-free security tombstones are retained for up to 90 days to prevent reprocessing. |
| Meta deletion-request record | Up to 90 days. A content-free signed-callback receipt is retained for up to 180 days to prevent a replay from deleting newly collected data after reconnection. |
| App login events | 90 days. Sessions expire after 7 days of inactivity and in all cases after 30 days; expired sessions are deleted during housekeeping. |
| Google identity and authentication factors | Until the App login account is deleted or an individual factor is replaced or removed. |
Provider-side security logs are retained under the relevant provider’s own terms.
9. Disconnecting and deleting data
- Stop monitoring a post: deletes that post, its stored comments, sentiment results and related alerts.
- Disconnect inside Pulse: unsubscribes where possible, revokes the connection permissions, deletes the stored access token and stops new collection. Existing monitoring history is retained so it can be reviewed or deleted later.
- Remove Pulse in Meta settings: Meta sends a signed deauthorization request and Pulse automatically deletes the matching connection and Meta-derived history.
- Send a privacy request: email dpo@massimilianopetrucci.it. Detailed options are on the data deletion page.
10. Your rights
Subject to applicable law, a data subject may request access, correction, erasure, restriction or portability of their personal data, and may object to processing based on legitimate interests. Where processing ever relies on consent, consent may be withdrawn without affecting earlier lawful processing.
Requests should be sent to dpo@massimilianopetrucci.it. Enough information may be requested to verify identity and locate the relevant account, post or comment. Do not send a password or access token. Pulse will respond without undue delay and normally within one month. That period may be extended by up to two further months when permitted by law, with notice and reasons provided within the first month.
A data subject may also complain to the Italian Data Protection Authority (Garante per la protezione dei dati personali) or another competent supervisory authority.
11. Children
Pulse is not directed to children and does not intentionally target them or use age for analysis. Because Pulse processes public comments without determining each author’s age, a monitored post could include a comment written by a minor. A parent, guardian or young person may contact the privacy address to request review and deletion.
13. Changes to this policy
This page and its “last updated” date will be revised before the purposes, recipients or material handling of personal data change. A prior version relevant to an active Meta App Review will be preserved in version control.