Privacy Policy
Last updated: July 23, 2026 (v3)
Effective: August 8, 2026
1. Information We Collect
Murmur, operated by 宇鏈科技企業社 (Unified Business No. 00634248) ("we", "our", "the Service"), collects the following information when you use our platform:
- Account information: your name, email address, and password (hashed) when you register.
- Facebook & Instagram data: when you connect a Facebook Page or Instagram Business account via OAuth, we receive and store page access tokens, page / post / comment data, and the public profile information for the connecting user. Access tokens are encrypted at rest using AES-256-GCM.
- Marketing API data: when you connect a Facebook Ad Account, we receive and store the authorizing user's Facebook user ID, the ad account access token (encrypted), and ad / ad creative metadata for posts you have tagged as sponsored.
- Usage data: audit logs of actions you take within the Service (e.g., replying to comments, changing settings, login events with IP). Audit logs are append-only and are retained for as long as the forensic, security, and legal-compliance purposes for which they are kept continue to apply (see Section 5).
2. Meta Platform Permissions We Request
When you connect a Facebook Page or Instagram account via OAuth, Murmur requests the following Meta permissions. Each permission is used solely for the purpose described below; we do not request or use any other permissions:
business_management— to list Business assets you manage so you can pick which Pages to connect.pages_show_list— to enumerate the Pages you administer.pages_read_engagement,pages_read_user_content— to sync posts and comments from your connected Pages.pages_manage_engagement,pages_manage_metadata— to reply to and hide comments on your behalf and to subscribe to Page webhooks.instagram_basic,instagram_manage_comments— to read media and manage comments on the Instagram Business account linked to your Page.ads_read(Ad Account connection only) — to read ad / ad creative metadata via the Marketing API for posts you tag as sponsored.
3. How We Use Your Information
- To provide the core Service: syncing posts and comments from Facebook / Instagram Pages and enabling you to manage and reply to comments.
- To match ad posts to their underlying Page posts via the Marketing API, so sponsored comments can be surfaced alongside organic ones.
- To send transactional emails (e.g., password resets, team invitations, security alerts).
- To improve the reliability and performance of the Service.
We do not use your Meta Platform data for advertising, for training machine-learning models, or for any purpose other than operating the Service for you.
4. Data Sharing
We do not sell, rent, or share your personal data or Facebook / Instagram data with third parties, except:
- As required by law or legal process.
- With service providers that help us operate (Hetzner for hosting, Cloudflare for DNS / CDN, Resend for transactional email, Telegram for operational alerts), under strict confidentiality obligations and Data Processing Agreements where applicable.
A public KOL post or comment may be processed for more than one customer organization when each organization is independently authorized to access the relevant KOL or connected Page. Each organization receives only the data available through its authorization, and its workflow state, assignments, reply identities, and internal settings remain isolated from other organizations.
5. Data Retention & Deletion
When an organization or account is terminated, it is disabled and active synchronization and processing stop. Because organizations are archived rather than automatically erased, associated Customer Data is retained until an authorized organization representative submits a written deletion or de-identification request, or as otherwise specified in a separate agreement. We process written requests within 30 days, subject to applicable law and the audit-log retention described below.
There are four paths to remove your data from Murmur:
- Automatic — Meta deletion request: Murmur implements Meta's Data Deletion Request Callback. When Meta sends us a valid signed deletion request on your behalf, we process it within seconds and you can verify the result using the confirmation code Meta provides. The data removed is limited to records we can match to the identifier in the request; our Data Deletion Instructions explain the scope, including how Instagram comment data is handled. The exact circumstances under which Meta sends a deletion request are determined by Meta.
- Automatic — Meta deauthorize: Murmur implements Meta's Deauthorize Callback. When you remove Murmur from your Facebook account or revoke its permissions (e.g., via "Apps and Websites" or "Business Integrations"), Meta notifies us and we perform the same cascade deletion as for an explicit deletion request, in line with Meta Platform Terms §3.d.i.2(d).
- Manual, by email: email [email protected] from your registered address and we will process the request within 30 days.
- Disconnect inside Murmur: removing a KOL connection through the Murmur dashboard deletes that organization's access, stored access tokens for the connection, and organization-scoped data. Cached posts and comments may remain while another organization retains its own authorization for the same KOL or Page. Disconnecting inside Murmur does not revoke the authorization in Meta.
Security and compliance audit logs are append-only and are retained for as long as the forensic, security, and legal-compliance purposes for which they are kept continue to apply. They record administrative actions (such as logins, configuration changes, KOL connections) and may reference Meta identifiers (e.g., a Page ID) as part of those records, but they do not contain the content of synced posts or comments. Audit log entries are not automatically scrubbed by Meta's data-deletion callback. If you need specific audit log entries reviewed or removed, please contact us at [email protected] and we will handle the request consistent with applicable law and our legitimate forensic / compliance interests.
6. Data Security
We protect your data using industry-standard measures including encrypted token storage (AES-256-GCM), HTTPS-only transport, and access controls. However, no method of electronic storage is 100% secure.
7. Your Rights
Under Taiwan's Personal Data Protection Act, in respect of your personal data we hold you may: inquire about or request to review it; request a copy of it; request that it be supplemented or corrected; request that we cease collecting, processing, or using it; and request that it be deleted. You may exercise these rights at any time through the Service or by contacting us at [email protected].
You may also disconnect a Facebook Page or linked Instagram Business account inside Murmur to remove that organization's connection and organization-scoped data. To revoke Murmur's authorization at Meta, use your Meta account settings. Certain data (for example, our append-only audit logs) may be retained where required by law or reasonably necessary for our legitimate forensic, security, or compliance interests; we will explain this when handling your request.
8. Facebook Platform Data
Our use of information received from Facebook APIs adheres to the Meta Platform Terms and Developer Policies.
9. Changes to This Policy
We may update this Privacy Policy from time to time. Updated versions are posted on this page with a revised "Last updated" date, and material changes are posted at least 14 days before the stated effective date.
10. Language
This Privacy Policy is made in Chinese. We may provide translations into English or other languages for convenience; in the event of any inconsistency, the Chinese version prevails.
11. Contact Us
If you have questions about this Privacy Policy, please contact us at [email protected].