arrow_back Start page

Privacy Policy

Last Updated: May 4, 2026 (rev. 4)

shield_with_heart

At ZenFeed ("we", "us", "our", or "zenfeed.eu"), we understand that protecting your brand means protecting your data. This Privacy Policy explains how we collect, process, and safeguard information when you use our automated moderation services.

We built ZenFeed with European privacy standards at its core. Our guiding principle is simple: we do not monetize your data, and we do not feed your community's comments to external third-party AI models.

1 How We Process Facebook Comments (End-User Data)

When you connect your Facebook Page to ZenFeed, our system analyzes incoming comments to detect and manage toxicity based on your settings.

  • memory
    Internal AI Processing

    All contextual and text analysis is performed exclusively on our own internal AI models. The content of the comments never leaves the ZenFeed infrastructure. We do not use third-party LLM APIs (such as OpenAI or Google) to process your community's data.

  • location_on
    Strict EU Data Location

    All our servers and data processing facilities are located strictly within the European Union (EU). Your data never crosses EU borders.

  • timer
    Data Retention & Deletion

    Comment text, together with the comment author's name and ID, is stored for a maximum of 30 days. This retention exists solely to provide you with analytics (e.g., viewing logs of the most toxic comments). By default, after 30 days the comment text and the author's name and ID are permanently deleted; we keep only numerical data (toxicity score, spam flag, the moderation action taken, and timestamps), the platform's own comment ID, and an irreversible cryptographic hash of the author's ID, which lets us keep counting statistics for blocked and trusted authors but cannot be turned back into the ID itself. If you've opted in to extended retention (see 'Opt-In Research & Algorithm-Improvement Retention' below), the comments covered by that consent are kept in full.

  • tune
    Custom Retention Periods

    If your organization's internal compliance requires it, you can request to shorten this retention period (e.g., immediate deletion after analysis) by contacting our support team.

  • person_off
    Comment Author Data & No Profiling

    The comment author's display name and platform ID are stored alongside the comment for the same retention period described above β€” permanently deleted after 30 days by default, or kept if you have opted in to extended retention for research. ZenFeed does not build or maintain profiles of comment authors, and does not use any personal data of commenters for any purpose other than the moderation decision and the statistics shown in your own dashboard (comment counts and average toxicity for the authors you have blocked or marked as trusted).

  • science
    Opt-In Research & Algorithm-Improvement Retention

    In your Account settings, you can optionally allow us to keep your comments for longer than 30 days β€” including their text and the author's name and ID β€” to help us improve our moderation algorithm and to support scientific research into online hate speech, potentially including published academic research. Without this consent, that data is permanently deleted after 30 days. This is entirely optional, off by default, has no effect on your service, and can be withdrawn at any time. Withdrawing consent means comments older than 30 days will be covered by the standard deletion on the next sweep; it does not restore data already deleted.

2 Data We Collect About You (Client Data)

To provide our service, we collect limited information about you as the account administrator:

  • check_circle Account Information: Name, email address, and billing details.
  • check_circle Facebook Meta Data: Page Access Tokens (encrypted at rest), Page IDs, and your moderation preferences (Toxicity Thresholds).

3 Data Sharing and Third Parties

We do not sell, rent, or share your data with data brokers, advertisers, or unauthorized third parties. We only share administrative data with trusted subprocessors strictly necessary to run our business. Our current subprocessors include:

Hetzner Online GmbH

Provides secure, EU-based cloud hosting and data storage infrastructure where our application and internal AI models are hosted.

Paddle

Processes your subscription payments securely. We do not store your full credit card details on our servers.

Sentry (EU region)

Collects anonymous error reports and performance data to help us detect and fix technical issues. Data is processed exclusively on EU servers (Frankfurt). Sentry does not use cookies. See sentry.io/privacy.

Attio

Manages our customer relationship data. When you register, your email address, current subscription plan, and onboarding progress are stored in Attio to help our team support you. Attio is a UK-based company; data may be transferred outside the EEA and is protected by Standard Contractual Clauses. Legal basis: legitimate interest (Article 6(1)(f) GDPR). See attio.com/legal/privacy.

4 Meta (Facebook) Compliance & Data Deletion

ZenFeed operates via the official Meta Graph API. We adhere strictly to the Meta Platform Terms on data use and deletion. Disconnecting a Facebook Page from ZenFeed monitoring β€” or stopping monitoring for an individual Page β€” is an immediate deletion trigger: we revoke the Page's access token and permanently purge all stored comment data, moderation logs, and any other Platform Data associated with that Page from our active databases. If you revoke the ZenFeed application's access via Facebook's App Settings, or request full account deletion, the same complete purge applies to all data across all your connected Pages. All deletions are initiated without delay and are irreversible.

5 Your Rights Under GDPR

If you are an EU resident, you have the right to:

  • check_circle Access the personal data we hold about you.
  • check_circle Request correction of inaccurate data.
  • check_circle Request erasure of your data (the "Right to be Forgotten").
  • check_circle Object to or restrict our processing of your data.

To exercise any of these rights, please contact us at hello@zenfeed.eu.

6 Security Measures

We implement industry-standard security measures, including HTTPS/TLS encryption for data in transit and AES-256 encryption for sensitive data (like Access Tokens) at rest.

7 Cookies and Website Analytics

We use essential cookies to provide our services, including session management (`zf_session`) and remembering your preferences (`lang`, `region`). These cookies are strictly necessary for the website to function. We also use Matomo, a self-hosted, privacy-friendly analytics tool that does not use cookies or collect personal data.

Matomo is self-hosted on our own EU servers (Hetzner) β€” no analytics data is shared with a third-party provider.

8 Contact Us & Data Controller

The Data Controller responsible for your personal information is Szymon Nieradka.

If you have any questions about this Privacy Policy, your rights, or our data practices, please contact us: