Privacy Policy

Appeal Magic Master Tools — last updated 9 August 2026. This policy explains exactly what the application collects, why, and how you can have it deleted.

1. Who we are

Appeal Magic Master Tools is an independent software product that helps people diagnose Facebook Page, account, monetization and payout problems, and prepare compliant appeal or support information.

We are not affiliated with, endorsed by, or sponsored by Meta Platforms, Inc. All Meta and Facebook trademarks belong to their owners.

2. Information you give us directly

Account information: your name, email address, password hash held by our authentication provider, and the workspace or organization you belong to.

Problem details: the description of the issue you are facing, notes you write, and screenshots or documents you choose to upload as evidence.

Support and billing information: support tickets you open and the subscription plan attached to your workspace.

3. Facebook Login and OAuth data

Connecting a Page uses Meta's official OAuth flow. We never ask for, receive, or store your Facebook password, two-factor codes, session cookies or browser storage.

When you authorize the app, Meta returns an access token together with the list of permissions you granted. The token is encrypted with AES-256-GCM before it is written to our database and is only ever decrypted inside our server runtime to call Meta's official Graph API. It is never sent to your browser and never appears in a URL.

We request the minimum permissions required for the features you use: pages_show_list to list the Pages you administer, and pages_read_engagement to read the basic Page information used for diagnostics. Additional permissions are only requested after Meta App Review approves them for a specific feature.

4. Page and business information obtained after authorization

After you authorize and select a Page, we store the Page ID, Page name, category, profile picture URL, the tasks/permissions Meta reports for you on that Page, and the publication state Meta returns.

We store the results of each diagnostic scan: which checks passed, which need attention, and which data points Meta does not expose through its API. We only record information the authorized Graph API legitimately returns.

We do not scrape Facebook, do not use undocumented endpoints, and do not access Pages you have not explicitly selected.

5. How we use information

To show Page health and connection status, to classify detected issues by severity, and to recommend the next step Meta officially supports.

To generate AI-assisted diagnosis summaries and appeal drafts from the specific content you submit for that request. You review and edit every draft before it is used anywhere.

To operate accounts, workspaces, roles and subscriptions, to keep an audit trail of privileged actions, and to secure the service against abuse.

We do not sell personal information, and we do not use your content to train third-party models beyond processing your individual request.

6. Third-party services

Meta Graph API — used to authorize your account and read the Page information you approved.

Our cloud database, authentication and file storage provider — hosts your account, Page records, evidence files and encrypted tokens.

Our AI provider — receives the specific issue text and evidence summaries you submit for analysis or appeal drafting.

Each provider processes data on our behalf under its own security commitments; we share only what a given feature requires.

7. Data security

Meta access tokens are encrypted at rest and are never exposed to client-side code. Application secrets, including the Meta App Secret, are held only in server-side secret storage.

Every database table enforces row level security so members of one workspace cannot read another workspace's data, and privileged operations re-verify the caller's role on the server.

OAuth requests are protected with a signed, expiring state parameter that binds the callback to the user who started the flow. Privileged actions are recorded in an audit log.

8. Data retention

Account, Page and issue records are retained while your account is active so you can track ongoing cases.

Disconnecting a Page removes its connection record and stored Page data. Disconnecting your Meta account deletes the encrypted access token immediately.

Deleting your account removes your profile, workspaces, Pages, issues, appeals, cases and uploaded evidence. Audit log entries required for security and abuse investigation may be retained in de-identified form.

9. Your rights

You can access and correct your profile information in Settings, disconnect Meta or an individual Page at any time, export the case information you have created, and object to optional processing such as AI analysis by simply not using that feature.

Depending on where you live you may also have the right to request a copy of your data, restrict processing, or lodge a complaint with your local data protection authority.

10. How to request deletion of your data

Use the Data Deletion page at /data-deletion to submit a request. You will receive a request code immediately and can check its status at any time with that code.

You can also email privacy@appealmagicmastertools.com from the address on your account. We aim to complete verified deletion requests within 30 days.

You can additionally remove this application's access from Facebook at any time under Settings & Privacy → Settings → Apps and Websites, which revokes the token we hold.

11. Contact

Privacy questions: privacy@appealmagicmastertools.com.

General support: support@appealmagicmastertools.com, or open a support ticket from inside the app.