Gotchu

Privacy Policy

Gotchu helps the owner of a Facebook Page answer the comments and messages it receives, with a person approving every reply. This policy says what data passes through it, why, and how to get it removed.

Last updated 15 August 2026

1. Who we are

Gotchu (gotchu.social) is operated by Enso Intelligence Labs, Inc., a Delaware corporation, referred to below as “we” and “us”. Questions about this policy, and every request described in it, go to support@gotchu.social.

2. Who controls the data, and who merely handles it

Two different people appear in this policy. Our customer is the agency or brand whose staff sign in to Gotchu and who own the Page that is connected to it. The public is everyone who comments on or messages that Page.

For everything that comes off a connected Page — comments, messages, and who wrote them — our customer is the data controller. They choose which Pages are connected, what their campaign says, and which reply goes out. We are a processor: we handle that content on their instructions, to run the service, and for nothing else. We do not decide what a Page publishes, and we never use one customer’s content for another.

For our customers’ own account data — the name and email address of a person who signs in, and the record of what they did in the product — we are the controller.

If you left a comment and want it removed from Gotchu, the fastest route is the Page that you commented on; our deletion page also explains how to ask us directly.

3. Connecting a Page, and the permissions we ask for

A customer connects a Page by signing in with the Facebook account that administers it and granting our app a set of permissions. We ask for the minimum the product needs:

  • pages_show_list — to show you the Pages you administer, so you can choose which one to connect.
  • pages_read_engagement — to read the connected Page’s own posts and the engagement on them, so a comment can be shown with the post it was left under.
  • pages_read_user_content — to read the comments people leave on the connected Page. This is the product’s core input.
  • pages_manage_engagement — to post the reply a person has approved, and to hide a comment when the Page owner chooses to.
  • pages_manage_metadata — to subscribe the connected Page to comment webhooks, so a new comment reaches the queue in seconds rather than being polled for.
  • pages_messaging — to receive and send messages in the connected Page’s inbox, including the private reply to a comment, where the customer uses that part of the product.

We do not request access to ads, audiences, Insights beyond the connected Page’s own posts, or the personal profile of the person who connects the Page beyond what signing in returns. We do not touch any Page that has not been connected, and we never ask anyone for a Facebook password.

4. What we store

From a connected Page:

  • Comments. The text of the comment, the commenter’s public display name and their identifier as the platform gives it to us, the post it was left on, its permalink, and the times it was written and reached us.
  • Messages. Where the Page owner uses the messaging part of the product: the text of the message, the sender’s page-scoped identifier, and timestamps. Page-scoped identifiers are specific to that one Page and cannot be used to find a person elsewhere.
  • What the system made of it. A classification of the comment (a question about a price, a complaint, a story, and so on), a draft reply generated for a person to approve, and the result of the automatic check that blocks a draft containing a figure the campaign has not approved.
  • The audit record. Every state change on a comment — classified, drafted, edited, approved, posted, escalated, resolved — with who did it, when, and the text before and after. It is written once and never edited: it is how a brand can prove exactly what was published in its name and by whom.
  • Timing events. The same journey recorded as events with timestamps, which is what the campaign report is calculated from.

From our customers:

  • Name and email address. Signing in is a link emailed to you, so we store no passwords.
  • The workspace, client and campaign a person belongs to, their role, and the playbook they write — the brief, tone notes and approved answers a campaign replies from.
  • An access token for each connected Page, which is what lets the service post a reply you have approved. No user of Gotchu can read it: it is excluded from every query the product makes on a user’s behalf. It stops working the moment the Page owner removes our app in their Facebook settings.

What we do not do: we do not build profiles of commenters across Pages or campaigns, we do not buy or add data about anyone from anywhere else, we do not run advertising or third-party analytics trackers, and we do not collect location or device data beyond the ordinary server logs our hosting providers keep. The only cookies we set are the ones that keep a signed-in user signed in.

5. Who else the data touches

We use three subprocessors, and no others. Each one only ever holds data because it is part of running the service:

  • Supabase — the database this all lives in, and the service that sends the sign-in link.
  • Vercel — hosting and serving the application itself.
  • OpenRouter — routes each classification and drafting request to the language model that answers it. The text of the comment or message and the campaign’s playbook are sent for this, and the reply comes back as a draft for a person to approve.

We do not sell data, ever, to anyone. We do not share it with advertisers or data brokers, and we do not use customer content or the public’s comments to train models of our own. We cannot independently audit the internal retention practices of every model provider OpenRouter is able to route a request to; a customer who needs inference restricted to providers that retain nothing should tell us before connecting a Page, so we can configure their routing accordingly.

Data may be processed in a country other than your own — our database is hosted in India (Mumbai) and the application is served from the United States.

6. How long we keep it

  • Comments, messages, drafts and classifications are kept while the workspace they belong to exists, because the queue, the report and the audit trail are all built from them. They are deleted on request, and when a customer closes their account.
  • Audit records and timing events are kept for the life of the workspace even after the comment they describe has been dealt with — being the durable record of who approved what is their entire purpose. When we act on a deletion request we remove the comment and message text these rows refer to and keep the record of the action itself: who did what, and when.
  • Account data is kept while the account exists and deleted within 30 days of it being closed.

There is no automatic expiry beyond this today. A customer who needs a shorter retention period for their workspace should ask us and we will agree one in writing.

7. Security

Traffic is encrypted in transit. Tenants are isolated in the database itself using row-level security rather than only in application code, so a customer cannot read another customer’s data even if the application has a bug; the same applies to the separate clients inside one agency’s workspace. Signing in is by emailed link, so there are no passwords to leak. Access to production data is limited to the people who operate the service.

We do not hold any security certification and this policy claims none. If you believe you have found a vulnerability, email support@gotchu.social and we will respond.

8. Your rights

If you commented on or messaged a Page, you can ask for that data to be deleted from Gotchu, and you can ask what we hold. Both requests are covered step by step on our deletion page.

Where UK or EU data protection law applies, our customer is the controller for Page content and we act on their documented instructions. We will help a customer answer a request made to them, and a data processing agreement is available on request. Requests we receive directly from a member of the public are actioned for the Page in question and passed to that Page’s owner, because they are the ones who must answer for it.

9. Children

Gotchu is a tool for businesses and is not directed at children. We do not knowingly store data about a child beyond a public comment that happened to be left on a customer’s Page. If you believe we hold a child’s data, email support@gotchu.social and we will delete it.

10. Changes to this policy

When this policy changes we update the date at the top of the page. If a change materially affects how customer or public data is handled, we email our customers before it takes effect.

11. Contact

Enso Intelligence Labs, Inc., a Delaware corporation, operator of Gotchu — support@gotchu.social.