Gotchu helps the owner of a Facebook Page answer the comments and messages it receives, with a person approving every reply. This policy says what data passes through it, why, and how to get it removed.
Last updated 15 August 2026
Gotchu (gotchu.social) is operated by Enso Intelligence Labs, Inc., a Delaware corporation, referred to below as “we” and “us”. Questions about this policy, and every request described in it, go to support@gotchu.social.
Two different people appear in this policy. Our customer is the agency or brand whose staff sign in to Gotchu and who own the Page that is connected to it. The public is everyone who comments on or messages that Page.
For everything that comes off a connected Page — comments, messages, and who wrote them — our customer is the data controller. They choose which Pages are connected, what their campaign says, and which reply goes out. We are a processor: we handle that content on their instructions, to run the service, and for nothing else. We do not decide what a Page publishes, and we never use one customer’s content for another.
For our customers’ own account data — the name and email address of a person who signs in, and the record of what they did in the product — we are the controller.
If you left a comment and want it removed from Gotchu, the fastest route is the Page that you commented on; our deletion page also explains how to ask us directly.
A customer connects a Page by signing in with the Facebook account that administers it and granting our app a set of permissions. We ask for the minimum the product needs:
pages_show_list — to show you the Pages you administer, so you can choose which one to connect.pages_read_engagement — to read the connected Page’s own posts and the engagement on them, so a comment can be shown with the post it was left under.pages_read_user_content — to read the comments people leave on the connected Page. This is the product’s core input.pages_manage_engagement — to post the reply a person has approved, and to hide a comment when the Page owner chooses to.pages_manage_metadata — to subscribe the connected Page to comment webhooks, so a new comment reaches the queue in seconds rather than being polled for.pages_messaging — to receive and send messages in the connected Page’s inbox, including the private reply to a comment, where the customer uses that part of the product.We do not request access to ads, audiences, Insights beyond the connected Page’s own posts, or the personal profile of the person who connects the Page beyond what signing in returns. We do not touch any Page that has not been connected, and we never ask anyone for a Facebook password.
From a connected Page:
From our customers:
What we do not do: we do not build profiles of commenters across Pages or campaigns, we do not buy or add data about anyone from anywhere else, we do not run advertising or third-party analytics trackers, and we do not collect location or device data beyond the ordinary server logs our hosting providers keep. The only cookies we set are the ones that keep a signed-in user signed in.
We use three subprocessors, and no others. Each one only ever holds data because it is part of running the service:
We do not sell data, ever, to anyone. We do not share it with advertisers or data brokers, and we do not use customer content or the public’s comments to train models of our own. We cannot independently audit the internal retention practices of every model provider OpenRouter is able to route a request to; a customer who needs inference restricted to providers that retain nothing should tell us before connecting a Page, so we can configure their routing accordingly.
Data may be processed in a country other than your own — our database is hosted in India (Mumbai) and the application is served from the United States.
There is no automatic expiry beyond this today. A customer who needs a shorter retention period for their workspace should ask us and we will agree one in writing.
Traffic is encrypted in transit. Tenants are isolated in the database itself using row-level security rather than only in application code, so a customer cannot read another customer’s data even if the application has a bug; the same applies to the separate clients inside one agency’s workspace. Signing in is by emailed link, so there are no passwords to leak. Access to production data is limited to the people who operate the service.
We do not hold any security certification and this policy claims none. If you believe you have found a vulnerability, email support@gotchu.social and we will respond.
If you commented on or messaged a Page, you can ask for that data to be deleted from Gotchu, and you can ask what we hold. Both requests are covered step by step on our deletion page.
Where UK or EU data protection law applies, our customer is the controller for Page content and we act on their documented instructions. We will help a customer answer a request made to them, and a data processing agreement is available on request. Requests we receive directly from a member of the public are actioned for the Page in question and passed to that Page’s owner, because they are the ones who must answer for it.
Gotchu is a tool for businesses and is not directed at children. We do not knowingly store data about a child beyond a public comment that happened to be left on a customer’s Page. If you believe we hold a child’s data, email support@gotchu.social and we will delete it.
When this policy changes we update the date at the top of the page. If a change materially affects how customer or public data is handled, we email our customers before it takes effect.
Enso Intelligence Labs, Inc., a Delaware corporation, operator of Gotchu — support@gotchu.social.