Group Post Alerts
How it worksPricingFAQ
Log inStart free

Legal

Privacy Policy

This policy explains what we collect, what stays on your own computer, and who else touches your data. The short version: your account details reach our servers, and the content of Facebook posts does not.

Last updated August 18, 2026

The short version

  • Facebook post content, author names, and group content are stored only in your browser. We never receive them.
  • Keyword matching and AI relevance scoring run locally on your machine. Post text is not sent to us or to any AI API.
  • The extension is read-only on Facebook. It never posts, comments, messages, likes, or joins groups.
  • We never sell or rent your data, and we never use it for advertising or creditworthiness.

1. Who this policy covers

This policy applies to the Group Post Alerts website, the account and billing area, and the Group Post Alerts for Facebook Groups Chrome extension. Together these are the “Service”. sydbin is the data controller. You can reach us at support@grouppostalerts.com.

2. What we collect on our servers

The list below is exhaustive. If a category is not named here, we do not store it.

DataWhy we hold it
Email address and account identifierTo create your account, sign you in, and link the extension to your plan.
Business profile you choose to enter (business name, website, description)Optional. Used to help you write matching criteria. Leave the fields empty and nothing is stored.
Your Facebook numeric account IDStored only if you link an account, so one subscription cannot be shared across several people. We store the ID and the link timestamps — not your name, profile, friends, photos, messages, or password.
Keyword and filter backupsStored only when you ask for a backup. These contain your own keywords and settings with opaque group identifiers. They never contain post content.
Hashed extension sign-in tokens and their expiryTo keep the extension signed in and let you revoke access.
Subscription status, plan, and billing eventsTo grant or withdraw access. Received from our payment provider. We never see or store your full card number.
Waitlist email (Managed plan)Only if you submit the waitlist form. Used to tell you when Managed opens.

3. What stays on your computer and never reaches us

The extension keeps a local database in your own browser. It holds the Facebook posts it read, the posts that matched your keywords, your monitoring schedule and cursors, and diagnostic logs. This data is not uploaded, backed up, or readable by us. It lives on your device until you clear it or remove the extension.

The extension only reads content you can already see while signed in to Facebook yourself, in groups you are already a member of. It does not use your Facebook password — you sign in to Facebook in Facebook’s own tab, and we never see those credentials.

4. How the AI filtering works

Relevance scoring runs inside your browser. The classification model ships inside the extension package, and the additional language models are executed locally by your CPU. The text of a post is never transmitted to us, and never transmitted to a hosted AI service such as OpenAI or Anthropic.

One clarification for completeness: the first time a language model is needed, the extension downloads the model files from the Hugging Face content delivery network. That request fetches a file. It carries no post content, no keywords, and no account data.

5. Alerts you send to your own destinations

When a post matches, the extension sends the alert directly from your browser to the webhook address youconfigured — Discord, Slack, Microsoft Teams, Google Chat, or your own endpoint. That alert contains the post text (up to 2,000 characters), the author name, the group, the timestamp, and the link.

This traffic does not pass through our servers. Once it reaches your destination, that platform’s own privacy policy governs it, and you are responsible for who can read that channel.

6. Why the extension asks for each permission

PermissionReason
Access to facebook.comTo read posts in the groups you selected. Read-only; nothing is written.
Access to discord.comTo deliver alerts to the Discord webhook you configured.
Access to grouppostalerts.comTo sign in and check your subscription status.
storageTo keep your keywords, settings, and matched posts on your device.
tabs and scriptingTo open a background Facebook tab on your schedule and read the group feed in it.
alarmsTo run the check on the interval you chose.
notificationsTo show a desktop notification when a post matches.
declarativeNetRequestTo set the Origin header to https://www.facebook.com on requests the extension makes to facebook.com, which Facebook requires before it will answer them. One static rule does this. It applies to facebook.com only, changes no other header, and never blocks, redirects, or inspects a request to any other site.

7. Chrome Web Store Limited Use disclosure

Our use of information received through the extension adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. Specifically, we affirm that we do not:

  • sell, rent, or lease user data to anyone;
  • use or transfer user data for any purpose unrelated to delivering the single purpose of the extension, which is alerting you to matching posts in your own Facebook groups;
  • use or transfer user data to determine creditworthiness or for lending purposes;
  • use user data for advertising, retargeting, or personalised advertisements;
  • allow humans to read your data, except with your explicit consent for a support request you initiate, where required by law, or on aggregated anonymised data for security and abuse prevention.

8. What the extension does not do

  • It does not publish posts, write comments, send messages, react, follow, or join groups on your behalf. Automated publishing is not part of this product.
  • It does not read Facebook Messenger, your inbox, or private conversations.
  • It does not collect your Facebook password or session cookies.
  • It does not track your browsing on other websites.
  • It does not run analytics or advertising trackers inside the extension.

9. Service providers

We use a small number of vendors to run the Service. Each processes data only on our instructions, under a data processing agreement.

ProviderPurposeData reached
SupabaseAuthentication and databaseEmail, account ID, business profile, keyword backups, subscription state
CreemPayments and subscription managementEmail, billing details, and card data, which is handled by Creem and never reaches our servers
VercelWebsite and API hostingRequest metadata such as IP address and user agent, in server logs
Hugging FaceDelivery of AI model files to your browserThe model file request only. No post content, no account data

We also disclose data if the law requires it, or to protect our rights, safety, or property. If the business is ever sold or merged, your data may transfer to the buyer under this same policy, and we will tell you before that happens.

10. How long we keep data

  • Account and business profile: for as long as your account exists.
  • Keyword backups: until you delete them or close your account.
  • Sign-in tokens: until they expire or you revoke them.
  • Billing records: for as long as tax and accounting law requires, typically seven years, even after you close your account.
  • Server logs: a rolling short retention window for security and debugging.
  • Local browser data: entirely under your control. Removing the extension removes it.

When you close your account we delete or anonymise your personal data within 30 days, except the billing records we are legally required to retain.

11. Your rights

Depending on where you live, you may have the right to access your data, correct it, delete it, receive a portable copy, restrict or object to processing, and withdraw consent. If you are in the EEA or UK, this covers your GDPR rights. If you are a California resident, this covers your rights under the CCPA/CPRA, including the right not to be discriminated against for exercising them. We do not sell or share personal information as those laws define it.

Email support@grouppostalerts.com and we will respond within 30 days. You may also complain to your local data protection authority.

12. Legal basis for processing

Where the GDPR applies, we process your data to perform our contract with you (running your account and subscription), to meet legal obligations (tax and accounting records), on the basis of our legitimate interest in keeping the Service secure and preventing abuse, and on your consent where you have given it, such as joining the waitlist.

13. International transfers

Our providers may process data in the United States and other countries. Where personal data leaves the EEA or UK, the transfer relies on Standard Contractual Clauses or another lawful transfer mechanism.

14. Security

Traffic to our servers is encrypted in transit with TLS. Extension sign-in tokens are stored as hashes, not in readable form, and can be revoked. Card data never touches our infrastructure. No system is perfectly secure, so we cannot promise absolute protection, but we will notify you and the relevant regulator without undue delay if a breach affects your personal data.

15. Children

The Service is for business use and is not directed at anyone under 18. We do not knowingly collect data from children. If you believe a child has given us data, contact us and we will delete it.

16. Changes to this policy

We may update this policy. When we do, we change the date at the top of the page, and for material changes we notify you by email or in the app before the change takes effect. Continuing to use the Service after that means you accept the updated policy.

17. Contact

Questions, requests, or complaints: support@grouppostalerts.com.

Group Post Alerts

Product

  • How it works
  • Pricing
  • FAQ
  • Install from Chrome Web Store

Company

  • Support
  • Account

Legal

  • Privacy Policy
  • Terms of Service
  • Refund Policy

© 2026 Group Post Alerts