Skip to content

Privacy

Last updated 18 September 2026

LeadWave connects to a Facebook Page you control and handles messages on its behalf. That means we hold some data about you and some data about the people who message your Page. This page says what, and why.

What we store about you

  • Your account. Your name, email address and profile picture, taken from the Google account you signed in with. We never receive your Google password.
  • Your workspace. Its name, time zone, plan and the members you invited.
  • Your Page connection. The Page's id, name, picture and a long-lived access token, encrypted at rest with AES-256-GCM. A leaked database dump is not, by itself, a leaked set of Facebook Pages.
  • Sessions. Only the SHA-256 hash of your session token, so a database read cannot be replayed as a login.

What we store about people who message your Page

  • Their Page-scoped id — the identifier Facebook gives us for that person on that Page. It does not work on any other Page.
  • Their first and last name and profile picture, as Facebook supplies them.
  • The messages exchanged in that conversation, so your inbox can show the thread.
  • Anything they gave you deliberately — an email address or a phone number they sent in response to a prompt.
  • Link clicks. The time, a coarse device type and country, and a hashed visitor fingerprint. The hash is enough to tell one person from another for counting purposes; it is not enough to identify anybody.

What we do not do

  • We do not sell personal data. Not to advertisers, not to data brokers, not to anyone.
  • We do not use your customers' messages to train a general-purpose AI model.
  • We do not read your Page's messages except to operate the features you switched on.
  • We do not store your Facebook password, because we never receive it.

LeadWave AI

If you enable LeadWave AI, the text of an inbound message, the recent thread context and the knowledge you have written are sent to Google's Gemini API to generate a reply. We send the minimum needed to answer, and we do not send your contact list, your other conversations or your account details. Google's handling of that data is governed by their API terms.

How long we keep it

  • Conversations and contacts — for as long as the Page is connected.
  • Analytics — 30 days on the free plan, indefinitely on paid plans, matching the retention your plan advertises.
  • Webhook records — a short window, long enough to make duplicate deliveries from Facebook harmless.
  • After you disconnect a Page — its access token is deleted immediately, and its data is removed within 30 days.

Your rights

You can export your contacts and leads as a CSV from the dashboard at any time, and you can delete your workspace, which removes everything associated with it. If you are in a jurisdiction with a statutory right of access, correction or erasure, the deletion route below satisfies it — see data deletion.

Cookies

One cookie, for your session, marked httpOnly so scripts on the page cannot read it. There is no advertising cookie and no third-party tracker on this site.

Meta

LeadWave uses Meta's official Graph API under the permissions you approved. We are not affiliated with, endorsed by or sponsored by Meta Platforms, Inc. Your use of Facebook and Messenger remains governed by Meta's own terms and privacy policy.

Contact

Questions about this policy or a request covered by it — email leadwaveonline@gmail.com.

This page is written to be understood, not to be unreadable. It is not legal advice, and if you are deploying LeadWave yourself you should have a lawyer review it against the jurisdictions you actually operate in before you publish it.