Bellerofonte · meta platform data

Versione italiana

How we handle Meta Platform Data

What Bellerofonte reads from Meta's APIs, under which permissions, what it is used for, who can see it, how long we keep it and how to have it deleted.

Last updated: 2026-09-20

Controller
Bellerofonte s.r.l.
Address
Via G. Galilei 2, 48018 Faenza (RA)
VAT no.
02648640395
App
Bellerofonte — https://dashboard.bellerofontedata.com
Privacy contact
privacy@piavedigitalagency.it
Security contact
security@piavedigitalagency.it

Bellerofonte analyses the public communication of organisations: public bodies, companies, publishers, Pages and professional accounts. A customer connects the channels they own or are entitled to monitor, and the platform computes aggregate indicators: publishing cadence, interactions received, sentiment, keywords, topics, period-over-period comparisons. It is not a people-surveillance tool.

1. What we mean by "Platform Data"

We use the term Platform Data with the meaning given to it by the Meta Platform Terms (§12): any information obtained by us, or by anyone acting on our behalf, from the Meta Platforms — directly or indirectly, before or after the date of the agreement — including data derived from that information.

The consequence we treat as binding: derived and aggregated data is still Platform Data. A sentiment score computed on an Instagram comment, a keyword extracted from a caption, a topic cluster, an interaction time series, a line in a PDF report — all of it remains subject to the same usage restrictions, the same retention rules and the same deletion obligations as the original record. There is no level of aggregation at which, for us, the data stops being Platform Data and becomes ours to sell or repurpose.

2. How we obtain the data

3. The four permissions we request

We request four permissions, all read-only. Connecting a Facebook Page uses two of them (pages_show_list and pages_read_engagement); connecting an Instagram professional account uses all four. For each one, the table states the Graph endpoints we actually call, the fields we request, Meta's declared allowed usage, and where the data appears in the product. Where a field is requested from Graph but never stored, we say so.

Permission Graph endpoints called Fields requested Allowed usage (Meta) Where it appears in the product
instagram_basic GET /{ig-user-id}
GET /{ig-user-id}/media
Account: id, name, username, followers_count, follows_count, media_count, profile_picture_url.
Media: id, caption, media_type, media_url, permalink, thumbnail_url, timestamp, username, comments_count, like_count, media_product_type. Of these, username and comments_count are not stored: we derive the comment count from the comments we actually read.
Get basic metadata about an Instagram professional account and get the media it has published. The channel header (name, @username, picture, follower count); the list of published media with date, type and permalink; the caption text, from which sentiment, keywords and topics are derived.
instagram_manage_insights GET /{ig-user-id}/insights
GET /{ig-media-id}/insights
GET /{ig-user-id}?fields=business_discovery.username(...)
Account: follower_count, accounts_engaged, follows_and_unfollows, engaged_audience_demographics, follower_demographics. The two demographic metrics are requested with a breakdown by age and gender.
Media: reach, views, likes, comments, saved, shares, total_interactions, follows; for reels, ig_reels_avg_watch_time and ig_reels_video_view_total_time in place of follows.
Get insights data for an Instagram professional account and its media; get metadata about other Instagram professional accounts through Business Discovery. Performance charts for the channel and for individual media; period-over-period comparisons; comparison against the public benchmark accounts chosen by the customer; reports. Demographic metrics arrive from Meta already aggregated into buckets (age and gender) and we use them only in that form: we never tie them to individuals and never use them to infer anything about a person.
pages_show_list GET /me/accounts
GET /{page-id}?fields=instagram_business_account
id, name, instagram_business_account{id,username}: the list of Pages the person administers and the Instagram professional account paired with each. The Page access token does not come from here: it is requested by a separate call, and only for the Pages that are actually connected. Show a person the list of Pages they manage and confirm that they in fact manage the Page. The channel connection screen only, where the whole list is displayed. Which Pages to authorise is chosen in the Facebook authorisation dialog, and we connect exactly those: the /me/accounts response is displayed and nothing more — we do not store it.
pages_read_engagement GET /{page-id} (metadata)
GET /{page-id}/feed
GET /{post-id} (refresh of a single post)
GET /{post-id}/comments
GET /{ig-media-id}/comments (comments on the media of the paired Instagram account)
Page: id, name, link, picture, fan_count. We do not request the Page's contact fields (emails, phone, whatsapp_number, personal_info, impressum).
Posts: created_time, message, permalink_url, full_picture, shares, attachments, story_tags, promotable_id and the reaction counts per type (like, love, wow, haha, thankful, sad, angry). The last three are not stored.
Public comments on Facebook: id, message, created_time, permalink_url, parent, like_count; on Instagram: id, text, timestamp, like_count, media. In neither case do we request from, the field identifying who wrote the comment: comments are stored without an author.
Provide the person with an aggregated view of the content and engagement of the Page they manage. The Page's header and posting history; publishing and interaction volumes; sentiment and topics computed on the text of the posts and of the public comments the Page received.

We request no other permissions. In particular we request no publishing permission, no messaging permission and no advertising permission: Bellerofonte only reads. It does not publish posts, does not reply to comments, does not send or read direct messages, and does not access campaigns, ad spend or advertising audiences.

Connection, renewal and revocation calls

Besides reading data, the app calls Graph to manage the life cycle of the consent. None of these calls reads content or data about people:

CallWhat it is for
POST /oauth/access_token Exchange the code returned by the authorisation dialog for an access token.
GET /oauth/access_token (grant_type=fb_exchange_token) Renew the long-lived token before it expires, without asking for consent again.
GET /debug_token Check validity, expiry and the permissions actually granted.
GET /{page-id}?fields=access_token Obtain the Page access token, only for the Pages being connected.
DELETE /{user-id}/permissions Revoke the consent on Meta when the user disconnects the channel.

There is finally GET /pages/search, used on the screen where a customer looks for the Facebook Page to add to their project: it returns public Page metadata (id, name, location, link, verification_status), the results are only displayed, and nothing is stored until the channel is actually added.

4. Business Discovery

Business Discovery is the Graph API feature that lets a connected Instagram professional account read the public data of other professional accounts by username: GET /{ig-user-id}?fields=business_discovery.username(...).

We use it for one thing: building the benchmark comparisons customers ask for — their own channel's performance next to that of other public channels in the same sector, for instance one municipality next to other municipalities, or one publisher next to other publishers.

It is the only legitimate way to read that data. The alternative would be collecting it from public web pages, that is scraping, which the Platform Terms prohibit and which we do not do. We would rather use an official endpoint with clear limits than a shortcut with none.

Which account the call is made from. Business Discovery is not a global search: it is queried through a professional account you control. If the person running the search has connected their own Instagram professional account, the call is made from that account and with their token — on behalf of the customer. If they have no account connected, the search falls back to the Controller's own professional account, and the page says so with a visible warning. The scheduled refresh of the public benchmark channels always uses the Controller's account, because it runs at night, with no user signed in.

What this means in practice:

5. What we do not do

Meta Platform Terms §3.a lists the prohibited uses of Platform Data. Below, one by one, what each of them means for Bellerofonte.

Prohibition (Platform Terms §3.a)How we comply
No discrimination based on protected attributes We do not infer anyone's ethnicity, religion, political opinions, trade union membership, health, sexual orientation or gender identity, and we do not use the data to treat anyone differently on those grounds. The demographic metrics we receive from Meta are already aggregated into buckets and stay that way.
No eligibility determinations We do not use the data — original or derived — to decide whether a person is eligible for employment, housing, credit, insurance, a public benefit or any other entitlement, and we do not supply the data to anyone who would use it for that.
No surveillance We do not provide surveillance tools and we do not process the data on behalf of law enforcement or of any authority seeking to monitor individuals, groups, protests or movements. Bellerofonte operates on organisations' channels, not on people, and offers no way to follow an individual over time or across locations.
No selling, licensing or purchasing of Platform Data We do not sell, license, transfer or purchase Platform Data. For us the prohibition covers derived and aggregated data as well: we do not commercialise sentiment indices, rankings, keyword datasets or reports built on Meta data. What a customer pays for is access to the tool over their own channels, not the data.
No profiles of individuals We do not build or enrich dossiers on individuals. Our units of analysis are the channel, the content item, the period and the topic, and we do not combine Meta data with other sources at individual level. Comments ingested through Meta's APIs carry no author: Meta does not provide us with the identity of the person who commented, and we do not request the field that would contain it — on neither Facebook nor Instagram. There is therefore no per-person record built from Meta data, and there cannot be one.
No re-identification or de-anonymisation We do not attempt to establish the identity of whoever wrote a comment, we do not attempt to de-anonymise aggregated data, and we do not link identifiers across sources to reconstruct a person.
No material change of processing without a new App Review If we ever wanted to use the data for purposes other than those described here, or to request further permissions, we would go through a new App Review first and update this page. We do not silently extend the use of data already collected.
No use outside the permitted purposes We use Platform Data solely to deliver the analysis features described on this page to the customer who owns the channel. We do not use it to train general-purpose models, we do not resell it as research material, and we do not reuse it in our other products.

6. Who sees what

Bellerofonte has no public feed, directory or search over Meta-sourced content and comments: to consult them you have to be an authenticated user of the project that channel belongs to.

7. Separation between customers

Each customer works inside their own project. Channels, content, insights and analysis outputs are bound to the project that produced them, and the application's queries are always scoped to the project of the user running them. One customer's data never flows into a shared pool available to other customers, and no feature exposes to one customer the data collected for another.

8. Retention and deletion

Meta-sourced content, comments and metrics are retained for 90 days, after which they are deleted automatically together with the derived outputs that remain associable with them (for example that comment's sentiment score). Only aggregates that can no longer be associated with a person are kept.

Before expiry, we delete Platform Data whenever any of the six triggers in Platform Terms §3.d.i.2 occurs — stated here in plain language:

  1. when we no longer need it for the legitimate business purpose for which it was collected — which is exactly what the 90-day expiry enforces;
  2. when we stop offering the feature the data was collected for, or discontinue Bellerofonte: for that case there is a full-purge procedure that deletes the data of every Meta channel with no time window at all;
  3. when Meta asks us to delete it, including to protect its own end users;
  4. when the user asks us to delete it, or deletes their Meta account;
  5. when an applicable law or regulation requires it;
  6. when Section 7 of the Platform Terms requires it, that is if our agreement with Meta is suspended, terminates or expires.

On top of these, one commitment of our own, beyond what the Platform Terms require: if the channel owner withdraws authorisation — disconnects the channel, revokes the permissions, or removes the app from their Facebook settings (in the latter case Meta sends us the deauthorization notification and we proceed on our own) — we delete that channel's data without waiting for expiry. Disconnecting the channel from the platform also revokes the consent on Meta (DELETE /{user-id}/permissions), deletes the channel's content, comments, metrics and derived statistics, clears the tokens, and immediately sweeps any record left without the data it was attached to, without waiting for the nightly pass.

All three routes — the disconnect button in the platform, the Deauthorize Callback and the Data Deletion Request Callback — go through the same procedure and leave a recorded request, with a confirmation code and a summary of what was deleted: it is the proof of deletion Platform Terms §3.d.i.3 require us to be able to produce to Meta or to an authority. One honest exception: if a Deauthorize Callback arrives with an identifier that matches no connection we know of, there is nothing to delete and we record nothing — that notification leaves no trace.

Two clarifications, so as not to claim more than we do. Deletion at expiry runs once a day, at night: a record disappears within twenty-four hours of reaching 90 days, not at the exact instant. And if a post or a comment is deleted on the source platform, we do not notice on our own: our copy goes away with expiry, with the disconnection of the channel, or on a deletion request — not at the next synchronisation.

9. Vendors and language models

The vendors processing data on our behalf are listed, with their function and their location, on the Processors page. Each one is appointed under a written agreement and bound to the same usage restrictions the Platform Terms impose on us.

Bellerofonte's infrastructure is located within the European Economic Area. Language processing — sentiment, keywords, topics, summaries — runs on models hosted on the Controller's own infrastructure: Meta-sourced text is not sent to third-party AI services and is not used to train anyone's models.

10. Security

So as not to claim more than we do: multi-factor authentication on administrative tooling, a centralised access log with periodic review, and a tested incident response plan are not yet in operation. They are planned work, not active measures, and until they are this page does not list them among our controls.

The detailed measures and the channel for reporting a vulnerability are on the Security page.

11. How to request deletion

Anyone can request deletion of their data, including people who are not customers and have never held an account with us. The form is public and asks for no Facebook or Instagram credentials:

Request deletion of your data

Each request receives a confirmation code for tracking its status on a public page until the final outcome. If a request is refused, the status page states the reason.

Alternatively, if you connected a Meta account to Bellerofonte, simply remove the app from your Facebook account settings (Settings & privacy → Settings → Apps and websites). Meta notifies us through the Deauthorize Callback and the Data Deletion Request Callback we have registered, and deletion starts automatically: nothing else is required of you.

If you are a customer and connected the channel yourself, the Disconnect button on the connection screen does exactly the same thing: it revokes the consent on Meta, deletes the data collected through that connection, and records the deletion request with its confirmation code.

For any other question about Meta data, write to privacy@piavedigitalagency.it. The full picture of our processing is in the Privacy Policy.