Privacy Policy
Last updated: February 27, 2026
EmotionWise Social (“we”, “our”, or “us”) operates the EmotionWise Social platform, a SaaS analytics tool that helps Instagram Business account owners understand the emotional tone of their posts and audience comments. This Privacy Policy explains what data we collect, how we use it, and your rights regarding that data.
1. Information We Collect
Account Information
When you register with an email and password, we collect your email address, full name (optional), and a hashed password. We use this solely to authenticate you and manage your account.
Facebook Login
If you choose to sign in with Facebook, we receive from Facebook’s API:
- Your Facebook user ID (used to identify your account)
- Your name as set on Facebook
- Your email address associated with your Facebook account
Instagram Account Data
When you connect an Instagram Business account via Instagram’s OAuth flow, we receive and store:
- Your Instagram user ID and username
- Follower count
- A long-lived access token (used to fetch your content on your behalf)
Post Data
After you trigger a sync, we retrieve from the Instagram Graph API and store:
- Post captions, media type, permalink, and timestamp
- Comment count per post
- Individual comment text, commenter username, and timestamp
Emotion Analysis Results
Post captions and comments are sent to the EmotionWise API (api.emotionwise.ai) for emotion detection. We store the resulting emotion scores (joy, anger, sadness, fear, surprise, disgust) alongside the original content. No raw text is retained by the EmotionWise API beyond the duration of the API call.
Payment Information
When you subscribe to a paid plan, payment is processed by Stripe. We do not store your credit card number or full payment details. We store your Stripe customer ID and subscription ID to manage your plan status.
Cookies
We use a single session cookie (ew_token) to keep you logged in. This cookie contains a signed authentication token and expires when your session ends or after 60 minutes of inactivity. We do not use advertising or tracking cookies.
Usage Data
We collect standard server logs (IP address, browser type, pages visited, timestamps) for security and operational purposes. We do not use third-party analytics trackers.
2. How We Use Your Data
We use the data we collect to:
- Provide the EmotionWise Social service — syncing your Instagram content and displaying emotion analytics
- Analyze the emotional tone of your post captions and audience comments
- Generate trends, alerts, and summaries shown in your dashboard
- Authenticate your account and maintain session security
- Process payments and manage your subscription plan
- Send transactional emails (e.g. welcome, password reset, sync summaries) — no marketing emails without your consent
- Improve service reliability and diagnose technical issues
We do not sell your data to third parties. We do not use your Instagram content or comment data for advertising purposes.
3. Instagram Permissions We Request
We request the following Instagram permissions when you connect your account:
instagram_business_basic
To read your profile information (username, follower count) and list your posts.
instagram_business_manage_comments
To read comments on your posts so we can perform emotion analysis on your audience's responses. We read comments only; we do not post, edit, hide, or delete comments on your behalf.
These permissions are used exclusively to provide the analytics features described above. You can revoke access at any time from your Instagram account settings under Apps and Websites.
4. Data Sharing
We share your data only with the following sub-processors, strictly as necessary to operate the service:
EmotionWise API (api.emotionwise.ai)
Receives post caption text and comment text for emotion analysis. Text is processed in real time and not stored.
Meta Platforms (Facebook & Instagram Graph API)
We communicate with Meta's API to authenticate users via Facebook Login and to fetch Instagram content. Meta's own privacy policy governs data on their platform.
Stripe
Processes payments for paid subscriptions. Stripe handles all credit card data under PCI-DSS compliance. We never see or store raw card details.
Brevo (formerly Sendinblue)
Delivers transactional emails such as welcome messages, password resets, and sync summaries on our behalf.
Cloud infrastructure (AWS)
Our database and application servers are hosted on Amazon Web Services. Data is encrypted at rest and in transit.
We will disclose data if required by law or to protect the rights and safety of our users.
5. Data Retention
We retain your account data and Instagram content for as long as your account is active. You may request deletion of your account and all associated data at any time by emailing support@emotionwise.social. We will process deletion requests within 30 days.
Disconnecting an Instagram account from within the app removes your access token and stops future syncs but does not automatically delete previously synced post and comment data. Contact us if you want that data removed as well.
6. Data Security
We take reasonable technical and organizational measures to protect your data, including:
- HTTPS encryption for all data in transit
- Passwords stored using bcrypt hashing
- Instagram access tokens stored encrypted at rest
- Session tokens stored in secure, HTTP-only cookies
- Access to production systems restricted to authorized personnel
7. Your Rights
Depending on your jurisdiction (including California / CCPA and the EU / GDPR), you may have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data (right to be forgotten)
- Object to or restrict certain processing
- Data portability (receive your data in a machine-readable format)
- Opt out of the sale of personal information (we do not sell personal data)
To exercise any of these rights, contact us at support@emotionwise.social.
8. Children's Privacy
EmotionWise Social is not directed at children under the age of 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
9. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the “Last updated” date at the top of this page. Continued use of the service after changes are posted constitutes your acceptance of the updated policy.
10. Contact Us
If you have any questions about this Privacy Policy or how we handle your data: