Skip to content
hweihwang

Legal

  • Privacy policy
  • Terms of service
All projects Email Privacy

Privacy Policy

Effective September 20, 2026 ยท Facebook Reset product name and diagnostics controls updated

  1. Scope
  2. Data collected
  3. How we use data
  4. Extensions
  5. Google APIs
  6. Sharing
  7. Retention
  8. Security
  9. Your rights
  10. Contact

1. Scope

This Privacy Policy describes how hweihwang ("we", "us", "our") handles personal data for hweihwang.com and all related software products and services, including apps, connectors, browser extensions, desktop and mobile apps, and APIs (collectively, the "Services").

2. Data We Collect

Data you provide directly

  • Contact details such as email address when you reach out for support or legal requests.
  • Information you submit in forms, feedback, or support messages.

Connector and authentication data

  • OAuth tokens, refresh tokens, granted scopes, and connector metadata required to run authorized features.
  • Account identifiers needed to map jobs or sync operations to your connected services.

Operational and diagnostic data

  • Job logs, run history, error diagnostics, and feature usage telemetry required for reliability and support.
  • Device or app metadata needed for security, abuse prevention, and troubleshooting.

Billing data

  • For paid features, payment processing is handled by third-party providers; we do not store full card numbers.

3. How We Use Data

  • Operate and provide the Services you request.
  • Authenticate accounts and maintain connector functionality.
  • Improve performance, reliability, and product quality.
  • Respond to support, legal, and security issues.
  • Enforce terms, prevent abuse, and comply with legal obligations.

4. Browser Extension Data

For Facebook Reset & Feed Control, previously named Bulk Group Leaver & Facebook Cleanup, Facebook list data, selected queues, Always keep items, Feed rules, hidden-post records, run history, and settings are stored locally in Chrome storage and IndexedDB on your device. This can include names, URLs, avatar URLs, activity hints, selected actions, and run results for Facebook groups, Pages, follows, friends, and sent friend requests. Local JSON/CSV history exports stay on your device. We do not receive your Facebook cleanup lists or Feed content.

Pro activation and validation may send a license key, checkout session identifier, sale identifier, product identifier, activation status, revocation status, and payment/license status between the extension, Gumroad, and our activation service. Server-verified delivery records also contain purchase dates, amounts, fees, and test/refund/dispute status. This supports license delivery, reconciliation, refunds, disputes, and abuse prevention. Checkout records expire after 30 days; license/sale indexes and delivery records expire after 400 days. We do not collect your Facebook password, card number, bank data, or full payment details.

Facebook Reset operational diagnostics are optional and off by default. They send coarse workflow stages, count buckets, outcomes, release, activation mode, screen names, and filtered errors. They do not send Facebook identifiers, names, relationships, page contents, rules, raw history, email, license keys, or error stacks. A random 45-day diagnostic ID groups consented events without a person profile and can link stages to a separate checkout session and server-verified sale. Cloudflare stores its summaries for up to 45 days; PostHog processes product and error events under the shared 12-month retention plan. No pre-consent history is uploaded. Turn this off in Settings to stop collection and request Cloudflare deletion. Contact us with the approximate date and version for a PostHog deletion request. See the full product disclosure.

The Facebook Reset website sends privacy-limited PostHog events with a random browser-session ID, product-page path and title, locale, campaign and referrer host, store or Pro clicks, scroll thresholds, load timing, and filtered JavaScript errors. Query strings, Facebook page content, geographic enrichment, person profiles, autocapture, and session replay are excluded. PostHog processes normal network metadata. The site also uses the disclosed 30-minute first-party source cookie for fixed outbound attribution.

Our use of data handled through Chrome extension permissions follows the Chrome Web Store User Data Policy, including the Limited Use requirements. We do not sell extension user data, use it for personalized advertising, use it for creditworthiness or lending, or allow humans to read Facebook cleanup data unless you explicitly share it for support or access is required for security or legal reasons.

The extension is an independent tool and is not affiliated with, endorsed by, or sponsored by Meta or Facebook.

5. Google API Data Use

If you connect Google services, our use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

  • We only use Google user data to provide user-facing features you explicitly enable.
  • We do not sell Google user data.
  • We do not use Google user data for advertising.

6. Sharing of Data

We do not sell personal data. We may share data only when necessary with:

  • Service providers and processors supporting hosting, security, support, analytics, or billing.
  • Third-party platforms you choose to connect, according to your authorization.
  • Authorities when required by law, court order, or legitimate legal process.

7. Data Retention

We keep data only as long as needed for service operation, legitimate business needs, legal compliance, and dispute resolution. Retention may vary by data type and product context.

8. Security

We implement reasonable technical and organizational safeguards to protect data, including access controls and secure handling of sensitive credentials. No method of storage or transmission is fully guaranteed secure.

9. International Processing

Depending on infrastructure and providers, your data may be processed in different countries. Where required, we apply appropriate safeguards for cross-border data transfers.

10. Your Rights

Subject to applicable law, you may have rights to access, correct, delete, or restrict processing of your personal data. You may also withdraw connector permissions by disconnecting integrations in-app or through the source platform.

11. Children's Privacy

The Services are not directed to children under 13, or the equivalent minimum age in your jurisdiction. We do not knowingly collect personal data from children in violation of applicable law.

12. Policy Updates

We may update this Privacy Policy periodically. Updated versions are posted at this URL with a revised effective date.

13. Contact

For privacy requests or questions, contact [email protected].

hweihwang
All projects Email Privacy Terms