Privacy policy

Last updated 25 September 2026

Ideaor handles information about your agency, your staff, and the families who message your Facebook Page. This explains what we hold, why we hold it, and what you can ask us to do with it.

This is a working draft. It describes how Ideaor actually operates, but it has not been reviewed by a lawyer. Do not rely on it as legal advice.

Who we are

Ideaor provides software that writes social posts, answers Facebook Messenger enquiries, and records leads for non-medical home care agencies. We serve agencies worldwide. You can reach us at hello@ideaor.com.

What we collect

  • Your account. Name, email address, and a password stored only as a hash we cannot reverse.
  • Your agency. Business name, website, service area, services offered, contact details, and the description of how you like to sound.
  • Your Facebook connection. The Page you choose, its name and picture, and access tokens. Tokens are encrypted before they are stored and are only decrypted on our servers at the moment a request is made.
  • Messenger conversations. Messages sent to your Page, the sender's Facebook display name, and replies sent on your behalf.
  • Leads. Names, phone numbers, email addresses, locations and notes, whether captured from a conversation or added by you.
  • Page performance. Aggregate figures Facebook reports about your Page and its posts.
  • If you use the chat on this website. What you write, and, so that the person answering can help you and we can stop abuse: your IP address, the rough location it suggests (country, region, city), and your browser and operating system. We do not know your exact whereabouts and we do not track you across other websites.
  • Visits to this website. Which pages were looked at and when. We count visitors using a code made by scrambling the IP address with a secret and the day's date, so the same person cannot be recognised tomorrow or traced back. No cookie is set for this.
  • Operational records. Sign-in attempts and security events, with secrets removed before anything is written down.

What we do not collect

Ideaor is built for non-medical care and is designed not to gather health information. Our assistant is instructed to decline medical questions and suggest speaking to a doctor. We do not ask for payment card numbers, and we do not record calls.

Why we hold it

  • To run the service you signed up for: writing posts, publishing them once you approve, and answering messages.
  • To show you your own numbers and conversations.
  • To keep accounts secure, including rate limiting and investigating suspicious activity.
  • To answer you when you contact us.

Who it is shared with

We do not sell your information. We use a small number of providers to run the service:

  • Supabase hosts the database and handles sign-in.
  • Vercel hosts the application.
  • Meta Platforms receives the posts you approve and the replies sent from your Page, because that is where they are published.
  • Our AI provider receives the brief you write, your brand description, and the text of a conversation when a reply is needed. It does not receive your Facebook tokens or your account password.

We may also disclose information where the law requires it.

If you ask us for help

Every account has four words in Settings, Account. Nobody at Ideaor can open your account without them, and you choose whether to read them out. They are not a password: they cannot sign anyone in, and they work nowhere except our own support screen.

When you do give them to us, the visit is recorded and shown back to you in that same screen: who looked, when, and what they were helping with. Access is read-only and expires by itself after an hour. You can replace your four words at any time, which immediately stops the old ones working.

How long we keep it

Things are deleted automatically once they have done their job:

  • IP addresses on website chats: removed after 30 days, while the conversation itself remains.
  • Website chats: deleted after 180 days.
  • Records of which pages were visited: deleted after 13 months.
  • Failed support-key attempts: deleted after 90 days.
  • Records of support opening your account: kept for a year, so the history is there if you need it.

Your own content, conversations and leads stay until you delete them or close your account. Disconnecting Facebook deletes the stored tokens for that Page immediately.

Your choices

  • Change your name, email or password at any time under Settings.
  • Disconnect your Facebook Page at any time, which stops all posting and replying.
  • Ask us for a copy of what we hold about you, or ask us to delete it, by writing to hello@ideaor.com.

Families who message your Page are your contacts, not ours. If one of them asks you to delete their details, you can remove the lead and conversation from your account.

Security

Every agency's data is separated at the database level rather than by application code, so one account cannot read another's. Facebook tokens are encrypted at rest. Traffic is served over HTTPS. No system is perfect, and we will tell you promptly if something happens that affects your information.

Children

Ideaor is a business tool and is not intended for anyone under 18.

Changes

If we change this policy in a way that matters, we will say so in the product before the change takes effect.