Technical draft — qualified legal review required
This page is an evidence-grounded technical inventory of the GroupsTracker processing currently implemented in this repository. It is not legal advice, is not final contractual language, and must not be published as a completed legal notice until qualified counsel confirms the applicable requirements.
Controller identity: [INSERT LEGAL ENTITY NAME]
Registered address: [INSERT ADDRESS]
Privacy contact: [INSERT PRIVACY EMAIL OR POSTAL CONTACT]
Jurisdiction and effective date: [INSERT AFTER LEGAL REVIEW]
The service uses this information to authenticate Clients, administer subscriptions, access configured Facebook Groups through operator-controlled accounts, evaluate posts against a Client Request, deliver Alerts, provide support, secure and recover the service, and reconcile billing. Post classification may use an operator-configured LiteLLM-compatible gateway and model provider. The current implementation records model and processing diagnostics for operations and cost review.
Facebook, Meta, Stripe, LiteLLM/model providers, alert destination providers, hosting, Postgres, Redis, Caddy, and Cloak Manager may be involved depending on the configured deployment and Client action. The exact provider list, roles, instructions, subprocessors, and contractual terms require operator confirmation before publication.
The technical retention policy is maintained in the operator data-inventory document. In summary, classification post text is set to null after 90 days by a periodic enforcement job; the classification event and operational fields remain. Billing, webhook, Alert, delivery, support, failure, and other audit records are not automatically deleted by the current implementation. Account and browser/session material follows operator retirement and cleanup workflows. Local backups may retain encrypted copies and are not automatically covered by application retention.
Recipients can include configured Alert providers, Stripe, Facebook/Meta platform endpoints, the configured AI gateway/model provider, hosting and infrastructure operators, and support personnel. Whether data leaves the deployment jurisdiction, which transfer mechanism applies, and the relevant provider terms are unresolved placeholders for legal and operator review; this draft does not assert a transfer conclusion.
Potential privacy rights, request procedures, identity verification, response periods, exemptions, and supervisory authority details depend on the controller and applicable jurisdiction. Counsel must replace this paragraph with an authoritative description and contact route. The application uses authentication cookies and a purpose-bound Cloak access cookie; cookie names, scope, duration, and required/optional classification should be confirmed during legal review. Security controls include encrypted application secrets, protected cookie boundaries, Postgres as the durable source of truth, Redis as coordination, access controls, HTTPS deployment guidance, and restricted Manager routing. No security measure is represented as risk-free.
GroupsTracker accesses Facebook/Meta content through operator-controlled accounts and configured browser infrastructure. The operator must independently review current Meta platform terms, automated-access rules, permissions, notices, and any consent or contractual requirements. This draft does not state that the integration is approved by Meta.