Privacy Policy

Last updated July 26, 2026

Who we are

Outlaw Data is a social media analytics dashboard operated by Johnny Outlaw LLC. You connect the social accounts you already own or manage, and we chart their performance over time in one place. This policy explains exactly what we access, why, where it lives, and how to get rid of it.

We do not sell personal data, we do not share it with advertisers or data brokers, and we do not use platform data to build advertising profiles or to train machine learning models.

What we collect

Account information. When you sign up we store your email address, your display name, and the workspace you belong to. Authentication is handled by Supabase Auth; if you sign in with Google we receive your email address and name, never your password.

Social platform data. When you connect a platform, we store an access token for that connection and the metrics we pull on your behalf. For Facebook and Instagram this means: Page and Instagram account identifiers and names, follower and fan counts, aggregate daily insight metrics (reach, impressions, engagement, profile views and similar), your own published posts and their captions, media thumbnails and permalinks, per-post performance metrics, and aggregate audience demographics (city, country, age band, gender distribution).

Aggregate demographics are exactly that — counts by bucket. We never receive, request, or store the identity of an individual follower, and we do not read comments, direct messages, or private messages.

Product usage. We record page views within the dashboard so we can see which reports get used. This is first-party and is not shared with third-party ad networks.

Billing. Subscription payments are processed by Stripe. Card numbers never reach our servers; we store only a Stripe customer identifier and your plan status.

Meta permissions we request, and why

When you connect Facebook or Instagram, Facebook shows you a consent screen listing the permissions below. Each one maps to a specific feature — we do not request permissions we have no use for.

  • The list of Facebook Pages you manage (pages_show_list) So we can show you which Pages are available to connect. We store only the Page id and name of the Pages you choose.
  • Engagement metrics for your Pages (pages_read_engagement) To populate the reach, engagement and follower charts on your dashboard.
  • Posts published by your Pages (pages_read_user_content) To list your own Page posts alongside their performance metrics. We do not read comments or messages from other people.
  • Page and Instagram insights (read_insights) This is the metric history the product exists to chart. Stored as aggregate daily values, never per-person data.
  • Your Instagram professional account profile (instagram_basic) To identify the Instagram account linked to a connected Page and label it in your dashboard.
  • Instagram account and media insights (instagram_manage_insights) To chart Instagram reach, impressions, follower counts and per-post performance.
  • Pages owned by your Business Portfolio (business_management) So Pages held in a Business Portfolio — rather than directly on your personal account — still appear in the list of Pages you can connect.

You can review or revoke this access at any time in your Facebook settings under Apps and Websites. Revoking access immediately stops all syncing.

How the data is used

Platform data is used for one purpose: rendering the analytics you asked for, to the people you granted access to in your workspace. A background job refreshes your metrics on a schedule so charts show history rather than only today.

Access is enforced per workspace in the database itself, not merely in the interface. A user of one workspace cannot read another workspace's data.

Where it lives, and who else touches it

We use a small number of processors, each contractually limited to providing their service:

  • Supabase — Postgres database and authentication (United States).
  • Vercel — application hosting (United States).
  • Render — the scheduled job that pulls metrics from the platform APIs.
  • Stripe — subscription billing.
  • Meta, TikTok, Google and X — the platforms you choose to connect, as the source of the data.

OAuth access tokens are encrypted at rest with authenticated encryption; the encryption key is held in the application environment and never stored in the database alongside the ciphertext. Data in transit is TLS-encrypted throughout.

How long we keep it

Metric history is retained for as long as the connection is active, because history is the product. When you disconnect an account — or when Meta tells us you removed our app and requested deletion — the stored token and every derived metric row for that account are deleted immediately. We do not keep an archival copy.

Deletion audit records (a confirmation code, a timestamp and a count of what was removed) are retained so that you and the platform can verify a request was honored.

Deleting your data

There are three ways to get your data removed, and all of them work:

  • In the app. Go to Connect Accounts and remove a connection. The token and all metrics for that account are deleted on the spot.
  • From Facebook. In Facebook Settings, under Apps and Websites, remove Outlaw Data and choose to delete your data. Facebook notifies our deletion endpoint, we delete everything tied to your Facebook user, and you receive a confirmation code you can check at outlawdata.com/data-deletion.
  • By email. Write to johnnyoutlawllc@gmail.com and we will delete your account and all associated data within 30 days, usually the same day.

Your rights

Depending on where you live you may have the right to access, correct, export or delete your personal data, and to object to certain processing. Email johnnyoutlawllc@gmail.com and we will respond within 30 days. We will not charge you or degrade your service for exercising these rights.

Children

Outlaw Data is a business tool and is not directed at children. We do not knowingly collect personal information from anyone under 13.

Changes

If we change this policy we will update the date at the top of this page. Material changes that affect how platform data is used will also be sent to the email on your account.

Contact

Johnny Outlaw LLC johnnyoutlawllc@gmail.com