What MARKETIA does
- Facebook: AI comment moderation and the Activity Quality Index (ICA) per post, reactions, Messenger in the unified inbox, publishing and scheduling, live videos, the Page action button and Page insights.
- Instagram (professional accounts linked to a Page): comments and mentions, direct messages in the inbox, publishing and insights.
- WhatsApp Business (Cloud API): customer conversations in the unified inbox, with the AI sales agent that replies and creates cash-on-delivery orders following the business's rules; Meta-approved templates and campaigns.
- Threads (Threads' own OAuth): publishing, reading and moderating replies, mentions and insights.
- Meta Ads: dashboards of campaigns, ad sets and ads with aggregated metrics, automation rules, AI analysis, custom audiences and the business's own lead forms (Lead Ads).
What it does not do
- It does not read personal profiles or Pages the business does not manage.
- Outside WhatsApp's 24-hour window, messages are only sent with Meta-approved templates, as the platform requires; MARKETIA's terms forbid unsolicited advertising.
- It does not sell data, use it for third-party advertising or to train AI models.
How authorization works
- An administrator of the business opens MARKETIA → Connections and clicks "Connect with Facebook" (Pages, Instagram and ads), "Connect WhatsApp" (Meta's WhatsApp Business Embedded Signup) or "Connect Threads".
- Meta's official dialog opens. The person chooses which Pages, Instagram accounts, ad accounts and WhatsApp accounts to share, and which permissions to grant.
- Meta returns the code to the callback URL; the server exchanges it, encrypts the tokens and records the granted permissions per asset.
- Every MARKETIA feature checks that the required permission is granted for that specific asset before running; otherwise it is shown as disabled with an explanation.
Permissions and what they are used for
Facebook Pages
| Permission | Used for |
|---|---|
pages_show_list | List the Pages the person manages so they can choose which to connect. |
pages_read_engagement | Read posts, followers and the Page action button. |
pages_read_user_content | Read visitor comments and posts to moderate them. |
pages_manage_metadata | Subscribe the Page to webhooks to receive comments and messages in real time. |
pages_manage_engagement | Reply to, hide or delete comments and like them as the Page. |
pages_manage_posts | Publish, schedule, edit and delete Page posts. |
pages_messaging | Reply to Messenger conversations from the inbox. |
read_insights | Page and Reels insights. |
publish_video | Go live on the Page (only if the business uses live videos). |
pages_manage_cta | Change the Page action button. |
pages_manage_ads and leads_retrieval | The business's lead forms (Lead Ads) and sending leads to its CRM. |
| Permission | Used for |
|---|---|
instagram_basic | Profile and content of the connected professional account. |
instagram_manage_comments | Read, reply to and hide comments and mentions. |
instagram_manage_messages | Instagram direct messages in the inbox. |
instagram_content_publish | Publish and schedule to Instagram. |
instagram_manage_insights | Account and media insights. |
Ads and business
| Permission | Used for |
|---|---|
ads_read | See ad accounts and their aggregated results. |
ads_management | Manage campaigns, ads, rules and audiences when the business asks for it. |
business_management | Read the business portfolio to list the assets the business shares. |
catalog_management | Manage product catalogs (if the business enables it). |
WhatsApp Business
| Permission | Used for |
|---|---|
whatsapp_business_management | Manage the WhatsApp Business account, its numbers and templates. |
whatsapp_business_messaging | Send and receive WhatsApp messages from the inbox. |
whatsapp_business_manage_events | Send WhatsApp conversions back to Meta (identifiers hashed with SHA-256). |
Threads (Threads' own app, not the Facebook dialog)
Callback: https://fapi.marketia.cerebria.co/api/v1/threads/oauth/callback
| Permission | Used for |
|---|---|
threads_basic | See the connected account's profile and threads. |
threads_content_publish and threads_delete | Publish and delete Threads posts. |
threads_read_replies and threads_manage_replies | Read, reply to and moderate replies. |
threads_manage_insights | Threads insights. |
threads_manage_mentions | Mentions of the account. |
threads_keyword_search and threads_location_tagging | Search Threads and tag locations when posting. |
What data is stored
- Comments and reactions on the business's posts, with the commenter's public name.
- Messenger, Instagram and WhatsApp messages, with name and profile picture when Meta provides them (the picture is copied to our storage because Meta's link expires). On Instagram, also username, follower count, whether they follow the business and whether they are verified.
- Aggregated ad account metrics (spend, impressions, clicks, conversions), which do not identify individuals, and the click-to-message ad ID each conversation came from.
- What people submit in the business's instant forms (Lead Ads).
- Access tokens, always encrypted, and the permissions granted per asset.
Encryption and security
- Meta tokens are encrypted at rest with authenticated encryption (Fernet: AES-128-CBC + HMAC-SHA256); they are never returned to the interface or the API.
- Facebook, Instagram, WhatsApp and Threads webhooks are verified with Meta's signature (
X-Hub-Signature-256). - Tenant isolation and roles: only the business's administrators connect or disconnect accounts; an ad account can only belong to one organization.
- All traffic is encrypted with TLS (HTTPS).
Disconnection, retention and deletion
- From MARKETIA: disconnecting an ad account deletes its metrics, campaigns and ads; disconnecting a Page stops new data (what was already received stays in the business's inbox until deletion is requested or the organization is deleted), and that Page's Lead Ads data is deleted.
- From Facebook (Settings → Apps and websites → MARKETIA → Remove): Meta calls our deauthorize callback (
https://fapi.marketia.cerebria.co/legal/meta/deauthorize) and we disconnect that person's Pages and ad accounts. - If deletion is also requested, Meta calls
https://fapi.marketia.cerebria.co/legal/meta/data-deletion:we delete the tokens, the Facebook ID and permission data, and return a confirmation code that can be checked on the data deletion page. - Threads has its own deauthorize and deletion URLs (below). Deletion on request is also available by email, within 30 days at most.
Related documents: privacy · data deletion · terms · security
Callback and webhook URLs
| Purpose | URL |
|---|---|
| Facebook Login OAuth callback (ads) | https://fapi.marketia.cerebria.co/api/v1/connections/meta/oauth/callback |
| Facebook Login OAuth callback (Pages) | https://fapi.marketia.cerebria.co/api/v1/connections/meta/pages/oauth/callback |
| Threads OAuth callback | https://fapi.marketia.cerebria.co/api/v1/threads/oauth/callback |
| Deauthorize callback (Facebook) | https://fapi.marketia.cerebria.co/legal/meta/deauthorize |
| Data deletion request callback (Facebook) | https://fapi.marketia.cerebria.co/legal/meta/data-deletion |
| Deauthorize callback (Threads) | https://fapi.marketia.cerebria.co/api/v1/threads/oauth/deauthorize |
| Data deletion callback (Threads) | https://fapi.marketia.cerebria.co/api/v1/threads/oauth/data-deletion |
| Facebook and Instagram webhooks | https://fapi.marketia.cerebria.co/api/v1/webhooks/facebook |
| WhatsApp webhook | https://fapi.marketia.cerebria.co/api/v1/webhooks/whatsapp |
| Threads webhook | https://fapi.marketia.cerebria.co/api/v1/webhooks/threads |
| Data deletion instructions (MARKETIA, Spanish) | https://fapi.marketia.cerebria.co/legal/eliminar-datos |
| MARKETIA privacy policy (Spanish) | https://fapi.marketia.cerebria.co/legal/privacidad |
Contact
For any question about the Meta integration, test accounts or data requests: developer@cerebria.co
Privacy and deletion requests: developer@cerebria.co