Introduction
VisiSocial is a personality analytics platform that analyzes your Facebook data to provide insights into your personality traits using the scientifically validated Big Five personality model. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our services.
By connecting your Facebook account to VisiSocial, you explicitly authorize us to access and analyze specific data as outlined in this policy. We are committed to transparency and giving you full control over your data.
What You Should Know
We only access Facebook data you authorize through Facebook's permissions system. We use OpenAI's API to generate personality descriptions. We use optical character recognition (OCR) to extract text from photos you've posted. We never sell your data. You can export or permanently delete all your data at any time.
Information We Collect
Information from Facebook
When you connect your Facebook account, we request the following permissions and collect:
- Basic profile information (name, email, profile picture, gender, birthday, age range)
- Location and hometown information
- Facebook posts and status updates you've published
- Pages you've liked and their categories
- Photos from your albums (we process up to 25 images)
- Languages you've listed on your profile
- Favorite teams and athletes (if available)
Data We Generate
Through analysis of your Facebook data, we generate and store:
- Text extracted from your photos using Tesseract OCR technology
- Personality scores based on the Big Five model (Openness, Conscientiousness, Extroversion, Agreeableness, Neuroticism)
- Sentiment analysis scores from your text content
- Word frequency analysis and common terms
- Interest categories derived from your likes and activities
- AI-generated personality descriptions created via OpenAI's API
- Engagement metrics and activity statistics
Technical Information
We automatically collect certain technical information:
- IP address and browser information
- Device type and operating system
- Access times and session duration
- Pages visited and features used
- Error logs and performance metrics
Important: Image Processing
We use optical character recognition (OCR) technology to extract text from up to 25 of your Facebook photos. This extracted text is used for personality analysis. We do not use facial recognition technology. Only text content is extracted and analyzed.
How We Use Your Information
We use the collected information for the following specific purposes:
Personality Analysis
- Analyze your social media text using natural language processing (NLP) libraries
- Calculate personality trait scores based on the myPersonality dataset and Big Five model
- Extract and analyze text from photos using Tesseract.js OCR
- Generate personalized descriptions using OpenAI's GPT models
- Compare your patterns against validated psychological models
Platform Services
- Create and maintain your user account
- Display your personality dashboard with interactive visualizations
- Generate insights and recommendations based on your data
- Provide data export functionality (JSON, CSV, PDF formats)
- Track analysis progress and task completion
Technical Operations
- Authenticate your sessions using cookies and tokens
- Cache analysis results to improve performance
- Monitor system performance and error rates
- Maintain security through rate limiting and authentication checks
- Store data in MongoDB with encryption at rest
AI Processing
We use OpenAI's API (GPT-4o-mini model) to generate human-readable personality descriptions, user insights, and recommendations. Your data is sent to OpenAI's servers for processing but is not used to train their models. OpenAI's data usage policy applies to this processing.
Your Privacy Rights
You have the following rights regarding your personal data:
Access and Export
- View Your Data: Access all your stored data through your profile dashboard
- Export as JSON: Download your complete data in JSON format via /api/export/json
- Export as CSV: Get your basic profile data as CSV via /api/export/csv
- Export as PDF: Generate a comprehensive personality report as PDF
- Export as ZIP: Download all your data including analysis results in a single archive
Control and Modification
- Refresh Analysis: Re-run personality analysis with updated Facebook data anytime
- Update Settings: Modify your preferences, display name, and privacy settings
- Revoke Permissions: Disconnect Facebook integration and revoke data access
- Manage Sessions: View and terminate active sessions from the settings page
Deletion Rights
- Delete Account: Permanently delete your account and all associated data from Settings > Profile > Delete Account
- Clear Analysis Data: Remove only analysis results while keeping your account via /api/analysis/clear
- Immediate Effect: Deletion requests are processed immediately and cannot be undone
GDPR & CCPA Compliance
We comply with GDPR (General Data Protection Regulation) and CCPA (California Consumer Privacy Act). EU and California residents have additional rights including data portability, right to be forgotten, and right to opt-out of data sales (which we don't engage in anyway).
Data Security
We implement multiple layers of security to protect your information:
Technical Safeguards
- Encryption: AES-256 encryption for data at rest in MongoDB, TLS 1.3 for data in transit
- Authentication: Secure Facebook OAuth 2.0 flow with token expiration
- Session Management: HTTP-only cookies, secure flags, session timeout after 24 hours
- API Security: Rate limiting (100 requests/hour standard, 10/hour analysis endpoints)
- Input Validation: DOMPurify sanitization to prevent XSS attacks
- Access Control: Role-based permissions and user-specific data isolation
Operational Security
- Regular security audits and vulnerability scanning
- Automatic token revocation on suspicious activity
- Server-side validation for all data operations
- Monitoring and logging of security events
- Backup systems with encryption
Your Responsibility
While we implement strong security measures, you are responsible for keeping your account credentials secure. Never share your password or access tokens. Enable two-factor authentication on your Facebook account for additional protection.
Children's Privacy
VisiSocial is not intended for users under 13 years of age. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately at [email protected], and we will delete such information.
For users between 13-18, we recommend parental guidance and supervision when using our services.
Data Retention
We retain your data for the following periods:
- Active Accounts: Data retained as long as your account is active
- Inactive Accounts: Accounts inactive for 2+ years may be deleted after notice
- Deleted Accounts: All personal data permanently deleted within 30 days
- Revoked Tokens: Expired authentication tokens deleted after 7 days
- Cached Data: Analysis cache expires after 1-7 days depending on type
- Logs: Security and error logs retained for 90 days
- Backups: Encrypted backups retained for 30 days for disaster recovery
Immediate Deletion
When you delete your account, your personal data is immediately removed from our production systems. Backups containing your data are permanently deleted within 30 days. Some anonymized, aggregated statistics may be retained for research purposes but cannot be linked back to you.
International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. These countries may have data protection laws different from your jurisdiction.
We ensure appropriate safeguards are in place:
- Standard Contractual Clauses for EU data transfers
- Encryption during international transmission
- Compliance with GDPR for European users
- Privacy Shield principles where applicable
Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes:
- We'll update the "Last Updated" date at the top of this page
- We'll notify you via email at your registered address
- We'll display a notification on the platform
- For significant changes, we may require you to acknowledge the new policy
Your continued use of VisiSocial after changes constitutes acceptance of the updated Privacy Policy. If you don't agree with changes, you should discontinue use and delete your account.
Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or your personal data:
Privacy Team
Email: [email protected]
Data Protection Officer: [email protected]
Support: [email protected]
Response Time: We aim to respond within 48 hours