Umbrelar is an AI marketing platform operated by Synquanta Technologies. This policy explains what personal data we collect, how we use it, and who we share it with. It also sets out your rights and describes the data we access from Facebook and Instagram through the Meta Platform.
Who we are. "Umbrelar", "we", "us" refers to Synquanta Technologies, the operator of the Umbrelar service. Questions or requests: info@synquanta.com.
1. Who this policy applies to
Umbrelar serves businesses in Nigeria and beyond. This policy covers two groups of people:
- Account holders. These are the business owners and team members who create and use an Umbrelar account. Umbrelar is the data controller for their data.
- End customers & leads. These are people who see a business's ads and content, or who contact that business because of them. When someone taps a business's ad and messages the business on WhatsApp, that conversation happens directly between them and the business in the business's own WhatsApp app. Umbrelar does not receive, store, or reply to those messages. Where Umbrelar processes any end-customer data on a business's instructions, it acts as a data processor and the business remains the controller.
2. Data we collect
Account & identity
- Name and email address.
- Your password, which we store only as a one-way hash (bcrypt). We never hold it in plain text.
- Email-verification status and the date you accepted our Terms of Service.
Security & technical
- IP address and device/browser information (user-agent), retained with session records for security and fraud prevention.
- Session and refresh tokens used to keep you signed in.
Business profile ("Brain")
- Business name, country and city, and industry.
- Marketing goals and monthly advertising budget.
- Brand details you provide: offerings/products, target audience, brand voice and tone, logo, and any brand documents or listings you upload.
Connected channels
- Identifiers for the accounts you authorize us to publish to: your Facebook Page ID and name, and your Instagram professional account ID and username. If you use advertising features that send customers to WhatsApp, we also store the WhatsApp number you tell us to point your ads at.
- If you connect a Meta ad account, we store its identifier, name, currency, time zone, and spending status, so we can create your ads correctly and warn you before a launch that cannot spend.
- Access tokens issued to us by Meta when you connect a Facebook Page or an Instagram professional account. We store a long-lived token for your Meta login and a token for each connected Page or account. These are what let Umbrelar publish on your behalf. If you connect an ad account, we also store a long-lived token for it. That token is different in kind: it is what lets Umbrelar create and manage ads that spend your money, so we name it here separately. Every one of these tokens is stored encrypted on our servers (see Section 10), none of them ever reaches the app on your phone, and you can revoke any of them at any time.
- A token is not a password. It cannot be used to sign in to your Facebook or Instagram account, and it only carries the permissions you granted. We never receive or store your Facebook or Instagram password, because you type it on Facebook's or Instagram's own screen, not ours. See Section 4 for how the connection works.
Content & creatives
- Content you create or that Umbrelar generates for you: ad copy, captions, generated images, posts, and publishing schedules. Generated images are stored in our cloud object storage and served over a content delivery network.
Advertising results (where enabled)
- When you use advertising features, we store the aggregate results Meta reports for your ads: what you spent, how many times your ads were shown, and how many conversations they started. These are counts and costs, not conversations. When someone messages you from an ad, the chat happens in your own WhatsApp app and does not pass through Umbrelar.
Billing
- Where paid plans apply, our payment processor (Paystack) handles the payment. We store only the subscription and customer references it returns to us, and we do not store your full card details.
Usage & diagnostics
- Error and crash reports (which may include your user ID and email) to keep the service reliable, and operational logs of AI requests for cost and quality monitoring.
3. How we use data
- To provide, operate, and secure the Umbrelar service and your account.
- To generate marketing content and creatives based on your business profile.
- To publish content to the Facebook and Instagram accounts you connect.
- To run the advertising you ask for and report its results from Meta's advertising insights (where enabled).
- To provide support, communicate with you, and send service and verification messages.
- To comply with legal obligations and enforce our Terms.
We do not sell your personal data, and we do not use your data or your customers' data to train our own general-purpose AI models.
4. Facebook & Instagram data (Meta Platform)
Umbrelar uses the Meta Graph API to publish content to the Facebook Page and Instagram professional account that you connect. If you use our advertising features, Umbrelar also uses the Meta Marketing API to create campaigns, ad sets, ad creatives and ads in your own ad account, and to read the results Meta reports for them. Each business connects its own accounts, and Umbrelar acts only on that business's own instruction. Ads are created paused: nothing spends money until you review the ad and set it live yourself.
How the connection works. You sign in to Facebook yourself. When you tap "Connect Facebook" in Umbrelar, we open Facebook Login for Business in your device's browser. You log in on Facebook's own screen, you choose which business portfolio, Facebook Page and Instagram account to share with Umbrelar, and you review the permissions before approving.
Facebook then sends an authorization code to our server. Our server exchanges it for a long-lived access token, and derives an access token for the Page you selected. Those tokens are stored on our servers, encrypted at rest. They are never sent to the app on your phone, and we never receive or store your Facebook password.
If you run an Instagram professional account without a Facebook Page, you can connect it directly through Instagram Business Login instead. The same rules apply: you log in on Instagram's own screen, and we hold only an encrypted token.
You can withdraw access at any time. Disconnect the channel in Umbrelar under Settings, or remove Umbrelar from Facebook under Settings & privacy → Settings → Business integrations, or from Instagram under Settings → Website permissions → Apps and websites. Meta notifies our servers when you do this, and we then mark the connection revoked, delete the stored token, and stop publishing to that channel.
Through this integration we access and process:
- The list of Facebook Pages you administer, so we can show you a picker. We keep only the Page you choose; the rest of the list is discarded.
- The identifier and name of the Page you connect, and the identifier, username and profile basics of its linked Instagram professional account (or of an Instagram account you connect directly).
- The access tokens described above, and the list of permissions you granted.
- Where your Page is owned by a Meta business portfolio, you choose that portfolio on Facebook's own screen when you connect. We do not read your portfolio, and we never change portfolio settings or people. We never change an ad account's own settings either. Inside a connected ad account we create and manage the campaigns and ads you ask for, and nothing else.
- If you connect an ad account: its identifier, name, currency, time zone and spending status, and the campaigns, ad sets, ad creatives and ads we create in it on your instruction.
- The advertising results Meta reports for those ads: what you spent, how many times the ads were shown, and how many conversations they started. These are counts and costs only. The conversations themselves happen in your own WhatsApp app and never pass through Umbrelar.
- Content we publish on your behalf (images and captions you wrote or approved) and the post identifiers Meta returns for those posts, so we can show you what was published and link you to it.
- Publishing permissions and publishing rate-limit status for the connected accounts.
We use Meta data solely to provide the features you ask for: publishing your content and, where you use them, creating your ads and reporting their results. We do not sell Meta data, we do not use it to build profiles of you or your customers, and we never share one customer's Meta data with another. Your ads run in your own ad account, for your own business; we never use your Meta data to advertise anything else to anyone. We handle it in accordance with the Meta Platform Terms and Developer Policies. You can disconnect a channel at any time in Umbrelar's settings, and you may request deletion of associated data as described in Section 9 and on our Data Deletion page.
5. AI processing
To generate marketing content, Umbrelar sends relevant parts of your business profile and brand information (your "Brain") and your prompts to third-party AI providers that generate text and images on our behalf:
- Text generation. We use large language models accessed through OpenRouter and Cloudflare AI Gateway, including models from Google, OpenAI, and Anthropic.
- Image generation. We use fal.ai.
These providers process your data under their own terms to return the generated content to us. We do not authorize them to use your business or customer data to train their models beyond what is necessary to provide the service.
6. Third-party subprocessors
We rely on the following service providers to operate Umbrelar. Each processes personal data only as needed to provide its service to us.
| Provider | Purpose | Data involved |
|---|---|---|
| Railway | Application hosting, PostgreSQL database, Redis | All stored account & business data |
| Cloudflare | AI Gateway (LLM proxy/logging) & R2 object storage/CDN | AI prompts, generated creatives |
| OpenRouter | LLM routing (Google / OpenAI / Anthropic models) | Business profile, prompts |
| fal.ai | AI image generation | Image prompts, brand context |
| Langfuse | AI request observability & cost monitoring | AI request metadata |
| Resend | Transactional & verification email | Email address, name |
| Sentry | Error & crash monitoring | User ID, email, diagnostic data |
| Meta Platforms | Publishing to your Facebook Page & Instagram account; creating & reporting on ads in your ad account (where enabled) | Connected account & ad account IDs, access tokens, published content, ad content & results |
| Paystack (where applicable) | Payment processing | Billing references |
7. How we share data
- With the platforms you connect. We send content to Meta (Facebook and Instagram) so that it can be published as you direct. If your ads point people to WhatsApp, the resulting chats stay between you and them in your own WhatsApp app.
- With our subprocessors. We share data with the providers listed above so that they can operate the service on our behalf.
- For legal reasons. We disclose data where the law requires it, where we must respond to a lawful request, or where disclosure is necessary to protect our rights, our users, or the public.
- On a business transfer. If Synquanta Technologies is involved in a merger, acquisition, or sale of assets, your data may transfer as part of that transaction, and this policy continues to govern it.
We do not sell personal data.
8. Data retention
We keep your personal data for as long as your account is active or as needed to provide the service. When you request deletion, we suspend the account immediately and permanently delete or anonymize your personal data after a 30-day grace period, during which signing in again cancels the request. The only exception is where a legal, tax, security, or audit obligation requires us to retain a specific record. See the Data Deletion page for how to request deletion.
9. Your rights
Under the Nigeria Data Protection Act 2023 (NDPA) and applicable law, you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Request deletion of your data ("right to be forgotten").
- Obtain a portable copy of your data.
- Object to or restrict certain processing.
- Withdraw consent at any time, without affecting prior lawful processing.
You can exercise these rights from within Umbrelar (data export and deletion tools) or by emailing info@synquanta.com. If you are an end customer or lead of a business that uses Umbrelar, please contact that business directly, or contact us and we will assist the business as its processor.
10. Security
We protect data with measures including:
- Encryption at rest for connected-channel access tokens. Every access token we hold for Facebook, for Instagram, or for a connected ad account is encrypted with AES-256-GCM before it is written to our database. The encryption key lives only in our server environment, never in the database and never in the mobile app. Tokens are decrypted in memory on our servers, only at the moment we make a request to Meta on your behalf.
- One-way password hashing (bcrypt). We never store your Umbrelar password in plain text, and we never hold your Facebook or Instagram password at all.
- Encryption of data in transit (HTTPS/TLS) between the app, our servers, and every provider we call.
- Scoped access controls, so each business's data is reachable only within its own workspace.
- Hashed one-time verification codes, and security audit logging of sensitive account actions.
No system is perfectly secure, but we work to protect your information and to respond promptly to incidents.
11. International transfers
Some of our subprocessors operate outside Nigeria (for example, in the United States or the European Union). Where your data is transferred internationally, we take steps to ensure it remains protected consistent with this policy and applicable law.
12. Children
Umbrelar is a business tool intended for users aged 18 and over. We do not knowingly collect personal data from children.
13. Changes to this policy
We update this policy from time to time. When a change is material, we revise the "Last updated" date shown above and, where appropriate, tell you directly. If you continue to use Umbrelar after a change takes effect, you accept the updated policy.
14. Contact us
Synquanta Technologies, operator of Umbrelar
Email: info@synquanta.com