When an authorized workspace owner or administrator connects Meta, we receive the Meta user identity, granted permission status, accessible Business Portfolios, Ad Accounts, Facebook Pages, and an optional Instagram professional account linked to a selected Page.
Meta access tokens and Page tokens are encrypted and stored server-side. Meta-derived asset data is used for connection validation, explicit asset selection, and manually approved creation of advertising objects in PAUSED status. It is not included in OpenAI prompts.
Connection records are retained while the integration remains connected. Users can disconnect Meta to request remote permission revocation and irreversible local credential deletion, or use the verified data-deletion workflow.