Who this policy covers
This policy applies to the Narrative Field website, dashboard, monitoring service, and related notifications. Narrative Field LLC is the controller for account, website, billing, and service-usage data. A customer may be the controller of monitoring instructions and material it directs us to process.
Independent service
Narrative Field is not affiliated with, endorsed by, or sponsored by Meta or Facebook. Use of Facebook content remains subject to applicable law, platform terms, and required permissions.
Data we collect
Account and authentication
We process your email address, account identifiers, authentication sessions, invitations, passkey metadata when used, account role, time zone, and workspace preferences. Magic-link tokens are short-lived security credentials and are not sent to analytics.
Workspace and monitoring data
We process submitted Facebook group URLs and identifiers, public/private classification, approval status, monitoring prompt titles and instructions, and group-to-workspace assignments. For approved coverage, we may process post text, author and group names, post URLs and identifiers, timestamps, listing details, and image URLs or related metadata made available to the monitored account.
Identified results and AI processing
We store matching decisions, confidence, reason codes, processing status, and delivery status. Relevant post text and a monitoring prompt may be sent to an AI provider to determine whether the post satisfies your instructions.
Billing and notifications
We store Stripe customer, subscription, price, invoice, and payment-status identifiers. Stripe handles payment-card details; Narrative Field does not store full card numbers. If configured, we process notification email addresses, Slack webhook destinations, WhatsApp phone numbers, opt-in records, delivery status, and usage counts.
Website contact inquiries
When you use the contact form, we process your name, work email, optional company name, message, and limited security information needed to prevent abuse. The form uses a first-party, signed security question; it does not require advertising cookies, behavioral tracking, or an external CAPTCHA service.
Technical and analytics data
We process security and operational logs such as request times, service errors, delivery events, and limited network/device data needed to protect and operate the service. For new account registrations, this includes the server-observed IP address, approximate country or region, network/ASN, VPN, proxy, Tor, hosting and abuse signals, first landing page, referring site, and supplied UTM campaign parameters. These signals help us investigate automated registrations and service abuse; they are not treated as conclusive proof by themselves. PostHog and Firebase Analytics are optional and begin only after you select “Allow analytics." Separately, limited pseudonymous account, sign-in, and subscription lifecycle events are measured server-side under our legitimate interest in operating and improving the service. These use an internal account ID and do not send the account name or email address. We deliberately exclude query strings, monitoring prompts, captured post content, magic-link tokens, and notification destinations. For consenting signed-in users, PostHog receives the internal account ID, name, email address, role, and selected product actions so we can measure activation and conversion. Dashboard text and form inputs are masked in session recordings.
How and why we use data
- Provide the contract: authenticate users, monitor approved groups, evaluate posts, display results, send selected notifications, and manage subscriptions.
- Legitimate interests: secure the service, prevent abuse, respond to requested sales or support inquiries, diagnose failures, measure reliability, and improve result quality where those interests do not override your rights.
- Consent: optional website analytics and notification channels where consent or opt-in is required.
- Legal obligations: billing, tax, fraud prevention, lawful requests, and enforcement of our agreements.
We do not sell personal data and do not use monitoring prompts or captured post content for advertising.
Service providers and disclosures
We disclose only what is reasonably needed for the service:
- Stripe for subscriptions, invoices, payment status, and customer billing portals.
- Resend for sign-in, account, subscription, group-status, monitoring, and website-inquiry emails.
- OpenRouter and the selected model provider for contextual evaluation of posts against monitoring prompts.
- Twilio for WhatsApp delivery when a customer enables that channel.
- Slack when a customer supplies a webhook and enables Slack delivery.
- Google Firebase for consent-based website analytics and static hosting of a public site copy.
- PostHog for consent-based website and product analytics, funnels, heatmaps, and privacy-masked session replay.
- ipapi.is for server-side signup IP geolocation, ASN, hosting, VPN, proxy, Tor, and abuse-risk classification.
- Infrastructure and security vendors that host or protect the service.
We may also disclose data when required by law, to protect rights or safety, or as part of a merger, acquisition, financing, or sale subject to appropriate confidentiality and notice requirements.
Some providers operate internationally. Where required, we use recognized transfer safeguards or rely on provider transfer mechanisms.
Your choices and rights
Depending on your location, you may request access, correction, deletion, restriction, portability, or objection, and may withdraw consent at any time. You may manage optional analytics in the Cookie Policy, manage notification channels in the dashboard, and manage billing through Stripe.
Use the account-deletion process or email support@narrativefield.com from your account email. We may verify identity before acting. Some information may be retained where law or a valid exception requires it.
See the Data Retention Policy for category-specific periods.
Security and children
We use access controls, encrypted transport, server-side session checks, tenant-scoped queries, encrypted notification credentials, credential rotation procedures, and operational monitoring. No security control eliminates all risk, so please report suspected compromise immediately.
The service is intended for business users aged 18 or older and is not directed to children. Do not use monitoring prompts to intentionally identify or profile children.
Changes and contact
We may update this policy as the service or law changes. Material changes will be posted here and, where appropriate, communicated through the account email or dashboard.
Privacy and data-rights requests: support@narrativefield.com.
