# Privacy policy requirements for Facebook and Meta apps

> Meta Platform Terms require a public privacy policy URL, clear processing disclosures, and a way to request data deletion. What to include for apps.

Meta's Platform Terms require developers who use Facebook Login, Instagram APIs, the Graph API, or other Meta platform features to provide, maintain, and comply with a privacy policy available at an active, publicly available, easily accessible URL. The policy must explain what data you process, how and why, and how users can request deletion, and you must give users an easily accessible and clearly marked way to ask for their platform data to be modified or deleted.

Canonical URL: https://legalpolicygenerator.com/resources/facebook-app-privacy-policy

## What the Platform Terms require

Section 4.a of the Meta Platform Terms requires you to provide, maintain, and comply with a privacy policy that is available through an active, publicly available, easily accessible URL. Section 4.b requires the policy to clearly explain what data you are processing, how you process it, the purposes for which you process it, and how users may request deletion of that data. Section 3.d.i requires an easily accessible and clearly marked way for users to ask for their platform data to be modified or deleted.

## Where the policy and deletion route are provided

The privacy policy URL and the deletion method are configured in the app's settings in Meta's App Dashboard, which checks that the policy URL loads. Meta has offered both a data deletion instructions URL and a data deletion callback that your server implements. Confirm the current field names and options in the dashboard before submitting for review, because they change over time.

## Describing Facebook Login and API data

Facebook Login typically provides a user ID scoped to your app, name, profile picture, and email address if the permission is granted; other permissions can provide pages, posts, Instagram content, or business assets. Your policy should list the permissions you request, the data each provides, why you need it, how long you store it, and whether you combine it with other data. App Review looks for alignment between requested permissions, demonstrated use, and the policy.

## Explaining deletion

The policy must tell users how to request deletion of data obtained from Meta. If you use deletion instructions, give concrete steps and a contact route; if you implement a callback, explain that removing the app in Facebook settings triggers deletion and give a status link or confirmation code. Describe any data you must keep for legal reasons and for how long.

## Meta Pixel, Conversions API, and SDKs

Using the Meta Pixel, Conversions API, or Meta SDKs for advertising sends browsing or app events, and sometimes hashed customer information, to Meta. That is separate from Facebook Login and belongs in the advertising and tracking sections of your policy, with the applicable consent or opt-out wording. Under California law this activity is commonly treated as sharing for cross-context behavioral advertising.

## Restrictions to reflect in your practices

The Platform Terms restrict selling platform data, using it for discrimination, eligibility decisions, surveillance, or building user profiles for data brokers, and they require security measures, incident notification, and cooperation with audits. Your policy should not describe uses of platform data that the terms prohibit, and it should describe your actual security and retention approach without guarantees.

## Data use checkups and ongoing review

Meta may ask developers to review and certify their data use periodically and can request information about how platform data is processed. Keep an internal record of the permissions requested, the features that use them, where the data is stored, and your deletion process, so that the policy and any certification describe the same practices. Remove permissions you no longer use rather than keeping them in case they become useful.

## Generating the policy

Choose the platforms that match your product, select Meta under third-party services and, if you use the social features, the relevant social uses such as social login or embedded content. If you run Meta advertising, select the advertising level and Meta as a provider so the advertising and consent clauses activate. Add a short section listing the specific Meta permissions and your deletion method, and link the hosted policy in the App Dashboard.

## Common questions

### Does a website with only a Facebook Like button need this?

The Platform Terms target apps that use Meta platform features and data. A website embedding social plugins still needs to disclose the embedded third-party content and any cookies it sets in its own privacy policy.

### Can I use the same policy for my app and website?

Yes, if it clearly covers the Meta integration, the permissions requested, and the deletion method in addition to your general practices.

Generated wording reflects supplied facts. It is not legal advice or a guarantee of compliance or enforceability.
