Sassy Tools Privacy Policy
Effective date: September 4, 2026
Last updated: September 4, 2026
1. Who We Are
Sassy Tools is a suite of software products for marketers, agencies, small businesses, and entrepreneurs. Creative Cat LLC owns and operates the Sassy Tools brand and its Sassy Insights product ("Creative Cat," "Sassy Tools," "we," "us," or "our"). Our products include Sassy Insights and other Sassy Tools applications, websites, dashboards, integrations, and related services (collectively, the "Services").
This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information when you use the Services. It also explains the choices and rights available to you.
For clarity, the Growth Keys Insights Meta app (App ID 1708611677075414) is the technical Meta developer app used to connect Meta assets to Sassy Insights. Creative Cat LLC owns and operates this integration. "Growth Keys Insights" is the Meta app name, while Sassy Insights is the customer-facing Sassy Tools product that uses the integration.
2. Scope and Roles
This Privacy Policy applies when you visit sassytools.com, create or use a Sassy Tools account, connect a Facebook or Instagram account, connect Meta business assets, contact us, or otherwise use the Services.
When an agency, business, or other organization uses the Services to process information on behalf of its clients, that organization may determine why and how the information is used. In those circumstances, the organization acts as the data controller or business, and Sassy Tools acts as its service provider or processor. Questions about an organization's use of information should first be directed to that organization.
3. Information We Collect
A. Information You Provide
We may collect:
- Account information, such as your name, email address, organization, role, and login credentials for the Services.
- Workspace information, settings, reporting preferences, client names, and other information you enter into the Services.
- Communications and support information when you contact us, submit feedback, or request assistance.
B. Information Received Through Meta Platforms
When you choose to connect Facebook, Instagram, Meta Business Manager, or Meta advertising assets, we receive data that Meta makes accessible through the permissions you grant and the assets the connecting user selects. Connected content may include information about people who do not use Sassy Tools, as explained below. Depending on the features you enable and the assets you are permitted to manage, this may include:
- Facebook Login information: The standard public_profile scope provides your app-scoped Meta user ID, name, and other public profile fields made available by Meta. Sassy Tools also requests the email scope, which provides your email address when it is available through your Meta account and you authorize access. We process OAuth access tokens, authorization status, and token expiration information needed to maintain the connection. We do not receive or store your Facebook or Instagram password.
- pages_show_list: Page names, Page IDs, access status, and related Page access tokens where provided by Meta. This lets an authorized user discover and select the correct Facebook Pages for a Sassy Insights workspace instead of entering Page identifiers manually.
- pages_read_engagement: Profile information, Page-authored posts and media, and Page-level engagement or performance data available through the Meta APIs. This is used to create Facebook Page content and performance reports. It does not allow Sassy Tools to publish to the Page.
- instagram_basic: Account ID, username, profile information, media objects, captions, media type, media URL or permalink, timestamps, and related metadata for connected Instagram professional accounts. This identifies the correct professional account and supports content-level reporting.
- instagram_manage_insights: Account- and media-level Instagram insights, such as reach, impressions, interactions, engagement, and other metrics Meta makes available. This powers Instagram performance dashboards and reports.
- business_management: Business portfolio IDs and names, connected Pages, Instagram accounts, ad accounts, and the authorized user's relationship to those assets. Agencies and businesses commonly manage client assets through a Meta business portfolio; this permission lets Sassy Insights discover, validate, and organize only the assets the connecting user is authorized to access.
- ads_read: Read-only information from selected Meta ad accounts, including account identifiers, campaigns, ad sets, ads, creative metadata, delivery status, spend, results, and performance metrics. This powers advertising dashboards and client reports and does not permit Sassy Tools to create, edit, or publish campaigns.
The exact information available may change based on your Meta permissions, account type, business role, the assets you select, Meta's API availability, and the features you use. The permissions above are needed because Page, Instagram, business-portfolio, and ad-account discovery and reporting are separate functions in Meta's APIs; a narrower permission cannot supply all of those user-requested reporting features. Sassy Tools does not use these permissions to publish content or modify campaigns.
Authorized Page posts, Instagram media, and ad creative may include names, images, captions, or other information about people who do not use Sassy Tools. We process that information only as part of the asset owner's requested reporting and do not use it to create individual advertising profiles. Requests concerning information contained in an organization's connected assets may need to be handled in coordination with that organization.
C. Information Collected Automatically
When you use the Services, we may automatically collect technical and usage information, including:
- IP address, browser type, device type, operating system, and general location inferred from IP address.
- Pages or features viewed, actions taken, timestamps, referring URLs, and diagnostic events.
- Cookies, local storage, and similar technologies used for authentication, preferences, security, analytics, and Service operation.
- Error logs, performance data, and security events.
4. How We Use Information
We use information to:
- Create, authenticate, maintain, and secure user accounts.
- Connect the Meta assets that a user selects and is authorized to access.
- Import, organize, analyze, and display authorized Facebook, Instagram, business, and advertising data.
- Generate dashboards, reports, comparisons, trends, alerts, and other insights requested by users.
- Allow authorized members of a user's organization or client workspace to view and collaborate on reports.
- Maintain integrations, refresh authorized data, and troubleshoot connection or data-quality issues.
- Provide customer support and respond to requests.
- Monitor performance, prevent fraud or abuse, investigate security incidents, and protect the Services.
- Improve and develop the Services using aggregated or de-identified information where reasonably possible.
- Comply with law, enforce our agreements, and protect our rights and the rights of others.
We do not sell Meta Platform Data. We do not use Meta Platform Data to build advertising profiles about individual users or to target advertising to them. We use Meta Platform Data only to provide and improve the user-requested features of the Services, maintain security, comply with law, and fulfill our obligations under Meta's terms and policies.
5. Legal Bases for Processing
Where applicable law requires a legal basis, we process personal information:
- To perform a contract with you or provide the Services you request.
- With your consent, including when you choose to connect a Meta account or authorize specific assets and permissions.
- For our legitimate interests in operating, securing, supporting, and improving the Services, provided those interests are not overridden by your rights.
- To comply with legal obligations or protect legal rights.
You may withdraw consent or disconnect a Meta integration at any time. Withdrawal does not affect processing that occurred before the withdrawal.
6. How We Disclose Information
We may disclose information:
- Within your organization or workspace: To users whom your organization authorizes to access the same account, client, dashboard, or report.
- To service providers: To vendors that help us host, secure, analyze, and provide the Services. They may process information only to perform services for Sassy Tools and subject to applicable contractual, confidentiality, and security obligations.
- At your direction: When you direct us to export, share, or connect information to another service or recipient.
- For legal and safety purposes: When reasonably necessary to comply with law, legal process, or government requests; enforce agreements; investigate fraud or security issues; or protect rights, safety, and property.
- In a business transaction: In connection with a merger, financing, acquisition, reorganization, or sale of assets, subject to appropriate confidentiality protections and applicable law.
We do not disclose Meta Platform Data to data brokers or sell it to third parties. Our service providers may access it only as necessary to operate or support the Services and must handle it consistently with our obligations to users and Meta.
Our principal service providers include:
- Supabase, which provides database, authentication, and backend infrastructure used to store and process account information, integration credentials, imported Meta data, and application records.
- Cloudflare, which provides network, content-delivery, performance, and security services.
- OpenAI, which processes information submitted to AI-assisted features when those features are used. This may include report content or connected marketing data when necessary to generate an analysis or response requested by the user.
- Google Analytics, which processes website and application usage information, such as pages viewed, device and browser information, and interaction events, to help us understand and improve use of the Services.
7. Data Retention
We retain personal information only for as long as reasonably necessary for the purposes described in this Privacy Policy, including to provide the Services, maintain security, comply with law, resolve disputes, and enforce agreements.
Meta Platform Data is generally retained while the relevant integration and Sassy Tools account remain active and the data is needed to provide requested reporting or analytics features. Raw API responses and refresh caches may be retained for shorter operational periods, while reports and historical metrics may remain in the user's workspace until the relevant asset, workspace, or account is deleted.
When you delete the relevant account or workspace or submit a valid Meta-data deletion request, we will permanently delete identifiable Meta Platform Data under our control as promptly as reasonably practicable and no later than 90 days after we verify the request. This includes stored OAuth tokens, imported asset data, refresh caches, and associated workspace reports within the scope of the request, except where limited retention is required by law or necessary to investigate fraud, abuse, or a security incident.
Disconnecting an integration or removing the app through Meta stops future authorized retrieval after the token is revoked or expires, but does not necessarily delete data already imported into Sassy Tools. Submit a deletion request to ensure previously imported data is deleted.
Aggregated statistics that cannot reasonably be linked to a person, Meta account, or connected business asset may be retained for security and service analytics. Copies that a user previously exported from Sassy Tools or independently shared outside the Services are not under our control and are not automatically deleted from the recipient's systems.
8. Your Choices and Privacy Rights
Depending on your location, you may have the right to request access to, correction of, deletion of, or a copy of your personal information; object to or restrict certain processing; withdraw consent; or appeal our response to a privacy request.
You may also:
- Remove the Sassy Tools or Growth Keys Insights integration through your Facebook or Instagram settings.
- Request deletion of your Sassy Tools account, connected Meta data, or other personal information by following our Data Deletion Instructions or contacting info@creativecat.co.
We may need to verify your identity and authority over the relevant account before completing a request. If you use the Services through an organization, we may direct your request to that organization or coordinate with it.
Sassy Tools does not sell personal information or share personal information for cross-context behavioral advertising as those terms are defined under applicable U.S. state privacy laws.
9. Meta Data Deletion Requests
You can request deletion of information received from Meta regardless of where you live. Send a request to info@creativecat.co with the subject "Meta Data Deletion Request" and include:
- The email address associated with your Sassy Tools account.
- The name and, if available, ID of the connected Facebook Page, Instagram account, business portfolio, or ad account.
- A statement that you want the associated Meta data deleted.
Do not send your Facebook or Instagram password or access token. We may request limited additional information to verify your authority over the Sassy Tools account and connected asset. After verification, we will disable scheduled data refreshes, revoke tokens where Meta provides a revocation method, delete stored tokens under our control, and permanently delete the associated identifiable Meta Platform Data as promptly as reasonably practicable and no later than 90 days after verification. We will confirm completion by email.
Our complete public deletion procedure is available in the Sassy Tools Data Deletion Instructions.
10. Security
We use administrative, technical, and organizational safeguards designed to protect personal information. These measures may include access controls, encryption in transit, restricted production access, logging, monitoring, and vendor review. No system can guarantee absolute security, and users are responsible for maintaining the security of their own accounts and devices.
We do not ask for or store your Facebook or Instagram password. Meta login credentials are entered only through Meta-controlled authentication interfaces.
11. International Data Transfers
Sassy Tools and its service providers may process information in the United States and other countries where privacy laws may differ from those in your location. Where required, we use appropriate safeguards for international transfers.
12. Children's Privacy
The Services are intended for businesses and are not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided personal information to us, contact info@creativecat.co.
13. Third-Party Services
The Services may link to or integrate with third-party services, including Meta products. Those third parties process information under their own terms and privacy policies. Meta's handling of information is governed by Meta's own privacy policy and settings. This Privacy Policy governs Sassy Tools' handling of information it receives or processes.
14. Changes to This Privacy Policy
We may update this Privacy Policy as our Services, integrations, or legal obligations change. We will post the updated version with a revised "Last updated" date and provide additional notice when required by law.
15. Contact Us
For privacy questions, requests, or complaints, contact:
Creative Cat LLC — operator of Sassy Tools
Email: info@creativecat.co
If applicable law gives you the right to complain to a data protection authority, you may also contact the authority in your location.