Data and security

How access tokens and messages are stored, who can see them, and how to remove your data

Access tokens

Connecting an account gives Arolead a Meta access token for it. Tokens are encrypted at rest with AES-256-GCM and decrypted only when a request to Meta is made on your behalf. They are never shown in the product, never logged, and never sent anywhere except Meta.

Messages and media

Conversations are stored so the inbox and the lead timeline have history. Media attachments are copied into private storage before Meta's temporary links expire, and served through signed URLs that expire.

Removing your data

  • Disconnect an account in Accounts: the token is removed and the account's automations are deactivated.
  • Delete your account and data by writing to support from the dashboard. Deletion removes your workspace, leads, conversations, documents and tokens.
  • Revoking Arolead inside Facebook, Instagram or WhatsApp Manager stops access on Meta's side immediately, regardless of what is stored here.

Payments

Card details are never stored by Arolead; the payment processor holds them. WhatsApp message fees are billed by Meta directly against your own Billing Hub.

Questions

Write to support from the dashboard, or read the privacy policy.