Privacy policy
Effective date: September 29, 2026 · Last updated: September 29, 2026
Who we are
QueueCove (“QueueCove”, “we”, “us”) is a social media scheduling and publishing tool. It lets a business connect its Facebook Pages and Instagram professional accounts, prepare captions and media, schedule posts, and publish them. QueueCove is operated by Prabhava Labs, based in Sri Lanka.
A workspace administrator connects their own Facebook Pages and Instagram accounts and decides what to schedule and publish; QueueCove acts on the workspace’s behalf to do that. If you are a follower or customer who sees content a business published through QueueCove, this policy does not cover how that business itself handles your data. Contact the business directly.
Information we collect
- Account details: your email address, display name, and password, stored as a salted hash, never in plain text. If you enable two-factor authentication, we store your authenticator secret encrypted, not the codes it generates.
- Workspace content: captions, titles, links, schedules, time zones, drafts, and workspace settings you create in QueueCove, and a record of who did what in the workspace (the audit trail).
- Media you upload: the image and video files themselves, plus technical properties we read from them, such as file size, dimensions, and duration, to validate them before scheduling.
- Sign-in data: a session identifier tied to your account, and, briefly and only in server memory, your IP address, used to rate-limit sign-in and password-reset attempts. We do not store IP addresses in the database or write them to logs.
- Data from connected Meta accounts: described separately below.
We do not sell or share your personal information, and we do not use it for advertising, profiling, or training generative models.
Data from your Meta accounts
When a workspace administrator connects a Facebook Page or a linked Instagram professional account, they do so through Facebook Login for Business, Meta’s own consent screen. We never see or store a Facebook password. The connection requests four permissions:
pages_show_list: lets QueueCove list the Facebook Pages you manage, so you can choose which ones to connect.pages_manage_posts: lets QueueCove publish the posts you compose and schedule to the Facebook Page you connected.instagram_basic: lets QueueCove read your linked Instagram professional account’s basic identity, its id, username, and name, to confirm the connection and show it in the workspace.instagram_content_publish: lets QueueCove publish the photos, videos, and carousels you schedule to that Instagram account.
For each connected account, we store: the Page or Instagram account’s id, name, and username; a long-lived access token, encrypted at rest with AES-256-GCM and never returned by our API once stored; the permissions Meta granted; the app-scoped Meta user id of the person who authorized the connection, kept only so we can act on Meta’s own deauthorize and data deletion callbacks (see Meta Platform disclosures); and the outcome of each publish attempt, a post id, a public permalink, or an error message.
We use this data only to publish content a workspace member schedules, to show whether a connection is healthy or about to lapse, and to report each attempt’s result. When you schedule media, we hand Meta a short-lived, signed link to that exact file so Meta can fetch it, and nothing else. Our handling of data obtained through the Graph API is also bound by Meta’s own Platform Terms and Developer Policies, in addition to this policy.
How we use information and why
- to operate the service: sign you in, enforce workspace membership and roles, and store your drafts and media;
- to publish and schedule content at your direction, and show you the outcome of each attempt;
- to warn you about an expiring Meta connection or a failed post so you can act on it;
- to keep the service secure, prevent abuse, and diagnose errors;
- to send service email you request or need: verification links, password resets, and security notices about your account;
- to comply with legal obligations and respond to lawful requests.
Where a legal basis is required for processing, we rely on performance of a contract with you or your workspace (running the service and publishing what you schedule), legitimate interests (keeping the service secure, preventing abuse, and improving it), and legal obligation (recordkeeping and lawful requests). We do not rely on consent as a legal basis except where a specific feature asks for it.
Retention and deletion
- Meta tokens: deleted immediately when you disconnect an account in the app, when you remove QueueCove from Facebook (which triggers Meta’s deauthorize callback), or when Meta notifies us of a data deletion request for the person who authorized it. If Meta’s data access for a token lapses (about 90 days without reconnecting), the token stops working and the app asks you to reconnect or disconnect the account.
- Uploaded media: kept while it is in your workspace’s media library or referenced by a scheduled post, and deleted from storage immediately when you remove it. A file that a scheduled post still uses cannot be removed until you unschedule that post.
- Posts, publishing history, and the audit trail: kept for as long as your workspace exists, so you have an accurate publishing record, and deleted when the workspace or account is deleted.
- Account and workspace data: deleting your account or a workspace from account settings deletes its data in a single operation, immediately, not on a delay. Deleting your account also deletes every workspace where you are the only member; a workspace you share with others just removes your membership from it.
- Backups: we keep access-restricted daily database backups for 7 days, weekly backups for 4 weeks, and monthly backups for 6 months, plus daily copies of media, so that we can recover from an outage or a mistake. Data you delete from the live service can persist in these backups until they roll off this schedule.
- Logs: our request logs record only the method, path, status code, duration, and a request id, never headers, request bodies, passwords, tokens, or captions, and we keep them for up to 30 days.
Security
Meta access tokens are encrypted at rest with AES-256-GCM, under a key held only in server configuration, never in the database, and are never returned by our API once stored. Sessions are random tokens; only a SHA-256 digest of the token is stored, so a copy of the database alone cannot sign in as you. Traffic to the site and app is encrypted in transit (HTTPS). Access to production systems is limited to the people who need it to operate QueueCove. No method of storage or transmission is completely secure, and we cannot guarantee absolute security.
Your rights and choices
You can review, export, and delete your account data, and disconnect any Meta account, from account settings in the app at any time; the Export my data button gives you a JSON download of your profile and every workspace you belong to.
If Sri Lanka’s Personal Data Protection Act, No. 9 of 2022 (as amended), applies to you, you have the right to access your personal data, correct it, have it erased, object to how we use it, and withdraw consent where we rely on it. The Data Protection Authority of Sri Lanka is the regulator for these rights and hears complaints about how we handle personal data.
If you are in the European Economic Area, the United Kingdom, or Switzerland, you have the same rights under the GDPR or UK GDPR: access, rectification, erasure, restriction, objection, and portability where it applies, and the right to lodge a complaint with your local data protection supervisory authority (the ICO in the United Kingdom, or your national authority in the EU).
To exercise a right that account settings do not cover, write to us at privacy@prabhavalabs.com.
Meta Platform disclosures
Our use of data obtained through Facebook Login for Business and the Graph API is bound by Meta’s own Platform Terms and Developer Policies, in addition to this policy. Under those terms we may use Platform Data only to provide QueueCove’s scheduling and publishing features to you, we do not sell it, and we delete it once it is no longer needed for that purpose or when you or Meta ask us to.
You can remove QueueCove’s access to your Facebook and Instagram accounts at any time from Facebook, independent of anything in the app: open Facebook Settings → Business Integrations, find QueueCove, and remove it. Doing so calls our deauthorize callback automatically, and we revoke the connection and delete its stored token without further action from you.
You can separately ask Meta to have your data deleted from QueueCove, from the same Business Integrations settings. We answer that request right away by deleting the Meta access token and every identifier tied to your Meta account, and by giving Meta a status page you can check at any time: app.queuecove.prabhavalabs.com/data-deletion?code=<confirmation code>. See the in-app data deletion page for the full steps.
International transfers
Prabhava Labs is based in Sri Lanka, and our subprocessors (Cloudflare, Resend, and our hosting provider) operate infrastructure in other countries as part of their global networks; Resend sends email from its EU region. Where personal information moves from a region with its own transfer rules, such as the EEA, the UK, or Switzerland, to a country without an equivalent adequacy decision, we rely on standard contractual clauses or an equivalent safeguard in our agreement with that subprocessor.
Children
QueueCove is a business tool and you must be at least 18 years old to use it. We do not knowingly collect personal information from anyone under 18. If you believe a child has given us personal information, contact us at the address below and we will delete it.
Changes to this policy
We will post updates on this page and change the “Last updated” date above. For a material change, we will also notify workspace owners by email or an in-app notice before it takes effect.
Contact
For privacy questions or to exercise a data-protection right, write to privacy@prabhavalabs.com. For anything else, write to support@prabhavalabs.com. QueueCove is operated by Prabhava Labs, based in Sri Lanka.