Privacy Policy
Last updated 16 September 2026
Tallgrass reads posts you are already looking at on Facebook and scores them against the median for their own group. This page says exactly what that means for your data, in the order that matters: what leaves your browser, who else sees it, and how to get rid of it.
What the extension collects
The extension only reads a page while a scan is running — after you press Start in the extension window. Opening Facebook, or opening a group, collects nothing. When you press Stop, it stops.
While scanning, it reads the posts visible on the page you are on:
- the post's text
- the author's display name and profile link
- reaction, comment and share counts
- the link to the post, its type (photo, reel, link…) and its timestamp
- the address of the post's main image, so the dashboard can show a thumbnail
- the name and address of the group, page or profile you are viewing
Comments on your posts
When you open a post and press Save comments to Tallgrass, the extension reads that one post's comment thread and nothing else. For each comment and reply it reads the commenter's display name, the comment's text, its link, and whether a reply on the page is from you. That happens only when you press the button; opening a post reads nothing.
Messenger
On facebook.com/messages, and only when you press a button:
- Find unanswered chats reads the chat list on your screen. For each chat it sends only who the chat is with, the chat's link, whether you or they sent the last message, roughly when, whether it is unread, whether the last message looked like a question or an opportunity, and a one-way fingerprint of that message so a new message can be noticed. The message text itself is not sent or stored. That judgement is made in your browser.
- Suggest a message reads the recent messages in the conversation you have open and sends them to the AI provider once, to write a draft. The conversation is not stored by Tallgrass, and the draft is put in Messenger's box for you to send — Tallgrass never sends a message.
- AI sorting is off unless you turn it on in Settings. When it is on, the preview line the chat list shows for each chat waiting on you, and the recent messages of a chat you open, are sent to the AI provider once so it can label the chat (opportunity, question, not now). The text is not stored; the label and a reason of a few words are.
What it does not collect
- Your Facebook password, or any Facebook credential. The extension never sees the login form.
- Your Facebook cookies or session token.
- The text of your messages, except as described under Messenger above: sent to the AI provider for a draft when you ask, or to be sorted if you turned AI sorting on — and never stored.
- Your friend list, your notifications, or your own profile data.
- Comment text during a scan. A scan reads only the comment count; comments themselves are read only from a post you open and save, as described above.
- Private groups you are not a member of. The extension can only see what your own logged-in account can already see on screen.
It has no ability to browse on its own. It reads the tab you are looking at, and only while you have a scan running.
What the dashboard stores
- Your account: your email address and a password hash. Your password is stored using scrypt and is never stored, logged or transmitted in readable form.
- Your API key: stored as a hash, not as the key itself. We cannot read your key back — a lost key has to be reissued, not recovered.
- Your captured posts: the fields listed above, kept under your account and visible only to you.
- Messenger chats: the chat summaries described above — names, links, who spoke last and when, and with AI sorting on a label and a few-word reason; never message text. Forget all chats on the Messages page removes them immediately.
- Comments you save: the commenter names, comment text and links described above, kept under your account and visible only to you. Forget on the Comments page removes a post's comments immediately.
When your posts are sent to an AI provider
This is the one place your captured data leaves our servers, so it is worth being blunt about it.
If you use Sage, remix, Suggest reply or Suggest a message — or save comments while an AI key is set up, which sends each new comment once so it can be sorted into hot lead, question, praise, tag or spam — the posts, comments or messages involved are sent to a third-party AI provider — Anthropic or OpenAI, whichever is configured — so it can answer or rewrite. Those posts are typically written by other people, so you are sending someone else's public post to a third party. Both providers state that API content is not used to train their models, but it does leave our infrastructure.
These features are optional and off unless a key is configured. If you never use Sage or remix, nothing you capture is ever sent to an AI provider.
If you save your own provider API key in settings, it is stored in our database so it can be replayed on your requests. Unlike your password, a provider key cannot be hashed — it has to be sent onward to work. Prefer setting it as a server environment variable if that matters to you.
Payments
Card details never touch Tallgrass. Checkout is hosted by Stripe on Stripe's own page, and we never see, receive or store your card number. We store only your Stripe customer and subscription identifiers and your plan status, so we know what you are entitled to.
Who else receives data
- Render — hosts the application and its database.
- Stripe — payments and subscription status.
- Anthropic or OpenAI — only when you use Sage or remix, as described above.
There are no analytics trackers, no advertising pixels, and no third-party scripts on the dashboard. We do not sell your data, and we do not share it with anyone not named on this page.
Cookies
One cookie, holding your login session. It is HttpOnly,
SameSite=Lax, and marked Secure when served over
HTTPS. There are no advertising or analytics cookies, which is why you are
not being asked to accept anything.
Keeping and deleting your data
Captured posts stay until you delete them. Clear all captures in Settings erases every post under your account immediately. To delete your account and everything attached to it, email us and it will be removed.
You may request a copy of your data, correction of it, or its deletion, at the address below.
Other people's posts
Most of what Tallgrass stores was written by other people. It is collected from pages your own account can already see, it is kept private to you, and it is never published or resold. If you are a Facebook user and believe your posts are held here, write to us and we will remove them.
Children
Tallgrass is a business tool and is not intended for anyone under 16. We do not knowingly collect data from children.
Changes
If this policy changes in a way that affects what we collect or who receives it, the date at the top changes and material changes are announced in the app.
Contact
Questions, deletion requests, or anything else: macrandleacres@gmail.com.
Tallgrass by MacRandle Acres.