PUBLIC POLICY · UPDATED 28 AUGUST 2026
Privacy policy
This policy explains how Alejandro Carbajo Vidales handles personal data through alejandrocarbajo.com and the owner-operated PersonalBrand Social Connector used with Alejandro's Facebook Page and Instagram creator account.
Who is responsible
The data controller is Alejandro Carbajo Vidales, based in Spain. Privacy questions and requests can be sent to carbaj03@gmail.com.
Website measurement
The website records aggregate page paths, language and explicit newsletter or portfolio actions through Cloudflare Web Analytics and a first-party Cloudflare Analytics Engine endpoint. These measurements do not set advertising cookies, create a cross-site profile or intentionally store an IP address, email address or other visitor identifier. They are used to understand which public pages are useful and where a person chooses to continue.
Data the connector processes
When Meta sends an authorized webhook event, the connector may process account, Page, media, comment, message or mention identifiers; event types and timestamps; bounded source references; and integrity hashes used for deduplication and security.
The webhook ingress does not intentionally retain comment or message bodies. Raw webhook bodies are verified, normalized and discarded. If source-text processing is separately enabled, the reply worker retrieves a public comment and bounded public post context just in time through Meta's official API. In SHADOW mode it may classify and draft, but it cannot write to the provider. It does not send private messages or intentionally retain the source text locally.
A public comment that passes deterministic private, crisis, safety and injection pre-screening may be sent transiently to OpenAI through the locally authenticated Codex service to decide whether no action or a bounded public reply is appropriate. Generated reply artifacts are stored privately with an integrity hash before any authorization. Provider access tokens and app secrets remain in the macOS Keychain and are not passed to the Codex subprocess through its input or environment.
Why the data is used
- to authenticate and operate the exact social accounts Alejandro owns or manages;
- to publish content that has passed the applicable approval boundary;
- to receive, deduplicate and classify authorized interaction events;
- to protect the service, investigate delivery failures and maintain an accountability record;
- to respond to a person only when the applicable platform, privacy, safety and policy-authorization rules allow it.
Where applicable, this processing is based on the account owner's authorization, consent, performance of a requested service, and the legitimate interest in operating and securing the connector. Consent or account authorization can be withdrawn at any time.
Storage and retention
Normalized terminal webhook metadata is retained for up to 30 days and then tombstoned or redacted under the connector's retention process. Credentials remain until they are revoked, rotated or no longer required. Minimal security, deletion and publication records, including generated public reply text and its hash, may be retained when necessary to demonstrate that a request or public action was handled correctly.
OpenAI processes text sent through Codex under the ChatGPT account's terms and data controls. Autonomous source-text processing remains disabled unless the account-wide “Improve the model for everyone” control is off. An ephemeral local Codex run prevents a persistent local session; it is not a promise that OpenAI retains no service-side safety or operational data.
Who receives data
Data is not sold. Meta provides the Facebook and Instagram APIs. Cloudflare supplies DNS and encrypted tunnel transport only. OpenAI supplies the Codex model used for pre-screened public-comment no-action or bounded-reply decisions. Durable ingress storage and the policy, authorization and provider-execution services run on Alejandro's local Mac Mini. These providers process data under their own terms and privacy policies.
Your choices and rights
Depending on applicable law, you may request access, correction, deletion, restriction, objection or portability, and may withdraw consent. You can also revoke the app directly in Facebook or Instagram's Apps and Websites settings. See the data-deletion instructions for the practical route. OpenAI also provides a privacy request portal for data it controls.
Security and children
The connector uses signed webhooks, exact route allowlists, loopback-only local service binding, Keychain-backed credentials and platform kill switches. No system can guarantee absolute security. The connector is not directed to children and is not intended to collect children's data.
Changes
Material changes will be published on this page with a new effective date. Questions can be sent to carbaj03@gmail.com.
Current automation boundary: an integration being technically connected does not by itself authorize a post, reply or private interaction. The autonomous reply worker remains in shadow mode until its independent privacy, qualification and official readback gates pass.