Privacy Policy for Meta, Facebook & Instagram Apps
To pass Meta App Review — for Facebook Login, the Graph API, or Instagram integrations — you need a privacy policy URL that Meta’s reviewer can actually load, and it must address the data you receive from Meta’s platforms.
Create My Privacy PolicyLast updated July 8, 2026
Why this affects your privacy policy
Meta’s Platform Terms require every app to have a privacy policy that explains what data you collect and how you use it. When you use Facebook Login or the Graph API, you receive profile data such as name, email, and profile picture; Meta expects this to be reflected in your policy, along with an explicit reference to Meta where you share data with it.
Data typically processed
| Data type | Details |
|---|---|
| Facebook profile data | Name, email, profile picture, and any scopes you request via Login. |
| Facebook/Instagram user ID | The platform-scoped identifier for the user. |
| Graph API data | Any additional permissions you request and are granted. |
| SDK signals | Event and device data if you include the Meta SDK/pixel. |
What to disclose
- That users can sign in with Facebook and what profile data you receive.
- An explicit reference to Meta Platforms, Inc. where you share data with it.
- The permissions/scopes you request and why.
- How users can revoke access and delete data (including a data-deletion callback/instructions).
- A privacy policy URL that loads over HTTPS and is not behind a login.
Example wording
Signing in with Facebook. If you choose to sign in using Facebook, we receive basic profile information from Meta Platforms, Inc. — such as your name, email address, and profile picture — based on the permissions you approve. We use this information only to create and manage your account. You can revoke our access at any time in your Facebook settings and request deletion of your data using the contact details below.
Sample language only — adapt it to your actual data practices.
Best practices
- → Reference “Meta Platforms, Inc.” explicitly — generic “third-party services” language is often rejected for Login apps.
- → Provide a data-deletion instruction URL or callback; Meta requires a way for users to request deletion.
- → Never use a Notion page or a site behind a login as your policy URL — Meta’s bot often cannot fetch it.
- → Only request the minimum Login scopes you actually use.
Generate a policy that already covers Meta / Facebook and host it at a permanent URL.
Host Your PolicyFrequently asked questions
Why does Meta App Review keep rejecting my privacy policy?
Do I need a data-deletion callback?
My app only uses Facebook Login — do I really need all this?
Related guides
This guide is for general informational purposes only and is not legal advice. Your privacy policy should reflect your actual data practices and applicable legal requirements, which vary by jurisdiction and platform.
Create and host your privacy policy
Fill out a short form, get a permanent HTTPS URL for your app submission.
Create My Privacy Policy