App Stores

Privacy Policy for Meta, Facebook & Instagram Apps

To pass Meta App Review — for Facebook Login, the Graph API, or Instagram integrations — you need a privacy policy URL that Meta’s reviewer can actually load, and it must address the data you receive from Meta’s platforms.

Create My Privacy Policy

Last updated July 8, 2026

Why this affects your privacy policy

Meta’s Platform Terms require every app to have a privacy policy that explains what data you collect and how you use it. When you use Facebook Login or the Graph API, you receive profile data such as name, email, and profile picture; Meta expects this to be reflected in your policy, along with an explicit reference to Meta where you share data with it.

Data typically processed

Data type Details
Facebook profile data Name, email, profile picture, and any scopes you request via Login.
Facebook/Instagram user ID The platform-scoped identifier for the user.
Graph API data Any additional permissions you request and are granted.
SDK signals Event and device data if you include the Meta SDK/pixel.

What to disclose

  • That users can sign in with Facebook and what profile data you receive.
  • An explicit reference to Meta Platforms, Inc. where you share data with it.
  • The permissions/scopes you request and why.
  • How users can revoke access and delete data (including a data-deletion callback/instructions).
  • A privacy policy URL that loads over HTTPS and is not behind a login.

Example wording

Signing in with Facebook. If you choose to sign in using Facebook, we receive basic profile information from Meta Platforms, Inc. — such as your name, email address, and profile picture — based on the permissions you approve. We use this information only to create and manage your account. You can revoke our access at any time in your Facebook settings and request deletion of your data using the contact details below.

Sample language only — adapt it to your actual data practices.

Best practices

  • Reference “Meta Platforms, Inc.” explicitly — generic “third-party services” language is often rejected for Login apps.
  • Provide a data-deletion instruction URL or callback; Meta requires a way for users to request deletion.
  • Never use a Notion page or a site behind a login as your policy URL — Meta’s bot often cannot fetch it.
  • Only request the minimum Login scopes you actually use.

Generate a policy that already covers Meta / Facebook and host it at a permanent URL.

Host Your Policy

Frequently asked questions

Why does Meta App Review keep rejecting my privacy policy?

The most common reasons: the URL doesn’t resolve for Meta’s bot (Notion/redirects/login walls), or the policy never mentions Meta/Facebook despite using Facebook Login. A stable hosted HTTPS URL that names Meta fixes most cases.

Do I need a data-deletion callback?

Meta requires that users can request deletion of the data your app obtained. You can implement a data-deletion callback or provide clear deletion instructions; either way, reference it in your policy.

My app only uses Facebook Login — do I really need all this?

Yes. Facebook Login gives you personal data (name, email), so a compliant privacy policy is mandatory to pass review.

Related guides

This guide is for general informational purposes only and is not legal advice. Your privacy policy should reflect your actual data practices and applicable legal requirements, which vary by jurisdiction and platform.

Create and host your privacy policy

Fill out a short form, get a permanent HTTPS URL for your app submission.

Create My Privacy Policy