Atribu

Data Deletion

Last updated: October 8, 2026

1. Your right to data deletion

You have the right to request the deletion of your personal data from Atribu at any time. This includes data collected through your account, connected integrations, and any data obtained via Facebook Login, other Meta integrations, or GoHighLevel.

2. What data we store

When you connect your Meta (Facebook/Instagram) account to Atribu, we may store the following data:

  • Ad account information — campaign structure, ad sets, ads, and creative metadata.
  • Advertising metrics — spend, impressions, clicks, reach, and frequency data at the ad level.
  • OAuth tokens — encrypted access tokens used to fetch data from the Meta Ads API on your behalf, and, when a business connects a messaging channel, the encrypted access token of the connected Facebook Page, Instagram account or WhatsApp Business account.
  • Messages sent to a connected business — when a business connects a Facebook Page (Messenger), an Instagram account or a WhatsApp Business account, the messages people send to it. See “Messages” below for what we keep and for how long.

We never receive your Facebook password, and we do not read content from your personal Facebook profile or timeline.

Messages

Facebook Messenger. Atribu does not keep a Messenger conversation history. Each message a person sends to a connected Facebook Page is forwarded to the inbox application the business connected through Atribu (for example, Vitrina), which stores and displays the conversation. To deliver those messages reliably, Atribu keeps:

  • a copy of each forwarded event, including the message text, in its delivery log, so a failed delivery can be retried. These copies are deleted in monthly batches between three and four months after they were written;
  • a copy in its delivery queue, whose message content is removed after 2 days and which is deleted after 7 days;
  • a receipt of each webhook Meta sends us, with the identifiers and timestamps but without the message text or attachments, for 30 days.

Instagram and WhatsApp. When a business uses Atribu with an Instagram account or a WhatsApp Business account, the conversations and messages are stored as part of that business’s workspace. They are kept while the channel exists in the workspace — including after an inbox application’s access to it is revoked — and are deleted when the business disconnects the channel or when deletion is requested as described below.

GoHighLevel data

When you connect a GoHighLevel location to Atribu, we store the following data from it:

  • Contacts — name, email address, phone number and the attribution source (such as UTM parameters) recorded on the contact.
  • Opportunities — the pipeline stage and the monetary value of each opportunity.
  • Appointments — appointment events GoHighLevel sends to Atribu by webhook.
  • OAuth tokens — the access and refresh tokens GoHighLevel issues when you install the app, stored encrypted.

3. How to request data deletion

To request deletion of your data, you can use any of the following methods:

Option A: Delete from within Atribu

Sign in to your Atribu account, navigate to Settings → Integrations, and disconnect the Meta integration. This will revoke the OAuth connection and schedule deletion of all associated Meta data from your profile.

Messaging channels: disconnect the channel or the app

When a business disconnects a Facebook Page (Messenger), Instagram or WhatsApp channel, Atribu deletes the stored access token for it. Atribu also removes its webhook subscription from the Facebook Page or WhatsApp Business account, unless another Atribu connection still uses the same Page or account. (Meta offers no way to remove the subscription of an Instagram account connected with Instagram Login; once the channel is disconnected, Atribu discards anything Meta still sends for it.)

When an inbox application’s access to a Messenger, Instagram or WhatsApp channel is revoked — by the business in Atribu (Connected apps), or by the application itself — Atribu deletes the stored access token for that channel, removes its webhook subscription on the same terms as above, and stops receiving and sending messages for it. The channel’s existing conversations are kept as part of the business’s records (they can be deleted through Option B), and reconnecting the channel restores it.

Messages already forwarded stay in the delivery records described above until those periods expire. To have them deleted sooner, use Option B.

GoHighLevel: disconnect the integration

In Atribu, go to Settings → Integrations → GoHighLevel → ⋯ → Disconnect. Atribu then deletes the stored GoHighLevel token, stops syncing that location, and calls GoHighLevel’s Uninstall API so the app is removed from the location on GoHighLevel’s side too. If another Atribu profile is still connected to the same GoHighLevel location, Atribu keeps the installation in place and only removes the connection you disconnected.

Disconnecting stops new data from arriving but does not delete the contacts, opportunities and appointments already synced into your workspace. To have them deleted, use Option B below.

Option B: Email us directly

Send an email to [email protected] with the subject line “Data Deletion Request.” Include the email address associated with your Atribu account. We will confirm receipt and process your request.

Option C: Delete your Atribu account

You may request full account deletion by contacting us at [email protected]. This will permanently remove your account, all workspaces you own, all profiles, and all associated data including integration data, analytics, and reports.

4. What happens when you request deletion

Upon receiving a valid deletion request, we will:

  • Revoke all OAuth tokens associated with the requested integrations.
  • Delete all advertising data (campaigns, ad sets, ads, spend metrics) linked to the disconnected accounts.
  • Remove any attribution data, conversion records, and analytics derived from the deleted integration data.
  • Purge all cached or processed data associated with the request.

For GoHighLevel data, we erase the personal data of the contacts you name — or of all contacts synced from the GoHighLevel location — including name, email address and phone number. The record itself may remain in de-identified form so that the conversion and attribution counts of your workspace stay consistent. Deleting your account (Option C) removes the workspace data entirely.

Deletion is typically completed within 30 days of receiving a valid request. Some data may be retained for a short period in encrypted backups before being permanently purged.

5. Data we may retain

Even after a deletion request, we may retain limited data where required by law or legitimate business interests, including:

  • Audit logs for security and compliance purposes (anonymized where possible).
  • Aggregated, non-personal analytics that cannot be used to identify you.
  • Records required to comply with legal obligations, resolve disputes, or enforce our agreements.

6. Revoking Facebook permissions

In addition to requesting data deletion from Atribu, you can revoke Atribu’s access to your Facebook data directly from your Facebook account:

  • Go to Facebook Settings → Security and Login → Apps and Websites.
  • Find “Atribu” in the list of active apps.
  • Click Remove to revoke all permissions.

Revoking permissions from Facebook will prevent Atribu from accessing any new data. To delete data already stored, please also follow the deletion steps above.

7. Uninstalling Atribu from GoHighLevel

You can also remove Atribu from inside GoHighLevel by uninstalling the app from your location or agency. GoHighLevel then notifies Atribu with an uninstall webhook, and Atribu marks the connection as disconnected, deletes the stored GoHighLevel tokens and stops syncing immediately. An uninstall from one location affects only that location; an agency-level uninstall disconnects the locations connected through that agency.

As with disconnecting in Atribu, data already synced stays in your workspace until you request its deletion as described above.

8. Contact us

If you have questions about data deletion or need assistance, please contact us at [email protected].