NTV App

Terms and privacy

Effective

Privacy policy

What data this site and the NTV App applications process, for what purpose, where it is kept and how to exercise your rights.

Article 1.- Controller

NTV App is the public name of the operator of this site and of the applications described in this policy. It operates from Peru and its only point of contact is [email protected]. This policy applies to this website and to the three tools described; other applications or services of the operator are outside its scope.

Article 2.- This website

This site is static. It uses no cookies, no analytics tools, and has no user accounts or forms. It does not process personal data of its visitors, other than the standard access logs of the server that hosts it (for example IP address, date and time, requested address and browser), which the operator keeps on its own server.

Article 3.- The applications

NTV App operates three private tools: content-creator, Postiz and a messaging automation. They are for the use of a single operator and are used only against social pages and accounts that the operator owns or administers. No outside person connects their own accounts to these applications; people who write messages to the operator’s pages only send messages. Each tool has an annex with its details.

Article 4.- Data that is stored

content-creator stores on the operator’s server: access keys and tokens (as environment variables), drafts and posts (as JSON files), generated or uploaded images, and operational logs. It has no database and no user accounts.

Postiz stores on the operator’s server: the operator account, OAuth tokens of the connected integrations, scheduled and published posts, uploaded media, the comments and messages tables built into the tool, and notifications.

Messaging automation runs on the operator’s n8n instance (n8n.ntv-app.com) and replies to direct messages received on Instagram accounts and Facebook Pages that the operator administers. It processes the content of the messages a person voluntarily sends, their public Instagram or Facebook profile name, their platform user ID (needed to reply) and the date and time of the message. It does not process passwords, financial data or location.

Purposes of the messaging automation: to answer queries automatically with the help of artificial intelligence, to escalate the conversation to a human agent when requested or needed, to keep the conversation history during the active session so replies are coherent, and to improve the quality of automated customer-service answers. The basis for processing is the person’s implicit consent when starting a conversation with the business account, under Meta’s terms.

content-creator does not receive or read direct messages, comments or webhooks, and does not offer Facebook Login.

Article 5.- Platform permissions

content-creator uses the Meta Graph API with the permissions pages_manage_posts, pages_read_engagement, instagram_basic and instagram_content_publish, solely to publish to the operator’s Facebook Page and Instagram account. It posts to X (posting, OAuth 1.0a), uses a Telegram bot restricted to a single authorized chat as a control interface, and keeps a legacy IFTTT webhook. Postiz has the Facebook and Instagram integrations active; X, LinkedIn and TikTok are listed as pending. The messaging automation uses the permissions instagram_manage_messages (read and reply to Instagram direct messages), pages_messaging (read and reply to Facebook Page messages) and pages_read_engagement (basic page information the bot needs to work).

Article 6.- Third parties that receive data

To generate content, content-creator sends post text and images to Google Gemini, Groq and Cloudinary (image hosting and delivery) and, optionally, to OpenAI, Stability AI and Leonardo (image generation) and SerpAPI (news search). The platforms where content is published (Meta, X, Telegram, IFTTT) receive the published content. Each third party processes data under its own policies. Messages handled by the messaging automation are processed by a language-model provider to generate replies. Data is not sold or transferred to third parties for commercial or advertising purposes.

Article 7.- Retention and security

In content-creator and Postiz there is no automatic retention or deletion job: items are kept until the operator deletes them. In the messaging automation, conversation history is kept for at most 90 days and then deleted automatically. Data resides on the operator’s own server, including media files. Access to the applications is restricted and communications are encrypted in transit (TLS). Tokens are stored as server environment variables with restricted access.

Article 8.- Your rights

The reference framework is Law No. 29733, the Personal Data Protection Law, and its regulation in force. You may request access, rectification, deletion and opposition by writing to [email protected]. We will respond within 30 days. If you wrote a message to one of the operator’s pages, you can exercise the same rights through that address. To request data deletion, see the data deletion page.

Article 9.- Minors

The services are not directed to minors and do not knowingly collect their data.

Article 10.- Changes

This policy may be updated. The effective date shown in the header of this page corresponds to the current version.