Privacy Policy
Last updated 2 August 2026
SoldPilot is a Chrome extension and web service that writes replies to buyers on Facebook Marketplace on a seller's behalf. This policy describes exactly what it reads, what it sends, what is kept, and for how long.
What the extension reads
The extension runs only on facebook.com and messenger.com, and only on Marketplace inbox and item pages. It reads the page you already have open, in your own logged-in browser session. It does not read any other site, and it has no access to your Facebook password — it cannot see it, and never asks for it.
What is sent to our servers
When a buyer messages you about a listing, the extension sends:
| Data | Why |
|---|---|
| The messages in that conversation | So the reply answers what was actually asked |
| The buyer's display name | So the reply can address them |
| The listing's title, price, URL and sold status | So the reply is about the right item |
Nothing else about your Facebook account is transmitted — not your friends, your profile, your other conversations, or anything outside the Marketplace thread being answered.
Third parties
Anthropic
Conversation text is sent to Anthropic's API to generate the reply. Anthropic does not train its models on data submitted through its API.
Stripe
Payments are handled entirely by Stripe. Card numbers are entered on Stripe's own pages and are never sent to, seen by, or stored on our servers.
What we store
- Your account — your name, the city and country you give us, your email address, and a hashed password. Passwords are stored using scrypt and cannot be read back, by us or anyone else. Name and location are used to know who our customers are and where they sell; they are never sold, shared, or used to advertise to you.
- Your settings — business description, tone, trading policy and the instructions you write.
- Your listings — title, price, URL and any details you add or that are read from your own Marketplace listing pages.
- A reply history — for each conversation handled: the buyer's display name, their most recent message, the reply that was sent, and a score describing how likely they were to buy. This is what the Conversations tab shows you.
- Questions the assistant could not answer — when a buyer asks something your listing does not cover, the question and the buyer's display name are kept so the dashboard can ask you once and remember your answer. Your answer is stored against that listing.
Buyers' data
Replying to someone means processing what they wrote. We store a buyer's display name and their most recent message so you can review what was said on your behalf. We do not build profiles of buyers, do not track them across sellers, and never sell, share or transfer their data to anyone.
Follow-ups
If you switch it on, SoldPilot can send one short message to a buyer who showed real interest and then stopped replying — asking whether they are still interested. This is the only part of the product that messages someone first, rather than answering a message they sent.
It is off unless you enable it. It never sends more than one message per conversation, never sends to a buyer who is waiting on an answer from you, and never sends until the wait you configured has passed. Nothing about the buyer is kept beyond what is already described above.
What we never do
- Sell or rent your data, or your buyers' data, to anyone.
- Use your conversations to advertise to you or to anyone else.
- Send messages from your account other than the replies the assistant writes, and — only if you switch it on — a single follow-up to a buyer who went quiet. Nothing else is ever sent.
- Access your Facebook account when your browser is closed. The extension only works while you have a Facebook tab open.
Retention and deletion
Data is kept while your account is open. Delete your account and your settings, listings and reply history are removed. To delete your account, email the address below and it will be actioned within 30 days.
Your choices
- Pause at any time — the dashboard has a switch that stops all replies immediately, across every browser you've installed the extension in.
- Dry run — the extension can generate replies and show them to you without sending anything.
- Uninstall — removing the extension stops all reading and sending at once.
Security
All traffic between the extension, our servers, Anthropic and Stripe uses HTTPS. Sessions use signed, HTTP-only cookies. Account keys are per-account and can be rotated.
Contact
Questions, data requests, or account deletion: privacy@soldpilot.com
Changes
If this policy changes materially, the date at the top changes and the extension's listing is updated. Continued use after a change means you accept it.