This policy describes what Menivix actually stores, why the information is used, how Meta and Instagram connections work, and which providers process data for the service.
Hebrew version: הגרסה בעברית
Menivix is operated by Eitan Bellaiche. For privacy, deletion, or personal-data questions, contact menivix.official@gmail.com.
Account data: name, email address, phone number, account status, terms/privacy acceptance timestamps, password hash plus salt, hashed session tokens, hashed trusted-device tokens, hashed email verification codes, and hashed password-reset tokens.
Business and workspace data: business name, goals, services, target audience, benefits, offers, tone of voice, service areas, website or landing-page URLs, phone number, contact email, marketing preferences, logo, brand palette, website-derived business knowledge, campaign drafts, social-content drafts, captions, hashtags, scheduling data, and auto-publish consent records.
Media data: images and videos uploaded by the user, images generated through Menivix, Cloudinary URLs, file type, filename, file size, and Smart Reel or Veo-related media metadata when those features are used.
Meta/Facebook/Instagram connection data: Menivix stores the Facebook user ID, Facebook user name, Meta user access token, granted scopes, the list of returned Pages, the stored Page access token for each saved Page, linked Instagram business-account IDs and usernames, and the Page and ad identities selected for use. For the direct Instagram connection, Menivix stores the Instagram user ID, username, access token, granted scopes, connection time, and token expiration time.
AI, usage, and operational data: prompts, business context, website text submitted for analysis, reference images, AI request metadata, token and usage counters, estimated costs, request IDs, partial results or errors, publishing logs, audit logs, and technical data used for security, rate limiting, push notifications, and incident diagnosis.
Information comes directly from the user when creating an account, saving a business profile, uploading media, generating content, connecting Meta/Facebook/Instagram, enabling push notifications, or contacting Menivix. Additional information comes from the Meta and Instagram APIs after the user authorizes those connections, and from website pages the user asks Menivix to analyze.
Menivix uses the information to create and manage accounts, verify sign-ins, maintain sessions, manage businesses and media, generate content, propose or run automations, publish or schedule content only when requested or authorized by the user, send verification and reset emails, run push notifications, measure usage and quotas, investigate issues, prevent abuse, and maintain the service.
`pages_show_list`: used to show the Facebook Pages the user manages so the user can select the correct Page.
`pages_read_engagement`: used to retrieve the Page information and engagement-related data needed to connect and operate the selected Page.
`pages_manage_posts`: used to create and publish Page content only after the user requests it or enables an automation or schedule.
`instagram_business_basic`: used to identify and connect the user’s professional Instagram account and retrieve the basic account information Menivix needs.
`instagram_business_content_publish`: used to publish Instagram posts, Stories, or Reels that the user creates, approves, schedules, or authorizes Menivix to publish.
Menivix does not publish to an account the user did not select and authorize. Facebook publishing uses the Page selected inside Menivix. Instagram publishing uses the connected or selected Instagram account relevant to the request.
When the user triggers AI features, Menivix may send parts of the business brief, marketing text, saved business-profile information, website text submitted for analysis, prompts, metadata, and selected images or reference images to OpenAI or Google GenAI/Veo. That data is sent only to generate the text, image, storyboard, creative direction, or video the user asked Menivix to produce.
PostgreSQL through Prisma and `pg` stores account, business, content, and audit records.
Cloudinary stores and serves uploaded images, videos, logos, and Smart Reel or Veo outputs.
Meta/Facebook and Instagram provide the connection, Page retrieval, permissions, and authorized publishing APIs.
OpenAI is used for business-profile enrichment, website-text analysis, marketing copy generation, image generation, and Veo-supporting analyses.
Google GenAI/Veo is used for video generation when Veo features are enabled.
Brevo is used for verification and password-reset email delivery when Brevo is configured in the deployment environment.
As of the last-updated date, Menivix has no live payment processor and does not collect payment details through the website. The code contains Paddle Sandbox components that are not enabled to charge users.
Menivix uses a login session cookie, a CSRF cookie, short-lived OAuth state cookies for Meta and Instagram, and, when needed, trusted-device records, password-reset records, and email verification challenges.
Based on the reviewed code, passwords are not stored in plaintext. They are salted and hashed with `scrypt`. Menivix also stores session tokens, password-reset tokens, and verification artifacts in hashed or signed form where the implementation supports that behavior.
Menivix stores the Meta and Instagram access tokens it needs for the connected features in the database. The reviewed code did not show a separate application-level encryption layer for those stored tokens, so this policy does not claim such encryption.
Account, business, media, and content records are kept while the account remains active or while Menivix needs them to operate the product, secure the service, maintain audit trails, provide support, or handle disputes and legal obligations.
Password-reset records are valid for one hour. Email verification codes are valid for ten minutes. Session cookies are configured for up to 30 days and may be revoked earlier. Meta and Instagram connection data remain stored until the user disconnects them or requests deletion.
Menivix does automatically prune some unused system-generated images, retaining up to 18 unused system-managed media assets per business. For Meta or Instagram disconnection and account deletion requests, see the Data Deletion page.
Menivix uses access controls, authentication cookies, CSRF protections, hashed secrets in parts of the authentication flow, rate limiting, and operational logging. Menivix does not guarantee absolute security, absolute availability, or prevention of every unauthorized access event.
Users can request access, correction, deletion, Meta or Instagram disconnection, or clarification about their information by emailing menivix.official@gmail.com.
Based on the reviewed code, Menivix does not sell personal information to third parties. Menivix does send information to technology providers when needed to operate the product and the features the user requests.
Because Menivix uses cloud infrastructure, APIs, and AI providers, information may be processed in Israel and in other jurisdictions where Menivix or its service providers operate.
Menivix may update this policy when the product, providers, or operational flows change. Last updated: August 27, 2026.
Service operator: Eitan Bellaiche
Support email: menivix.official@gmail.com
Menivix is operated by Eitan Bellaiche