AutoStream Privacy Policy
Effective date: May 28, 2026 · Last updated: May 28, 2026
AutoStream (the “extension,” “we,” or “our”) is a manual listing
assistant for automotive dealership representatives. It helps dealership reps post
their own dealership's vehicle inventory to Facebook Marketplace by pre-filling
the listing form with vehicle data the rep has chosen to use. The rep
always reviews and submits each listing manually. This policy explains
exactly what data we collect, how we use it, where it goes, and what we
never do.
The short version, up front:
- We read your dealership’s own inventory data (vehicles, photos, prices) so we can pre-fill Facebook Marketplace listings.
- We do not auto-post. You click Submit on every listing.
- We do not sell, share, or transfer your data to advertisers.
- We do not read or collect any data from Facebook users.
- We do not run scripts on random pages you visit — only your configured dealership URL and Facebook Marketplace, and only when you explicitly initiate the action.
1. Who we are
AutoStream is operated by AutoStream, LLC. AutoStream is a
managed B2B product — to use the extension, your dealership must be onboarded
by AutoStream and you must be invited by your dealership manager. The extension
is not designed for, or intended to be used by, consumers without a managed
dealership account.
2. Data we collect
2.1 Account credentials
- Your email address and a password hash, used to authenticate you against the AutoStream backend. Passwords are hashed and are never stored or transmitted in plaintext.
- Your full name (if provided by your dealership manager during invitation).
- Your role within the dealership (sales rep, manager, admin).
- Your dealership association — which dealership invited you.
2.2 Dealership configuration data
The following are configured per-dealership by an AutoStream administrator (typically your dealership manager) and are visible to the extension when you sign in:
- Your dealership’s inventory URL — the public URL of your dealership’s own inventory page (e.g. the dealer’s website).
- Your dealership’s optional CarGurus dealer-page URL — used by the marketplace lane to read your dealership’s inventory from CarGurus for manual posting. CarGurus-sourced vehicles remain manual-post only and are not written to the dealership website or treated as dealer-site inventory.
- Optional dealership-level configuration: brand name, timezone, contact phone, and optional server-side AI configuration for caption generation.
2.3 Vehicle inventory data (read on your behalf)
When you click Refresh Inventory in the extension popup, the extension reads vehicle data from your dealership’s configured inventory URL and/or CarGurus URL. This includes:
- Vehicle title (year, make, model, trim)
- Price (and pricing history if visible on the source page)
- Mileage / odometer reading
- VIN (Vehicle Identification Number)
- Stock number
- Exterior and interior color, body style, transmission, drivetrain
- Features and equipment list
- Photo URLs — references to vehicle photos hosted by the dealership website or CarGurus. The extension reads the URLs and presents the images to you for selection. We do not re-host or modify the images.
- Vehicle detail page URLs — links the rep can use to verify data against the source.
This vehicle data is your dealership’s own data. We read it on your dealership’s
behalf — at the dealership manager’s direction, via the configured URL.
2.4 Posting activity
- Which vehicles you posted to Facebook Marketplace, and the timestamp of each post (used to track posting streaks and to detect stale listings).
- The vehicle title, VIN, and price at the time of posting, retained so we can detect if your dealership later changes the price and flag the listing for re-posting.
- Your acceptance of the AutoStream User Agreement and the timestamp of acceptance.
We do not store the content of the listing you submitted to
Facebook (description text, caption, etc.) on our servers — that lives only on
Facebook’s platform after you submit.
2.5 What we do NOT collect
- We do not collect your browsing history.
- We do not collect keystrokes, mouse events, screen captures, or behavioral telemetry beyond what you actively choose to send (e.g. clicking Refresh Inventory).
- We do not read data from websites other than (a) the URLs configured by your dealership admin, and (b) Facebook Marketplace pages when you click Create Listing.
- We do not collect or store any data about other Facebook users, your Facebook friends, your Marketplace browsing activity, or any non-listing content on Facebook.
- We do not collect personally identifiable information about the end consumers who will see your Facebook Marketplace listings.
- We do not track you across websites.
3. How we use your data
3.1 Inventory display + manual listing pre-fill
We read your dealership's vehicle inventory to populate the extension's
inventory list. When you click Create Listing on a vehicle,
the extension opens Facebook Marketplace and pre-fills the listing form with
that vehicle's title, price, mileage, photos, and other fields. You then
review the pre-filled listing and click Submit yourself.
AutoStream does not submit listings on your behalf.
3.2 Optional AI caption assistance
If your dealership has AI assistance enabled and you click
“Generate Caption,” the extension sends the selected vehicle’s
title, features, and (optionally) photo URLs to AutoStream’s authenticated
backend. AutoStream then forwards the request to Anthropic's Claude
API server-side to generate a suggested listing description. The
extension never receives or stores the Anthropic API key. The suggestion
appears in the extension; you can edit, accept, or discard it before posting.
Per Anthropic's published policies, Claude API request content is not used to
train Anthropic models. We do not store the AI-generated text on our servers;
it lives only in your current popup session and (if you submit it) on Facebook.
3.3 Posting history and analytics
We use posting timestamps, vehicle identifiers, and price snapshots to
surface helpful workflows: posting streaks, stale-listing reminders, and
price-change alerts when your dealership updates a vehicle’s price after
you've already posted it. These analytics are visible only to you and to
your dealership manager.
3.4 Account authentication and dealership scoping
Your email and password hash are used to authenticate you against the
AutoStream backend. Once authenticated, your dealership association is used
to enforce that you can only see inventory and posting history for your own
dealership.
4. Where your data goes
4.1 Local storage on your device (Chrome storage.local)
- Your inventory list (vehicles + photos) — cached locally for fast popup load.
- Posting history.
- Your UI preferences (sort order, filters, etc.).
This local data is wiped when you uninstall the extension.
4.2 AutoStream backend
Our backend is hosted on Supabase, a managed cloud database platform. It stores:
- Your account credentials (email, hashed password, role, dealership association).
- Your dealership’s configuration (inventory URL, CarGurus URL, brand, etc.) — managed by your dealership admin.
- Server-side cached inventory data for your dealership.
- Posting activity log.
Each dealership’s data is isolated: a sales rep at Dealership A cannot
read inventory, posting history, or any other data belonging to Dealership B.
AutoStream staff access for support and operations purposes is restricted
and logged.
4.3 Anthropic Claude API (only if you opt-in by clicking Generate Caption)
Vehicle title, features, and (optionally) photo URLs may be sent to
AutoStream’s authenticated backend, which forwards the request to
api.anthropic.com server-side to generate listing captions.
Anthropic processes the request and returns suggested text; per
Anthropic’s data handling policies, API content is not used to train
Anthropic's models. Anthropic API keys are never exposed to the extension.
4.4 Facebook (only when you click Create Listing)
When you click Create Listing in the extension, AutoStream opens
facebook.com/marketplace in a new tab and pre-fills the listing
form using vehicle data you have already reviewed. The data flows from your
browser to Facebook the moment you click Submit on Facebook’s form. We do not
send anything to Facebook automatically; the submission is always your
manual action.
4.5 What we do NOT do with your data
- We do not sell, share, or transfer user data to advertisers, data brokers, or other third parties.
- We do not share your dealership’s inventory with competing dealerships.
- We do not use your data to train any machine-learning model (Anthropic doesn’t either, per their API terms).
- We do not send marketing email or any unsolicited communication based on data collected via the extension.
5. Data security
- All network traffic between the extension and our backend is encrypted in transit (HTTPS).
- Account passwords are hashed and never stored or transmitted in plaintext.
- Each dealership’s data is isolated from every other dealership’s.
- Staff access to production data is limited to authorized personnel.
6. Data retention
- Local extension data is retained on your device until you uninstall the extension or sign out, at which point it is wiped.
- Account data is retained for as long as your dealership has an active AutoStream subscription, plus a 90-day grace period for re-onboarding.
- Posting history is retained for the duration of your dealership’s subscription. Your dealership manager can request earlier deletion.
- Server-cached inventory snapshots are overwritten on each refresh; historical snapshots are retained for 30 days for diagnostic purposes, then deleted.
7. Your rights and how to exercise them
You have the right to:
- Request a copy of the data we hold about you.
- Request correction of inaccurate data.
- Request deletion of your account and associated data.
- Object to or restrict processing of your data.
- Withdraw consent for optional features (e.g. AI caption assistance) at any time, with no effect on your access to the rest of the extension.
To exercise any of these rights, contact us at the email address below.
Most requests are processed within 14 days.
8. Children
AutoStream is a B2B workplace tool. It is not directed to children under
16, and we do not knowingly collect data from children. If you believe a
child has provided data to AutoStream, please contact us so we can delete it.
9. Changes to this policy
We may update this policy from time to time to reflect changes in features
or in legal requirements. We will update the “Last updated” date at the
top of this page when we do. If a change materially expands what data we
collect or how we use it, we will notify your dealership manager via the
AutoStream backend.
10. Contact
Questions or concerns about this privacy policy, or to exercise any of the
rights listed in Section 7:
- Email: hello@getautostream.com