Privacy Policy

Privacy Policy

Last updated: 10 September 2026

Who we are and what Aegis does

Aegis is a comment moderation and analysis service operated by Argus Digital in Australia. Our clients are elected representatives and registered political parties (each an "office"). An office connects the Facebook Pages and Instagram accounts it administers, and Aegis collects the public comments posted on them, classifies those comments, and gives the office's staff tools to moderate them and understand the conversation.

This policy explains what information Aegis handles about two groups of people: commenters — members of the public who comment on a connected Page — and office users — the staff who sign in to Aegis. Argus Digital provides Aegis to each office as its service provider. The office decides which Pages to connect, which comments to hide, and what to do with what Aegis shows it.

Information we collect

From Meta, about commenters. When a Page is connected, Aegis receives the following through the Meta Graph API for comments on that Page:

  • The text of each comment and reply, when it was posted, and whether it is hidden.

  • The post or media the comment belongs to, including the post's text and link.

  • The commenter's page-scoped user ID (or Instagram user ID), display name and profile picture link, as Meta provides them.

  • Links to any image, GIF or video attached to a comment, and a link to the comment itself.

  • Aggregate Page statistics (reach, engagement, follower demographics) with no individual data.

We only collect comments that are already visible to the Page. We do not collect private messages, friend lists, or anything from a commenter's own profile beyond the name and picture shown alongside their comment.

Information Aegis creates about commenters. Our software analyses each comment and records labels alongside it, including:

  • Sentiment, topic, and who or what the comment is directed at.

  • Whether the comment appears abusive, hateful, spam, or a possible threat of violence.

  • An estimated political leaning inferred from the language of the comment, such as self-declared support for a party. This is an automated guess from public text, is often "unknown", and is never confirmed with the commenter.

  • Signals that an account may be automated or part of a coordinated group, based on posting patterns and similarity to other comments.

  • A running summary per commenter on a given Page: how many comments they have made, how many were flagged, and the labels above rolled up over time.

  • Corrections that office staff make to any of these labels.

About office users. Name, email address and sign-in details (handled by our authentication provider), the workspace you belong to, your role, and a log of the moderation actions you take in Aegis.

How we use it

  • Moderation — surfacing comments that need attention and letting authorised staff hide, unhide, reply to, or block, on the office's Page. In some workspaces, comments the software rates as clearly abusive or spam can be hidden automatically; every such action is recorded and can be reversed.

  • Understanding the conversation — dashboards showing the tone, topics and estimated leanings across a Page's comments, and per-commenter summaries so staff can see the context of a comment.

  • Safety — comments that may contain a threat of violence are listed for human review. An office may choose to report such a comment, with the commenter's name and the comment text, to police.

  • Reports — aggregate reports for the office. These do not name individual commenters.

  • Improving accuracy — our engineers periodically review samples of comment text, with the labels the software assigned and any corrections staff made, to fix classification mistakes. Those working copies are deleted within a week.

Audience exports. Aegis includes a feature that lets an office group commenters into segments and export those segments to Meta Ads Manager as a Custom or Lookalike Audience. That feature is currently switched off for every office, and no commenter information is being used for advertising. If it is switched on in future, this policy will be updated first, and only the page-scoped IDs of people who have already engaged with the office's own Page would be sent, under Meta's Custom Audience terms.

We do not sell information about commenters or office users to anyone.

Automated analysis and AI

Most classification is done by rules running on our own servers. When those rules are not confident, or to check whether a flagged comment is really a threat, the comment is sent to an AI model operated by Anthropic (Claude) in the United States. What is sent is the comment text, the text of the post it was under, and, for a reply, the text of the comment it replies to. The commenter's own name and ID are not sent, and where a reply opens by naming the person it answers, that name is replaced with a placeholder before sending. Under Anthropic's commercial terms this data is not used to train its models.

Every AI or rule-based label is advisory. It is shown to office staff alongside the comment, staff can correct it, and no decision that affects a commenter beyond hiding a comment on the office's own Page is made from it automatically.

Who we share it with

We share information only with the providers we need to run Aegis, each of which is bound by contract to handle it only on our instructions:

  • Meta Platforms — the source of the data; moderation actions are sent back to it.

  • Supabase — our database, hosted in Sydney, Australia.

  • Vercel — hosting and background processing, in Sydney, Australia.

  • Clerk — office user sign-in.

  • Upstash — request rate limiting (holds office user IDs and request counts only; no commenter data).

  • Anthropic — AI classification, as described above.

  • GitHub — short-lived working copies of comment samples used for the accuracy reviews described above.

Some of these providers store or process information outside Australia, including in the United States. We also disclose information where an office directs us to (for example a threat referral to police) or where the law requires it.

How long we keep it

  • Comments, commenter identifiers and the labels we create are kept for up to seven years from when the comment was posted, or until the Page they came from is disconnected from Aegis, whichever comes first. A nightly process deletes anything older. (An office may ask us to configure a shorter period for its workspace, down to three years.)

  • When an office disconnects a Page in Aegis, everything collected through that Page is deleted: comments and their labels, commenter identifiers and profile links, per-commenter summaries, block lists, coordination data, and the stored access token. Removing the Aegis app inside Facebook settings revokes our access and stops collection, and any deletion request Meta forwards with it is recorded and given a confirmation code, but the office's existing records are only deleted once we have confirmed the request with the office — contact us if you want it done sooner.

  • A record that moderation actions happened (what was hidden, by whom, when) is kept in an audit log for accountability. It does not contain comment text.

  • Engineering review copies are deleted within seven days. Written accuracy reviews may quote short extracts of comments without names.

  • Information already sent to Meta or to police cannot be recalled by us.

How we protect it

  • Each office's data is isolated from every other office's at the database level.

  • Meta access tokens are encrypted before they are stored and decrypted only at the moment of use.

  • All connections to Meta, our providers and your browser are encrypted in transit.

  • Access to commenter data requires a signed-in office user with the right role; bulk exports require a moderator or admin.

  • The moderation audit log is append-only and cannot be edited or erased by application credentials.

  • If we become aware of a security incident affecting commenter or office data, we will contain it, notify the affected office and Meta, and notify affected individuals and regulators where required.

Your choices and requests

Commenters. Everything Aegis holds about you comes from comments you posted publicly on an office's Page. Deleting your comment on Facebook or Instagram removes it from the platform; you can also ask us to delete what Aegis holds about you on a given Page, or to tell you what we hold. Write to Hello@argusdigital.com.au with the Page name and a link to one of your comments, or use our data deletion page. Every request is given a confirmation code you can check on that page. We act on deletion requests within 30 days and confirm in writing.

Office users. Ask your workspace admin, or write to us, to correct your details or close your account.

Complaints. If you are unhappy with how we have handled your information, contact us first and we will respond within 30 days. You may also contact the Office of the Australian Information Commissioner (oaic.gov.au).

Legal basis

Aegis is provided to elected representatives and registered political parties for use in connection with the political process. Australian privacy law treats acts done for that purpose by political representatives, registered parties and their contractors differently from other commercial activity. Whether or not a particular activity is covered by those provisions, we follow the practices described in this policy for all information Aegis handles.

Changes to this policy

We will update this page when what Aegis collects, creates, shares or keeps changes, and before any switched-off feature that uses commenter information is turned on. The date at the top shows the current version.

Contact

Argus Digital, Australia.Hello@argusdigital.com.au