Q&A /Security and privacy

Security and privacy

Here we've gathered everything about protecting your Facebook and dashboard logins, what the service stores (and what it doesn't), and how we reduce the risk of your account being blocked. The main rule: only you enter your Facebook password, and the service never sees it.

Is it even legal and safe to let a bot post on my behalf?
You're posting your own listings (real estate, goods, services) within Israeli law and the rules of each specific group. You log in to Facebook yourself via VNC (it's like TeamViewer right inside your browser), and the service never asks for, sees, or stores your password. The bot behaves like a human: realistic clicks, random pauses, and constant monitoring of Facebook's restrictions. Spam, fraud, phishing, and posting in groups where your type of content is explicitly forbidden are not allowed — following each group's rules is your responsibility.
Where is my Facebook password stored?
Nowhere on our end. You enter it yourself in the Chrome browser that's open on YOUR own server via VNC — the password only goes to your server, never to us. From there the login is "remembered" in the Chrome profile on that server, and the bot signs in on its own. All our database keeps about Facebook is a "logged in" flag — the password itself isn't there, and there isn't even a separate column for the FB password in the database.
So a support operator can't get into my Facebook?
No. Since your FB password isn't stored anywhere on our side, an operator can't log into your account "for you" — it simply isn't kept with us. The persistent session lives in the Chrome profile on your server; to switch accounts or log back in, you have to open the VNC screen of your server specifically, and that's available only to you (and, if needed, to an admin for technical support).
Will Facebook ban my account because of the bot?
The risk can't be fully eliminated — Facebook changes its rules, and responsibility for the account stays with you (you confirm this at registration). But the service does a lot to reduce that risk: the bot works at a human pace with random delays, there's a posts-per-hour limit, the Facebook groups and Marketplace windows are spread out over time (groups during the day from 07:00, Marketplace at night), and at the first sign of a restriction the bot pauses itself and sends you an alert on Telegram. And if Facebook does restrict the account anyway — that's not a failure of the service.
What exactly do you do to reduce the risk of a ban? Can you give details?
Several mechanisms work together. Pace: random pauses between actions, and a 20–60 second delay after each post. Limit: 4 posts per hour by default, with a warning in the dashboard "no more than 5 — risk of restriction." Windows: groups and Marketplace post at different times, never simultaneously. Group tagging: in large, strict groups the bot leaves a minimal "footprint" (phone only, no extra links). Anti-duplicate: the bot doesn't send the same listing to the same group more than once every 4 hours, plus multiple servers won't post the same apartment in the same hour (otherwise Facebook reads it as coordinated spam). And on a rate-limit, the bot puts itself into a cooldown on an escalating ladder: 3h → 6h → 24h.
What exactly does the service store about me?
Only the minimum needed to operate: your name, contact details (Telegram/WhatsApp/phone), email and an encrypted (bcrypt) dashboard password, your listings (apartment photos and descriptions), the list of your FB groups, technical server data (IP, tokens), payment history, and an action log. We don't store your Facebook password. The most sensitive items — your server password, your Telegram session, and your 2FA secret — we store only in encrypted form.
I want to delete all my data. How do I do that?
Send "delete my data" on Telegram to the operator @BuzzPostil (or via WhatsApp +972 58-638-4995). Under the Privacy Policy, all your data is deleted within 24 hours. Note: deleting your data and getting a refund are two different things; money for a paid month is not refunded.
Can I enable two-factor authentication (2FA) for logging in to the dashboard?
Yes. Go to your dashboard → "Security" section → "2FA" tab → "Enable 2FA," confirm with your current password, scan the QR code in Google Authenticator / Authy / 1Password (or enter the secret manually), and click "Confirm and enable." After that, every login will require a 6-digit code from the app in addition to your email and password. The QR and the secret never leave our server, and the same code can't be reused.
How do I disable 2FA if I've lost access to my authenticator app?
You can turn off 2FA in your dashboard → "Security" → "2FA" → "Disable 2FA," confirming with your current dashboard password. When it's disabled, all previously issued sessions are revoked, so an old stolen token won't survive the change. And if you've lost both the app and the ability to log in — write to support @BuzzPostil.
Is dashboard login protected against password guessing?
Yes. After 5 failed login attempts within 15 minutes, login is blocked for 15 minutes. There are also additional limits: no more than 10 attempts per minute from one IP and no more than 20 per hour for one email, and the login form is protected by a CSRF token. The dashboard password itself must be at least 10 characters long and is stored only as a bcrypt hash.
Who has access to my server's screen and data?
Only you (the owner) and the service admin. Both the regular request to start VNC and the remote-screen channel itself verify that you're the owner of that server, and block access for any other user (returning a 403 error). When you open VNC, no one but you can see that screen. Other people's screenshots and post history can't be viewed either — everything is strictly tied to the owner.
If someone steals your encryption key, will all my data be exposed right away?
The sensitive fields (your server password, Telegram session, 2FA secret) are encrypted with the Fernet algorithm. For Telegram sessions, an individual per-user "salt" is also used, so leaking a single shared key isn't enough to expose them, and the operator can reissue the salt for a specific user without affecting the others. This limits the impact of even an unlikely leak.
Can I see the password for the server itself (Windows) in the dashboard?
No, that password isn't shown in the dashboard — it's stored in encrypted form. And you don't actually need it for day-to-day use: logging in to Facebook and managing the server are done through the VNC window and the buttons in the dashboard. Technical access to the machine itself belongs to the service admin for maintenance.
Why does registration require a checkbox about responsibility for Facebook?
Because your Facebook account and any restrictions on it (rate-limit, a group ban, account suspension) are your area of responsibility. At registration you need to check your agreement with the Terms of Use and the Privacy Policy and confirm that you understand this; without the checkbox, registration won't go through. The service reduces the technical risks, but it can't guarantee that Facebook will never restrict your account.
I don't give anyone access to my dashboard. But what if I want to give it to a partner — is that allowed?
Under the Terms, you may not share panel access with third parties, resell the service, or attempt to reverse-engineer it — that's grounds for termination with no refund. The service is also for people 18+ only (a requirement of both Facebook and Israeli law). And technically you wouldn't be able to "share" your server's screen anyway: both the VNC request and the remote-screen channel only let the account owner in.
And is there a log of who did what with my account?
Yes, the service keeps an action log: the action, the time, and the IP address are recorded — including sensitive events like enabling and disabling 2FA. This exists precisely for security, so things can be sorted out if something goes wrong. On top of that, enabling or disabling 2FA and changing your password always require entering your current password — that's a safeguard in case someone hijacks your session.

Didn't find an answer?

Message us - we reply within an hour during working hours (07:00-24:00).