Privacy Policy
Last updated: September 5, 2026
1. Information we collect
- MINT account data: email address, display name, workspace membership, and role.
- Threads connection data: the connected user's bounded profile identity, display name, exact granted permissions, and token expiry/status metadata.
- Instagram review-only data: the connected Professional account, exact two permissions, encrypted credential, one normalized JPEG, caption, and approval/execution/deletion state.
- Publishing workflow data: text drafts, previews, DryRuns, ActionRequests, approvals or rejections, schedules, executions, and normalized external publication results.
- Safety and audit data: identifiers, hashes, timestamps, and normalized outcomes/errors that exclude post bodies and secrets.
2. Exact Threads and Instagram API use
Threads is approved maintenance-only and default OFF. The already approved threads_basic permission displays the connected user's own profile and posts read-only. The threads_content_publish campaign is used only to publish a text post that the user explicitly approves.
Instagram is review-only and default OFF. It is limited to instagram_business_basic and instagram_business_content_publish, one immediately published JPEG and caption explicitly approved by a human, and execution-time gates. This policy does not claim a live connection, pilot, or publication has been verified. Facebook is a static, not-connected mock with no real account, token, permission, or external API access.
3. Token and secret protection
Threads and Instagram publishing credentials are owned by their workspace/account and encrypted at rest with versioned AES-GCM. MINT never stores or displays tokens, authorization codes, passwords, OTPs, reviewer codes, or encryption keys in cookies, plaintext database fields, logs, AuditLog metadata, or UI output.
4. Why we use the data
- Account connection, text composition, preview, human approval, scheduling, publishing, and result display
- Duplicate prevention, token refresh, reauthentication, recovery, safety, and audit
- Product improvement and support
5. Sharing
We do not share personal data except with the user's explicit consent, where legally required, or with contracted service providers to the minimum extent necessary. For an immediate plan, an approved post body is sent to Threads only when the user separately chooses Publish. For a scheduled plan, explicit Approval authorizes the displayed due time; schedule creation sends nothing to Threads, and every gate is re-checked when execution becomes due.
6. Retention, disconnect, and deletion
- MINT-local disconnect removes MINT's proof/snapshot, encrypted credential, and saved grants, and causes scheduled work to fail closed.
- Local disconnect does not remove MINT from Threads Website permissions. The user must separately remove that authorization in Threads settings when appropriate.
- Verified signed Threads deauthorization and data-deletion callbacks idempotently purge the matching provider account's credential and related data.
- An Instagram immutable JPEG revokes its delivery lease and remains in a deletion-pending queue until its R2 object is removed. Delivery URLs, original metadata, and tokens are not retained in UI or audit records.
- Published Threads posts are controlled by Threads. MINT does not request or execute a delete permission in this campaign.
- Audit records may be retained for fraud prevention, security, and legal obligations, then deleted under the applicable retention policy.
Read the exact data deletion instructions.
7. Cookies
MINT uses only cookies needed for authentication, locale, CSRF protection, and short-lived OAuth state. Threads and Instagram publishing tokens are never stored in a cookie. MINT does not use advertising cookies.
8. Security and changes
Controls include encryption, least privilege, explicit approval, idempotency, due-time revalidation, and redacted audit. Material changes to this policy will be announced in the service.
9. Contact
Contact the Support page or support@sns-mint.com.