Privacy Policy
Social Content OS · Effective 29 September 2026
Who we are
Social Content OS is a private application its operator uses to plan, publish and manage content and audience engagement for the operator's own brands and their Instagram professional accounts. It is not offered to the public. Questions about this policy: jsohi@hotmail.com.
Information we process
We only process information Meta makes available about our own connected accounts and the people who interact with them.
- Connected accounts. Identifiers and usernames of the Instagram professional accounts and Facebook Pages connected to the service. Access credentials granted through Facebook Login are kept in server-side configuration and are never shown to a browser.
- Published content. Content plans and drafts, captions, media references, Instagram media identifiers, permalinks, publishing status and timestamps.
- Comments on our posts. Comment identifiers and text, the commenter's Instagram-scoped identifier and username, timestamps, the post a comment belongs to, and reply threading.
- Direct messages to our accounts. Message identifiers and text, whether a message contained an attachment (attachments themselves are not stored), the sender's Instagram-scoped identifier and username, conversation identifiers and timestamps.
- Engagement and moderation records. Classifications (for example positive, question or spam), suggested replies, approval state, the replies we send (text, time, the identifier Meta returns, and whether sending succeeded), automated decisions and their reasons, and moderation recommendations. The service flags content for human review; it does not hide or delete comments automatically.
- Notification records. Metadata about notifications received from Meta (time, type, counts and signature-check result). The raw notification payloads are not stored.
- Performance data. Where that capability is enabled, aggregate metrics Meta provides about our own posts and accounts, such as reach and engagement.
- Operator sign-in. The operator's sign-in email address and authentication records.
We do not ask for or store the passwords of Instagram or Facebook users.
How we use it
- Operating the service for the operator's own brands.
- Publishing approved content to our own Instagram accounts.
- Responding to engagement. Reading comments and messages sent to our accounts and replying to them. Replies are approved by a person, or sent automatically only within narrow rules set by the operator (for example, a short thank-you to a positive message, only within Meta's messaging window).
- Moderation. Flagging spam, abuse or sensitive content for human review.
- Analytics and improvement. Where enabled, using performance data and engagement outcomes to evaluate and improve future content and replies.
- Security and audit. Verifying that notifications genuinely come from Meta, preventing duplicate actions, keeping a record of actions taken on our accounts, and troubleshooting.
Sharing and service providers
We do not sell Meta Platform Data or any other personal information, and we do not use it for advertising or share it with data brokers. We use these service providers to run the service:
- Meta Platforms — the Instagram and Facebook APIs the service reads from and writes to.
- Supabase — database and operator authentication.
- Vercel — hosting for the private application.
- Cloudflare — hosting for these public pages, and secure tunnelling used while testing notification delivery.
- Anthropic — an AI model provider, used only if AI-assisted drafting is enabled. In that case the text needed to draft a suggestion (such as post context or the comment or message being answered) is sent to it for processing.
We may also disclose information where the law requires it.
Retention
We keep this information only as long as it is needed for the purposes above, including an audit trail of actions taken on our accounts. Records belonging to a brand workspace are deleted when that workspace is deleted, or earlier when a deletion request is completed. Copies may remain in our providers' routine backups until those backups expire.
Security
Access is limited to the operator through authenticated sign-in. The database enforces owner-only access rules. Credentials are held server-side only. Connections use HTTPS, and every notification from Meta is checked against its signature before it is processed.
Your choices
- To ask what we hold about you, or to have it deleted, see Data deletion or email jsohi@hotmail.com.
- Deleting a comment or unsending a message on Instagram does not automatically remove the copy held by this service. Send a deletion request if you want it removed.
Children
The service is not directed to children under 13, and we do not knowingly process their information.
Changes
We will update this page if our practices change. The effective date above shows the current version.