Privacy Policy
Last updated: 13 July 2026
This is a translation of the Portuguese original, provided for convenience. In case of any divergence between the two versions, the Portuguese version at codecell.io/privacy/ is the governing text.
This policy describes how CodeCell Social ("we", "the app") collects, uses, stores and deletes data when managing social media accounts on behalf of their holders. By connecting an Instagram, Threads or TikTok account, you agree to the practices below.
1. Data we collect
- Account identity: the Instagram/Threads id and username of the connected account; for TikTok, the app-scoped
open_id, the display name, the username and the avatar. - Access tokens: OAuth tokens issued by Meta or by TikTok, required in order to operate on your behalf.
- Content: posts, comments, mentions and direct messages received, when you use the corresponding features.
- App account data: the app user's email and organization.
2. How we use the data
We use the data exclusively to provide the social media management functions you request: publishing and deleting content, moderating and replying to comments and mentions, reading/triaging direct messages, posting video to TikTok and searching public posts relevant to your niche. Each permission is used only for the corresponding feature:
instagram_business_basic— identify the connected account.instagram_business_content_publish— publish content you create.instagram_business_manage_comments— list, reply to and hide comments.instagram_business_manage_messages— receive and read direct messages for triage and reply.threads_basic— identify the connected Threads account.threads_content_publish— publish content on Threads.threads_keyword_search— search public Threads posts by keyword, so that you find conversations in your niche and can take part in them from your own account.threads_read_replies— read replies to posts for triage.threads_manage_replies— reply to and hide replies.threads_manage_mentions— read and reply to mentions.threads_delete— delete, at your request, posts created by you through the dashboard.
The TikTok scopes are used as follows:
user.info.basic— identify the connected TikTok account (open_id, display name, avatar).user.info.profile— show the username, the profile link and the verified badge, so you can tell your accounts apart.user.info.stats— show your own follower, like and video counts in the dashboard.video.list— list your own public videos next to the posts from your other channels.video.publish— post a video to your account, with the privacy level and the interaction settings you chose on the export screen.video.upload— send a video to your TikTok inbox, for you to finish and publish yourself in the TikTok app.
Regarding search results: the public posts returned by
threads_keyword_search are displayed to you in the dashboard and are not
resold, redistributed or used to build a public index. We do not store the content of
third-party posts beyond what is necessary to display them in the session. Every search is
recorded in an audit log (organization, user and term searched).
3. Storage and security
Access tokens are encrypted at rest (AES-256-GCM). Access to data is isolated per organization and protected by authentication. We do not record the content of direct messages in logs.
4. Sharing
We do not sell your data. We may process content through vendors strictly necessary to the operation (for example, AI-assisted text generation and cloud hosting), subject to their own policies. We do not share data with third parties for advertising.
5. Retention and deletion
You control your data at any time:
- Disconnect: removing the Instagram, Threads or TikTok connection in the dashboard revokes the corresponding token and stops collection.
- App removal: when you remove our app in the Instagram settings, Meta notifies us (deauthorization callback) and we revoke the corresponding connection. Revoking access from TikTok's own "Manage app permissions" page has the same effect on the TikTok connection.
- Data deletion request: we process the deletion request from Meta (data deletion callback), permanently removing the account's linked data and returning a confirmation code.
- Account deletion: you can delete your account and organization, removing all associated personal data.
The step by step for each of these options is in Data Deletion Instructions (available in Portuguese only).
6. Your rights
Under the LGPD (Brazil) and the GDPR (where applicable), you may request access, correction, portability or deletion of your data, as well as withdraw consents. To exercise these rights, use the controls in the dashboard or contact us.
7. Contact
Questions about this policy or about your data: privacidade@codecell.io.