Privacy Policy
Last updated: 13 July 2026
This is a translation of the Portuguese original, provided for convenience. In case of any divergence between the two versions, the Portuguese version at codecell.io/privacy/ is the governing text.
This policy describes how CodeCell Social ("we", "the app") collects, uses, stores and deletes data when managing social media accounts on behalf of their holders. By connecting an Instagram or Threads account, you agree to the practices below.
1. Data we collect
- Account identity: the Instagram/Threads id and username of the connected account.
- Access tokens: OAuth tokens issued by Meta, required in order to operate on your behalf.
- Content: posts, comments, mentions and direct messages received, when you use the corresponding features.
- App account data: the app user's email and organization.
2. How we use the data
We use the data exclusively to provide the social media management functions you request: publishing and deleting content, moderating and replying to comments and mentions, reading/triaging direct messages and searching public posts relevant to your niche. Each Meta permission is used only for the corresponding feature:
instagram_business_basic— identify the connected account.instagram_business_content_publish— publish content you create.instagram_business_manage_comments— list, reply to and hide comments.instagram_business_manage_messages— receive and read direct messages for triage and reply.threads_basic— identify the connected Threads account.threads_content_publish— publish content on Threads.threads_keyword_search— search public Threads posts by keyword, so that you find conversations in your niche and can take part in them from your own account.threads_read_replies— read replies to posts for triage.threads_manage_replies— reply to and hide replies.threads_manage_mentions— read and reply to mentions.threads_delete— delete, at your request, posts created by you through the dashboard.
Regarding search results: the public posts returned by
threads_keyword_search are displayed to you in the dashboard and are not
resold, redistributed or used to build a public index. We do not store the content of
third-party posts beyond what is necessary to display them in the session. Every search is
recorded in an audit log (organization, user and term searched).
3. Storage and security
Access tokens are encrypted at rest (AES-256-GCM). Access to data is isolated per organization and protected by authentication. We do not record the content of direct messages in logs.
4. Sharing
We do not sell your data. We may process content through vendors strictly necessary to the operation (for example, AI-assisted text generation and cloud hosting), subject to their own policies. We do not share data with third parties for advertising.
5. Retention and deletion
You control your data at any time:
- Disconnect: removing the Instagram or Threads connection in the dashboard revokes the corresponding token and stops collection.
- App removal: when you remove our app in the Instagram settings, Meta notifies us (deauthorization callback) and we revoke the corresponding connection.
- Data deletion request: we process the deletion request from Meta (data deletion callback), permanently removing the account's linked data and returning a confirmation code.
- Account deletion: you can delete your account and organization, removing all associated personal data.
The step by step for each of these options is in Data Deletion Instructions (available in Portuguese only).
6. Your rights
Under the LGPD (Brazil) and the GDPR (where applicable), you may request access, correction, portability or deletion of your data, as well as withdraw consents. To exercise these rights, use the controls in the dashboard or contact us.
7. Contact
Questions about this policy or about your data: privacidade@codecell.io.