What This Document Covers
Moyeo uses data from the external platforms you connect only to perform the tasks you request. Below you can find, for each platform, the permissions we request, the data we receive, the purposes of use, and how the data is retained and deleted. This document forms part of the Privacy Policy and is not to be interpreted differently from it.
| Platform | What this section covers |
|---|---|
| Permissions and data used for professional account connection, publishing, comments, comment auto-reply and performance | |
| Threads | Permissions and data used for profile connection, publishing, replies, mention auto-reply and performance |
| YouTube | Channel, video, comment and performance data received through YouTube API Services |
| Google Sign-In | Account information used for sign-in and compliance with Limited Use |
| Kakao Login | Kakao consent items and unlinking |
| Data deletion | How to request deletion on each platform and how it is handled |
Moyeo is an independent service and is not operated or officially endorsed by Meta, Google or Kakao. The structure of this document follows the common way social media management tools disclose their per-platform data use.
You can choose the features you want to use before connecting. The basic connection permission is required, and publishing, comment and performance permissions are requested only to the extent needed for the features you choose. If you add a feature later, we request permissions again. Depending on the platform, one feature may require several permissions, and only approved features can be used.
When you connect an Instagram professional account, we request the permissions below on Meta's official authorization screen. Moyeo does not receive your Instagram account password.
| Permission requested | When it is requested | Data received | Purpose of use |
|---|---|---|---|
| instagram_business_basic | When you connect a channel | Account identifier, name, handle, profile image, account type | Verify the account to connect and display it on screen |
| instagram_business_content_publish | When you choose the publishing feature | Processing result of the publish request and the post identifier | Publish posts you have written or scheduled |
| instagram_business_manage_comments | When you choose the comment feature | Text of comments and replies, author's display name, handle and profile image, time of writing, attachments and links | Collect and display comments; write, hide and delete replies; perform the reply and Send DM actions of comment keyword auto-replies |
| instagram_business_manage_messages | Together with the comment feature | Text, sender identifier and time sent of DMs received by channels with DM auto-reply turned on | Send the reply you saved once to a DM containing a keyword. Received DMs are kept encrypted only until processed and are deleted right after processing, upon disconnection or permission removal, workspace deletion or a Meta data deletion request, and in any case within 24 hours; the log is kept for 30 days without the message text |
| instagram_business_manage_insights | When you choose the performance feature | Views, reactions and follower counts of posts and accounts, and aggregate ratios by age group, gender and region provided by the platform | Build the performance screens |
When we fetch posts, we also receive whether Instagram has attached an "AI info" label to each post and display it as-is on the post and comment screens. Moyeo does not add or change this label on its own, and includes the label in a publish request sent to Instagram only for posts where you turned on the AI info label yourself on the compose screen.
Data received is used only within the connected workspace and is not used for ad targeting, sale or profiling. If you request an AI feature and have reviewed the processing notice, we pass the minimum input necessary to process the request to the AI processor. The items passed and how they are processed are described in the Privacy Policy. Authentication tokens are stored encrypted. If you disconnect a channel, delete a workspace or delete your account, we delete the authentication credentials and that channel's comment, performance and media reference data, the auto-replies you created and their logs, and AI suggestions made using that data.
We operate both the Deauthorize callback and the Data Deletion Request callback provided by Meta. When you remove Moyeo's connection in your Meta account settings, we verify the signed request sent by Meta, stop any further use of the revoked credentials, delete the stored tokens and start deleting that channel's data. A revocation request for a previous connection is not applied to credentials from a newer connection. You can also request deletion by disconnecting in Moyeo's channel settings or through the data deletion procedure below. However, because Moyeo connects using Instagram Login, removing the app in your Meta account settings may not send a Deauthorize callback to Moyeo. To be sure the connection is removed, disconnect directly in Moyeo's channel settings or submit a request via the Data Deletion Instructions. When you request data deletion through Meta, we record the request in a ledger, start the deletion procedure, and return to Meta a confirmation code and a URL where the processing status can be checked. You can check progress on the status page opened with the confirmation code.
Threads
When you connect a Threads profile, we request the permissions below on Meta's official authorization screen.
| Permission requested | When it is requested | Data received | Purpose of use |
|---|---|---|---|
| threads_basic | When you connect a channel | Profile identifier, name, handle, profile image, list of posts | Verify the profile to connect and display it on screen |
| threads_content_publish | When you choose the publishing or comment feature | Processing result of the publish request and the post identifier | Publish posts you have written or scheduled |
| threads_location_tagging | When you choose the publishing feature | Location value you selected | Show a location on the post |
| threads_read_replies | When you choose the comment feature | Reply text, author's display name and handle, time of writing | Collect and display replies |
| threads_manage_replies | When you choose the comment feature | Reply processing results | Write and hide replies, and post the replies of comment keyword auto-replies |
| threads_manage_mentions | Together with the comment feature | Identifier and text of posts in which others mention you, author's display name and handle | Collect and display mentions and post replies, only while mention auto-reply is turned on |
| threads_manage_insights | When you choose the performance feature | Views, reactions and follower counts of posts and profiles | Build the performance screens |
Data is retained and deleted on the same basis as Instagram. Mention logs are kept for no longer than 30 days. Meta's Deauthorize callback and Data Deletion Request callback apply equally to Threads connections, and the possibility that the callback may not arrive and the reliable way to disconnect are also the same as for Instagram.
YouTube
Moyeo uses YouTube API Services.
By using the YouTube integration features, you agree to the YouTube Terms of Service, and Google's processing of personal information is governed by the Google Privacy Policy. The same document is also available at https://policies.google.com/privacy.
| Permission requested | When it is requested | Data received | Purpose of use |
|---|---|---|---|
| https://www.googleapis.com/auth/youtube.readonly | When you connect a channel | Channel identifier, channel name, channel profile image, list of videos with title, description, thumbnail and whether the "altered or synthetic content" label is set | Verify the channel and videos to connect and display them on screen |
| https://www.googleapis.com/auth/youtube.upload | When you choose the publishing feature | Upload result and video identifier | Upload the Shorts you specify |
| https://www.googleapis.com/auth/youtube.force-ssl | When you choose the comment feature | Text of comments and replies, author's display name, channel identifier and profile image, time of writing | Collect and display comments; write and hide replies; post a first comment |
| https://www.googleapis.com/auth/yt-analytics.readonly | When you choose the performance feature | Aggregate metrics for channels and videos such as views, watch time, reactions and subscriber changes | Build the performance screens |
Data received from the YouTube API is refreshed differently depending on its type. Performance metrics are refreshed once a day for each connected channel, and comments are refreshed by re-fetching recent activity about every 3 hours and re-fetching the entire history period once a day. Channel information such as channel name, handle, profile image and description is received and stored when you connect or re-authorize the channel, and refreshed by re-fetching about every 3 days. When a comment deleted on YouTube is confirmed as deleted during a run that fetches the entire history period, we erase its text immediately and delete its record within one day. Comments that have not been re-fetched for 30 days are deleted. Video information is re-fetched starting 27 days after it was last checked, and videos that have been deleted or could not be checked for 30 days are deleted together with their related performance data. Performance metrics received from YouTube Analytics are kept up to your plan's history period while access has been verified within the last 30 days and the connection and analytics permissions remain in place. If these conditions are not met, performance metrics older than 30 days are deleted. If you disconnect a channel, delete a workspace or delete your account, we delete the related data stored by Moyeo and ask Google to revoke the authentication token. Authentication tokens are stored encrypted.
If you disconnect a channel, delete your account, or request deletion in the Moyeo app, we delete the YouTube data stored by Moyeo within 7 days; if you revoke Moyeo's access in your Google Account security settings, we delete it within 30 days. The same deadlines apply to data of channels that can no longer be fetched because token refresh failed.
Data received is used only to provide the features displayed to you. It is not used for advertising purposes, is not provided for ad targeting or credit assessment, and is not provided to third parties or combined with information from other sources without your separate request or consent.
Moyeo does not create its own metrics from YouTube data. The screens show the metrics provided by YouTube as-is, and we do not add them to figures from channels not owned by the same owner or from other platforms, or newly calculate and display ratios, rankings or scores. Deleting information stored in Moyeo does not delete videos or comments published on YouTube.
You can revoke Moyeo's access at any time in Manage third-party apps with account access in your Google Account.
Google Sign-In
When you sign in with a Google account, we request the openid, email and profile permissions on Google's official consent screen. The information received under these permissions is your Google account identifier, email address, display name and profile image URL, and it is used only to create your account and to verify that the same person is signing in again.
Because Google Sign-In involves providing personal information to an overseas business, we disclose the recipient and country together.
| Recipient | Destination country | Items transferred | Purpose of transfer | Retention and use period | How to refuse and effect of refusal |
|---|---|---|---|---|---|
| Google LLC | Countries where Google's data centers are located, including the United States | Google account identifier, email address, display name, profile image URL | Account creation and sign-in verification | Until you disconnect or delete your account. Processing on Google's side thereafter follows Google's policy | You can sign up with email or use another sign-in method. If you refuse, you cannot use Google Sign-In |
If you disconnect Google Sign-In in your account settings or delete your account, we delete the connection record kept by Moyeo. However, because Moyeo does not store the token used for Google Sign-In, we cannot confirm on your behalf that the app permission on the Google account side has been revoked. Please revoke it yourself in Manage third-party apps with account access in your Google Account.
Google API Services Limited Use Disclosure
Moyeo's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The detailed requirements are available in the Google API Services User Data Policy.
- Information received is used only to provide and improve the features displayed to users.
- We do not transfer or sell information to third parties for any purpose, including advertising.
- Humans do not read the information. However, a minimal number of staff may access it with the user's explicit consent, or where necessary for security investigations, compliance with laws, or support requested by the user.
Kakao Login
When you log in with a Kakao account, we obtain your consent to provide the items below on Kakao's official consent screen.
| Kakao consent item | Item stored by Moyeo | Purpose of use |
|---|---|---|
| Kakao Account (Email) | Email address | Account identification and login, sending service notices |
| Nickname | Display name | Initial value of the name displayed on screen |
| Profile Image | Profile image URL | Initial value of the profile image displayed on screen |
Because Kakao is a domestic business, this provision does not constitute a cross-border transfer. You can disconnect Kakao Login under login connection management in your account settings. If you delete your Moyeo account, Redband requests Kakao to unlink, removing the connection between Moyeo and your Kakao account. If the unlink result cannot be confirmed, you can unlink it yourself under connected services management in your Kakao account settings. Kakao's processing of personal information is governed by the Kakao Privacy Policy.
Data Deletion
How to delete data and revoke permissions for each platform is as follows. For detailed procedures and contact channels, please see the Data Deletion Instructions.
- Instagram and Threads: Disconnect in the workspace's channel settings, or submit a request using the app data deletion feature in your Meta account settings. If you request through Meta, you can receive a confirmation code and a status check URL.
- YouTube: Disconnecting in the workspace's channel settings deletes the stored data and asks Google to revoke the authentication token. You can also revoke access in Manage third-party apps with account access in your Google Account.
- Google Sign-In and Kakao Login: Disconnect under login connection management in your account settings.
- Your entire Moyeo account: Deleting your account in account settings also deletes the connections above and related data.
- Browser push notifications: Turning them off for each device in the device list in notification settings immediately deletes that device's subscription information. A push subscription is a value issued by the browser and is not linked to any external platform account.
- If you cannot log in: Send your sign-up email and the scope of deletion to support@moyeo.io, and we will process the request after verifying your identity.
Revision history
| Effective date | Changes |
|---|---|
| 2026-09-29 (current version) | Aligned when Threads permissions are requested with the in-app feature name (comments), and aligned terms with the app |
| 2026-09-23 | Initial version |
