Channel Connection Information
Moyeo receives only the authentication tokens issued by a channel through OAuth and never receives channel passwords.
- Tokens are stored encrypted with AES-256-GCM, using a new initialization vector for every write.
- Encryption keys are managed in a versioned keyring that writes with the new key and reads with previous keys, so keys are rotated without service interruption.
- Ciphertext is bound to the workspace, credential, platform and generation, so it cannot be decrypted if moved to another workspace.
- Authentication information, personal information fields, payment methods and idempotent responses use separate key families.
- When you connect a channel, we request the permissions needed for channel lookup, publishing, comments and performance features together, and explain the purposes of use on the connection screen.
Account Security
- Passwords are stored hashed with Argon2id, and the plaintext is never kept (64 MiB memory, 3 iterations).
- You can log in only after completing email verification, and a verification link is valid for 30 minutes and up to 5 uses.
- An account can be logged in on up to 5 devices at the same time; if you log in beyond that limit, the device that has gone unused the longest is automatically logged out.
- A login session lasts up to 30 days and expires after 7 days of inactivity.
- Sensitive actions, such as deleting your account, disconnecting a social login or logging out other devices, require re-authentication within the last 15 minutes.
- In settings, you can view the list of devices you are logged in on and log out individually or all at once.
- We record 19 types of security activity, including login, logout, password changes, email changes, and connecting and disconnecting social accounts, and the user identifiers and access IP addresses in those records are stored as hashed values instead of the originals.
- Session cookies and device cookies are issued with the HttpOnly, SameSite=Lax and Secure attributes.
Photos and Videos
- Files are uploaded directly to storage through a signed upload URL (valid for 10 minutes) and do not pass through Moyeo's API server.
- Uploaded files are checked against their SHA-256 digest and actually opened to verify their format and resolution.
- Images are re-encoded and stored in display and publishing versions, so the original's capture information (EXIF, GPS) does not remain, and orientation is corrected automatically.
- Allowed formats are JPEG, PNG and WebP, and MP4 and MOV.
- Originals used for publishing are kept for the period set by your plan. Files in use, such as in draft or scheduled posts, are retained; when the original retention period ends, the originals are deleted and previews are managed separately. Files that failed inspection are deleted after 1 day, and files not used anywhere after 7 days.
- When you disconnect a channel, we release the usage marks on files used for that channel's schedules and publishing, and those files are then kept or deleted according to the retention rules above. When you delete a workspace or your account, the corresponding files are deleted.
Data Deletion
- When you disconnect a channel, we discard the stored authentication information (for YouTube, we ask Google to revoke the token) and delete that channel's scheduling and publishing records and the post lists, comments and performance data fetched from it. Posts written in Moyeo remain, and their photos and videos remain in the library and follow the file retention rules.
- Account deletion ends your login sessions as soon as it is received and proceeds with deletion in stages, with no separate grace period.
- We process data deletion requests coming from Instagram and Threads and provide a code for checking their progress.
- Comments and performance data past the history period for each plan are deleted automatically.
If a security incident occurs at Moyeo that affects users, we notify them without delay by email and service notice.
Service Protection
- Excessive requests are limited automatically (by default 1,200 per minute, with stricter separate limits on login and authentication paths).
- We accept requests only from allowed origins and apply standard security headers.
- Cross-site request forgery is prevented with SameSite cookies and allowed-origin checks.
- Idempotency keys prevent the same request from being processed more than once.
Privacy and Analytics
- Visit and feature usage analytics is collected by default. Email, post content and internal account IDs are not sent to the analytics tool. Previously saved refusals and browser blocking are respected. See the Privacy Policy for collected information and collection controls.
- Error reports have URL query strings, cookies, headers and user-identifying information removed, and session recording is not used.
- Server logs do not record passwords, tokens or plaintext email addresses.
- The inquiry body and the screen and browser information sent with it are stored in Moyeo's database; the email address and display name needed for our reply are not stored but are read from the logged-in account and passed only in the email to the operator.
- Notification emails sent to operators do not contain passwords, authentication tokens or card numbers. Outage alert emails do not contain personal information.
Vulnerability Reports
If you find a security issue in Moyeo, please let us know at support@moyeo.io.
Revision history
| Effective date | Changes |
|---|---|
| 2026-09-29 (current version) | Clarified how files and data are handled when a channel is disconnected, and aligned terms with the app |
| 2026-09-26 | Clarified default analytics, collection controls and transmitted information |
| 2026-09-23 | Initial version |
