MINT

Privacy Policy

Last updated: September 5, 2026

1. Information we collect

2. Exact Threads and Instagram API use

Threads is approved maintenance-only and default OFF. The already approved threads_basic permission displays the connected user's own profile and posts read-only. The threads_content_publish campaign is used only to publish a text post that the user explicitly approves.

Instagram is review-only and default OFF. It is limited to instagram_business_basic and instagram_business_content_publish, one immediately published JPEG and caption explicitly approved by a human, and execution-time gates. This policy does not claim a live connection, pilot, or publication has been verified. Facebook is a static, not-connected mock with no real account, token, permission, or external API access.

3. Token and secret protection

Threads and Instagram publishing credentials are owned by their workspace/account and encrypted at rest with versioned AES-GCM. MINT never stores or displays tokens, authorization codes, passwords, OTPs, reviewer codes, or encryption keys in cookies, plaintext database fields, logs, AuditLog metadata, or UI output.

4. Why we use the data

5. Sharing

We do not share personal data except with the user's explicit consent, where legally required, or with contracted service providers to the minimum extent necessary. For an immediate plan, an approved post body is sent to Threads only when the user separately chooses Publish. For a scheduled plan, explicit Approval authorizes the displayed due time; schedule creation sends nothing to Threads, and every gate is re-checked when execution becomes due.

6. Retention, disconnect, and deletion

Read the exact data deletion instructions.

7. Cookies

MINT uses only cookies needed for authentication, locale, CSRF protection, and short-lived OAuth state. Threads and Instagram publishing tokens are never stored in a cookie. MINT does not use advertising cookies.

8. Security and changes

Controls include encryption, least privilege, explicit approval, idempotency, due-time revalidation, and redacted audit. Material changes to this policy will be announced in the service.

9. Contact

Contact the Support page or support@sns-mint.com.

日本語