Back to WorkspaceCompliance · Graph API v21.0
Legal Notice

Privacy Policy

Last updated: September 2026 · Effective across all connected workspaces

1. Overview & Data Philosophy

Orbit Workspace (“we”, “our”, or “the Service”) provides automated multi-account content scheduling, analytics aggregation, and publishing workflows for Instagram Business and Creator accounts through official Meta Graph API integrations.

We strictly limit data collection to the minimum technical parameters required to publish content on your behalf, render scheduled feeds, and calculate performance metrics. We never sell, rent, or monetize your account data.

2. Information We Access via Meta Graph API

When you authorize your Instagram account through our Facebook Login integration, we receive:

  • Instagram Business / Creator Account ID, username, and public profile picture
  • Connected Facebook Page identifier
  • Public media metrics (impressions, reach, engagement rates)
  • Limited-scope OAuth access token with expiration metadata

3. Token Security & Encryption Standards

All user and page access tokens are encrypted at rest using industry-standard AES-256-GCM encryption with unique initialization vectors (IVs) and authentication tags before being written to our database.

Tokens are stored in isolated cryptographic tables and decrypted strictly in memory inside ephemeral server execution contexts during active publishing jobs.

4. Data Retention & Deletion

You have the right to revoke account access at any time. When you disconnect an account via the Accounts dashboard or via Facebook App Settings, all associated access tokens are revoked immediately with Meta and deleted permanently from our database.

To submit an automated data deletion request, please visit our Data Deletion Page.