← Privacy & Terms EN RU

Meta Platform Integration Disclosure

Effective: April 11, 2026

This document describes how AI Orchestra integrates with Meta's Graph API (Facebook and Instagram) on your behalf, what data we read and write, what we store, and how you can disconnect.

It is the canonical, dedicated disclosure for Meta integrations and is referenced from the main Privacy Policy and from our Meta App Review submission notes. A live, technical reference mapping each requested permission to the exact Graph API endpoint is available at /meta-permissions.


1. Features that use Meta

The Platform exposes Meta integration through two distinct features. Each feature triggers its own Meta consent request and asks only for the scopes it actually needs (incremental authorization).

  • SMM Planner (/smm-planner) — schedules and publishes organic

content (Reels, posts) to your Instagram Business account. Requests publishing scopes only.

  • AI Target (/target) — manages paid Meta ad campaigns

(create, pause, activate, stop, read insights) under an ad account you own. Requests ads scopes only, and only when you explicitly click "Grant ads permission" inside the AI Target page.

A user who only publishes organic content never grants ads scopes, and vice versa.


2. Data we read from Meta

We only access data needed for the feature you actively use:

  • Facebook Page metadata (id, name, list of pages you administer) —

to identify which page is linked to the Instagram Business account you want to publish to.

  • Instagram Business account metadata (id, username, profile

picture) — to display which account is connected and to address publishing API calls correctly.

  • Page access token — required by Meta to publish content to the

linked Instagram Business account.

  • Long-lived user access token — required by Meta to call

ad-management endpoints on behalf of users who explicitly enable the AI Target feature.

  • Ad account list (id, currency, name, account status) — only if

you opt into AI Target; used to populate the ad-account picker.

  • Campaign performance metrics (impressions, reach, clicks,

spend, CTR, CPC) — only for ad campaigns you have created through AI Target.


3. Data we write to Meta

  • Organic content publication — when you click "Publish" in the

SMM Planner, we create a media container and publish it to your Instagram Business account using your page access token. No content is sent to Meta unless you explicitly trigger this action.

  • Paid ad campaigns — when you click "Submit" / "Activate" in

AI Target, we create / pause / resume / stop ad campaigns under the ad account you selected.


4. What we store

  • Encrypted page access token and encrypted user access token

(AES-256, per-row context, stored in user_instagram_tokens in our database).

  • Granted Meta permissions snapshot, last sync time,

instagram_user_id, page_id, page_name, facebook_user_id.

  • Records of content you have published or campaigns you have created

(id, status, timestamps, your input text/budget/targeting).


5. What we do not do

  • We do not read your Instagram direct messages.
  • We do not read or post to your personal Facebook profile.
  • We do not share Meta data with any third party.
  • We do not sell, license, transfer, or otherwise monetize Meta data

in any form — including anonymized, de-identified, or aggregated derivatives — in accordance with the Meta Platform Terms. Any aggregated or anonymized analytics we derive are used solely to operate and improve AI Orchestra for the originating user.

  • We do not use Meta data for any purpose other than the specific

feature it was granted for.

  • We do not transfer Meta data to any ad network, data broker, or

other advertising / monetization-related service.

  • We do not retain Meta data after you disconnect — see Section 7.

6. Permissions we request, and why

Each Meta Graph API permission is requested only for the corresponding user action:

| Permission | Requested when | Used for | |---|---|---| | instagram_basic | You click "Connect Meta" in SMM Planner | Read your Instagram Business account id and username | | instagram_content_publish | You click "Connect Meta" in SMM Planner | Publish a Reel or post to your account when you trigger it | | pages_show_list | You click "Connect Meta" in SMM Planner | List your Facebook pages so we can find the one linked to Instagram | | pages_read_engagement | You click "Connect Meta" in SMM Planner | Read the page access token from /me/accounts | | business_management | You click "Grant ads permission" in AI Target | List ad accounts you have access to | | ads_management | You click "Grant ads permission" in AI Target | Create / pause / resume / stop your ad campaigns | | ads_read | You click "Grant ads permission" in AI Target | Read performance metrics for your campaigns |

The technical reference at /meta-permissions adds the exact Graph API endpoint and code path for each permission.


7. Disconnection and deletion

You can disconnect at any time:

  • In the Platform — click "Отключить" / "Disconnect" on the

SMM Planner or AI Target connection card. Your stored Meta tokens are immediately marked as revoked and deleted from our active token store.

  • In Meta — go to *Settings → Business Integrations*, find

AI Orchestra, and remove access. Meta will call our deauthorization callback (/api/meta/deauthorize) and we will revoke and delete the tokens.

  • Permanent data deletion — submit a deletion request via Meta's

standard flow; Meta will call our data-deletion endpoint (/api/meta/data-deletion) and we will permanently delete all Meta-derived data associated with your Facebook user id, returning a confirmation code as required by Meta.

You may also email ai_orchestra_main@ai-orchestra.net at any time to request manual deletion.