Privacy Policy
Last updated: August 8, 2026
1. Information we collect
- MINT account data: email address, display name, workspace membership, and role.
- Threads connection data: the connected user's bounded profile identity, display name, exact granted permissions, and token expiry/status metadata.
- Publishing workflow data: text drafts, previews, DryRuns, ActionRequests, approvals or rejections, schedules, executions, and normalized external publication results.
- Safety and audit data: identifiers, hashes, timestamps, and normalized outcomes/errors that exclude post bodies and secrets.
2. Exact Threads API use
Threads is the only real provider. The already approved threads_basic permission displays the connected user's own profile and posts read-only. The new threads_content_publish review campaign is used only to publish a text post that the user explicitly approves.
MINT neither requests nor accesses reply, mention, moderation, delete, edit, insights, keyword/profile search, location, or media permissions. Facebook and Instagram are static, not-connected mocks with no real account, token, permission, or external API access.
3. Token and secret protection
A Threads publishing credential is owned by its workspace/account and encrypted at rest with versioned AES-GCM. MINT never stores or displays tokens, authorization codes, passwords, OTPs, reviewer codes, or encryption keys in cookies, plaintext database fields, logs, AuditLog metadata, or UI output.
4. Why we use the data
- Account connection, text composition, preview, human approval, scheduling, publishing, and result display
- Duplicate prevention, token refresh, reauthentication, recovery, safety, and audit
- Product improvement and support
5. Sharing
We do not share personal data except with the user's explicit consent, where legally required, or with contracted service providers to the minimum extent necessary. For an immediate plan, an approved post body is sent to Threads only when the user separately chooses Publish. For a scheduled plan, explicit Approval authorizes the displayed due time; schedule creation sends nothing to Threads, and every gate is re-checked when execution becomes due.
6. Retention, disconnect, and deletion
- MINT-local disconnect removes MINT's proof/snapshot, encrypted credential, and saved grants, and causes scheduled work to fail closed.
- Local disconnect does not remove MINT from Threads Website permissions. The user must separately remove that authorization in Threads settings when appropriate.
- Verified signed Threads deauthorization and data-deletion callbacks idempotently purge the matching provider account's credential and related data.
- Published Threads posts are controlled by Threads. MINT does not request or execute a delete permission in this campaign.
- Audit records may be retained for fraud prevention, security, and legal obligations, then deleted under the applicable retention policy.
Read the exact data deletion instructions.
7. Cookies
MINT uses only cookies needed for authentication, locale, CSRF protection, and short-lived OAuth state. A Threads publishing token is never stored in a cookie. MINT does not use advertising cookies.
8. Security and changes
Controls include encryption, least privilege, explicit approval, idempotency, due-time revalidation, and redacted audit. Material changes to this policy will be announced in the service.
9. Contact
Contact the Support page or support@sns-mint.com.