Orvoro Social

Privacy Policy

Who we are

Orvoro Social is a scheduling tool operated by [legal entity name], [registered address]. Questions about this policy or your data: [privacy contact email].

What we collect

We do not use advertising cookies or third-party analytics. The only cookie set is the one that keeps you signed in.

What we do not collect

We do not read your messages, contacts, or friends lists, and we do not request the permissions that would let us. We ask each platform only for the ability to identify your account and publish to it. Location metadata (EXIF GPS) is stripped from photographs when you upload them, so it is neither stored by us nor forwarded to any platform.

How your tokens are protected

The tokens that let us post on your behalf are encrypted with AES-256-GCM before they are written to our database, using a key held outside it. They are never written to logs and never returned by our API — not even to you.

What we send to the social platforms

When you publish, we send the platform you chose the caption and images for that post, the alt text you wrote, and any publishing options you selected. Nothing is sent to a platform you did not select, and nothing is ever published without you pressing Publish or scheduling it yourself. Each platform then handles that content under its own privacy policy: Meta (Facebook and Instagram), TikTok, LinkedIn, and X.

Images you attach are served from a temporary link with a signature in it that expires, because Facebook, Instagram and TikTok fetch pictures from us rather than accepting an upload. The link is unguessable and stops working once it expires.

Your rights

Changes

If this policy changes materially we will say so in the app before the change takes effect.