MMoises
Internal Application · Meta Platform

Meta Platform Privacy Policy

Last updated: 7 October 2026

This Meta Platform Internal Privacy Policy describes how Moises Systems Inc (“Moises”, “we”, “our”, or “us”) accesses, uses, stores, protects, and deletes data obtained through the Meta Platform — including the Instagram Graph API, the Facebook Graph API, and the Meta Marketing (Ads) API — for internal business purposes.

1.Scope and Purpose

Moises uses the Meta Platform only for internal business activities related to:

Our Meta Platform integrations are not public-facing products. They support internal analysis and reporting. A publicly reachable review website demonstrates the integration to Meta reviewers using Facebook Login. Its login page and this policy are public; account data requires authentication and is limited to the assets authorized by the person signing in. Authenticated discovery additionally accesses public Instagram hashtag posts and professional profiles through Meta Hashtag Search and Business Discovery on behalf of an authorized Instagram professional account. The internal production reports remain restricted to authorized Moises personnel.

Authorized assets

The review website reads Facebook Pages, linked Instagram professional accounts, and advertising accounts that the signed-in user authorizes. Moises uses the resulting analytics for internal business purposes. The review website does not create or edit advertisements, publish posts, or provide public access to company reports.

2.Relationship to Meta Policies

Our use of the Meta Platform is subject to the Meta Platform Terms and the Meta Developer Policies. Use of Meta products is also subject to Meta’s Privacy Policy.

Administrators of a Moises Meta asset may review or revoke this application’s access at any time:

3.Meta Platform Data We Access

Depending on the specific internal workflow, within the authorized account and public hashtag and professional-profile workflows described here, we may access the following categories of data.

3.1 Instagram professional accounts

3.2 Facebook Pages

3.3 Meta Ads (authorized ad accounts, Marketing API)

3.4 Review website login

The website receives the Facebook user ID and name, email if granted, granted permissions, and an access token. It records login identity, granted permissions, and login time in a restricted Firestore collection. Access tokens are not written to that login record.

3.5 Public Instagram hashtag discovery

On behalf of an authorized Instagram professional account, the review website reads Meta’s recent hashtag search history, searches user-entered campaign hashtags, and displays recent public post captions, publication times, media previews, original links, and available like and comment counts. Search queries are sent to Meta and may be included in Meta’s rolling seven-day hashtag history. The website does not maintain a separate permanent hashtag registry or persist the returned public posts. These posts may belong to accounts Moises does not manage. The interface does not retrieve commenter identities or comment text from public hashtag posts.

3.6 Public professional Instagram profiles

The review website uses Instagram Business Discovery to look up a user-entered professional username and read public profile details, follower counts, public media and available like/comment counts for internal campaign planning. These profiles may belong to creators Moises does not manage. This view does not read private account insights or comment text from those creators. Returned profiles and media remain in session memory and are not persisted by the review website.

4.How We Use the Data

Meta Platform data is used solely to produce internal reports and dashboards for the Moises team — measuring audience growth, content performance, community sentiment on our own content, advertising effectiveness, and public engagement around campaign hashtags. We do not use this data for automated decisioning about individuals, for advertising to third parties, or for any purpose beyond Moises’ internal analytics.

5.Storage and Access Controls

Internal data pipelines may store Meta Platform data in access-controlled Google Cloud services, BigQuery tables, internal databases, logs, and reporting environments. The review website separately requests analytics from the Graph API during the authenticated session; it does not persist the returned Page, Instagram, public hashtag, professional-profile, comment, or advertising analytics. Its login audit record is stored in Firestore.

Moises applies access controls designed to limit access to authorized personnel with a legitimate business need, including account-based permissions, role-based access controls, and project-level permissions. We do not sell Meta Platform data and do not provide unrestricted public access to it.

6.Data Sharing

Moises does not sell Meta Platform data. Such data may be accessed internally by authorized personnel or processed by infrastructure service providers (for example, Google Cloud) used to operate Moises systems, subject to appropriate access controls and business purposes. Moises does not make Meta Platform data publicly available and does not provide external users with direct access to raw Meta Platform data.

7.Data Retention, Refresh, and Deletion

Moises retains Meta Platform data only for as long as necessary to support the internal purposes described in this policy and in accordance with the Meta Platform Terms and Developer Policies. Stored data is periodically refreshed, updated, or removed.

If this application’s access to a Meta asset is revoked, Moises will delete the applicable authorized Meta Platform data as soon as reasonably practicable and within any timeframe required by the Meta Platform Terms.

Requesting deletion of your data

To request access to, correction of, or deletion of any Meta Platform data that Moises may hold in connection with an account you administer, email [email protected] with the subject line “Meta Data Deletion Request”. We will verify the request and delete the applicable data within 30 days.

You may also revoke access at any time through the Meta settings listed in Section 2; upon revocation, the associated authorized data is deleted as described above.

8.Cookies and Tracking

The review website uses an essential, short-lived OAuth state cookie and an encrypted session cookie marked HttpOnly, Secure, and SameSite=Lax. The session contains the Facebook access token so the server can request the authorized data. Signing out removes the session cookie. The review website does not use advertising trackers or build advertising profiles of individuals.

9.Security

Moises uses administrative, technical, and organizational safeguards designed to protect Meta Platform data against unauthorized access, misuse, disclosure, alteration, or deletion. These safeguards may include internal access controls, restricted Google Cloud Platform permissions, authentication requirements, logging, monitoring, and separation of internal environments.

10.Changes to This Policy

Moises may update this policy from time to time to reflect changes in internal systems, business practices, legal requirements, or Meta Platform policies. The “Last updated” date at the top of this policy indicates when it was most recently revised.

11.Contact

ControllerMoises Systems Inc
Deletion[email protected] · subject “Meta Data Deletion Request”