Privacy Policy
Last updated: August 30, 2026
This Privacy Policy explains how MLINO ("MLINO", "we", "us", or "our") collects, uses, stores, and protects information when you use MLINO Content Studio (the "Service"), including when you connect your Instagram professional account through Meta Platforms, Inc. ("Meta").
1. Who We Are
MLINO Content Studio is a content production and publishing platform that helps teams plan, create, review, and publish content, and connect their own social media accounts to manage approved publishing workflows.
2. Information We Collect
2.1 Account information
- Name, email address, and workspace details you provide when creating an account.
- Authentication credentials, stored using industry-standard hashing — we never store your password in plain text.
2.2 Content you create
- Drafts, briefs, images, captions, and other content you create or upload inside the Service.
- Review and approval history for that content.
2.3 Information from connected platforms (Meta)
MLINO connects to Instagram using Meta's "Instagram API with Instagram Login" — you sign in directly with your Instagram professional (Business) account; MLINO does not require a separate Facebook Page connection. When you connect an account, we receive:
- Basic account identifiers (account ID, username, account type) needed to publish on your behalf.
- An access token, scoped to the specific permissions listed below, which you approve during authorization.
- Publishing status information (e.g. whether a post succeeded) for content you explicitly approved for publishing.
- Basic, aggregate media insights (such as reach or interaction counts) for content published through the Service, read using the same permissions listed below, used to power in-app analytics.
We only request the permissions required for the features described in this policy. We do not request or use permissions for reading your private messages, or for any purpose you have not explicitly authorized.
2.4 Instagram permissions we request
| Permission | Why MLINO requests it |
|---|---|
instagram_business_basic |
Identifies the Instagram professional account you connect, and lets us read its basic account and media details. |
instagram_business_content_publish |
Lets MLINO publish a specific piece of content to your account, but only after you have explicitly approved that content inside the Service. |
MLINO does not request comment-management, direct-message, or advertising permissions — those are not implemented today (see what's available now).
2.5 Usage and technical data
- Log data such as IP address, browser type, and pages visited, used for security and reliability purposes.
3. How We Use Meta Platform Data
MLINO uses Meta APIs (specifically the Instagram API with Instagram Login) to let users connect their own professional Instagram account and manage approved publishing workflows. Data obtained through Meta APIs is used only to:
- Publish content to your connected account, but only after you have explicitly reviewed and approved that specific piece of content inside the Service — MLINO never publishes automatically just because content was AI-generated.
- Display the status of your connected account and recent publishing activity within your MLINO workspace.
- Show basic performance metrics for content you published through the Service, so you can see what worked.
- Maintain and troubleshoot the connection itself (e.g. detecting an expired or revoked token).
3a. AI Providers
MLINO uses DeepSeek to power the conversational assistant on our public marketing page (mlino.site) — the one that greets visitors and helps them understand the product before they have an account. That assistant only ever receives the visitor's own typed message and which page section they're viewing; it never has access to your workspace, your connected Instagram account, Meta Platform Data, or any other user data. If DeepSeek is unavailable, the assistant falls back to pre-written responses — no user or Meta data flows to DeepSeek in that fallback path either.
Content generation inside your actual MLINO workspace does not currently route through a third-party AI/LLM provider.
3b. Other Third-Party Service Providers
- Hosting infrastructure — our application and database run on a private virtual server we operate; we do not use a separate third-party database-as-a-service.
- Buffer — if a workspace chooses to publish through a Buffer-connected channel instead of (or in addition to) direct Instagram publishing, the approved content and a Buffer-specific access token are shared with Buffer to carry out that publish. This only applies to workspaces that explicitly set up a Buffer channel.
- DeepSeek — see AI Providers above; limited to the public marketing-page assistant.
4. How We Use Your Information (General)
- To provide, maintain, and improve the Service.
- To authenticate you and secure your account.
- To communicate with you about your account or the Service.
- To comply with legal obligations.
5. Data Storage and Security
- Access tokens for connected platforms are encrypted at rest and are never exposed in client-side code or API responses.
- Data for each workspace is logically isolated from other workspaces.
- We apply reasonable technical and organizational measures to protect your data, but no system can be guaranteed 100% secure.
6. Data Retention
We retain account and content data for as long as your account is active.
Disconnecting a connected Instagram account immediately and permanently stops MLINO from publishing to it or reading further data from it — every part of the Service that would use that connection checks its status first and skips it once disconnected. The encrypted access token record itself is not separately erased at the moment you disconnect; it is removed when you request full account/data deletion (see Data Deletion Instructions), or you can independently revoke MLINO's access from your own Instagram account settings at any time, which invalidates the token on Meta's side regardless of what MLINO does.
Raw provider API responses used for short-term debugging are retained for a limited period and then automatically purged.
7. Your Rights and Choices
- You can disconnect a connected Meta account at any time from your workspace settings — this immediately stops any further publishing access.
- You can request deletion of your account and associated data at any time. See our Data Deletion Instructions.
- Depending on your location, you may have additional rights to access, correct, or export your data. Contact us to exercise these rights.
8. Children's Privacy
The Service is not directed to individuals under 16, and we do not knowingly collect personal information from them.
9. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be reflected by an updated "Last updated" date above.
10. Contact Us
Questions about this Privacy Policy or your data? Reach us at privacy@mlino.site, or see our Contact page.