Privacy policy
Orbit is a small, private tool that Studio Sojo uses to plan and publish social media posts, for itself and for a few local businesses it works with. This page explains what information Orbit handles, why, who else receives it, how long it is kept, and how to have it deleted.
The short version
- Orbit uses what Facebook and Instagram share with it only to publish posts, show how they did, and avoid posting the same photo twice.
- We do not sell information, use it for advertising, or build profiles of people.
- Orbit gets totals, such as follower counts. It gets no list of who follows, likes or comments.
- You can remove Orbit's access on Facebook at any time, and ask us to delete what Orbit holds: projectaxis@proton.me.
Who runs Orbit
Orbit is run by Studio Sojo (“we”, “us”). Orbit is not a public service: its operator screens are for Studio Sojo only, and sign-up is closed. You can reach us at projectaxis@proton.me.
Who this page is about
- Businesses whose Facebook Page or Instagram professional account is connected to Orbit, and the person who connects it.
- People who open a client review link that Studio Sojo sends them.
- People who appear in photos we prepare or post.
- Studio Sojo's own sign-in to Orbit.
Facebook and Instagram themselves are covered by Meta's privacy policy, not this one.
What Orbit gets from Facebook and Instagram
Orbit connects through Facebook Login. An Instagram account is connected through the Facebook Page it is linked to. With the permissions you grant when connecting, Meta shares:
- Account details. The name, username, ID and profile picture of the Page or Instagram account, and the list of Pages and linked Instagram accounts the connecting person manages, so the right one can be picked.
- The person who connects it. Their name, Facebook ID and profile picture. Orbit saves a copy of that picture.
- Access keys. The keys (tokens) Meta issues so Orbit can act for the Page or account.
- Statistics. Totals for the Page or account and for its posts, such as reach, views, likes, comments, shares and follower counts. Totals only.
- Past Instagram photos, only when we ask Orbit to check them. Orbit reads the photos that account published itself and the links to those posts. It uses each photo only to make a fingerprint, so it can warn us before the same photo is posted twice. It keeps the fingerprint and the links to the post and to the photo on Instagram, not the photo itself.
Orbit does not read private messages, does not read the text of comments, and gets no list of individual followers or of who liked or commented.
Why Orbit asks for each permission
pages_show_list,business_management- To list the Pages you manage, including Pages held in a business portfolio, so you can pick the right one.
pages_manage_posts- To publish the posts we schedule to your Page.
pages_read_engagement- To read your Page's name and picture, and the links and basic details of the posts we published.
read_insights- To read your Page's statistics (totals).
pages_manage_engagement- To add a comment under a post we published, when a post is set up with one. Orbit does not hide, delete or answer other people's comments.
instagram_basic- To read the Instagram account's name and picture and the posts it published.
instagram_content_publish- To publish the posts we schedule to the Instagram account.
instagram_manage_comments- To add a comment under a post we published, when a post is set up with one.
instagram_manage_insights- To read the Instagram account's statistics (totals).
Other information Orbit keeps
- Posts and photos. The posts, captions, drafts, schedules and photo library we prepare for each business. Photos may show people, such as staff or customers. If you, or your child, appear in a photo and want it taken down, email us.
- Client review links. Studio Sojo can send a business a private link to review its own upcoming posts. There is no account or password. Orbit stores the label we give the link (which may include your name), when the link was last used, and what you do there: approvals, change requests, suggested wording and notes. Orbit does not ask for or store your email address.
- Sign-in details. For Studio Sojo's own account: name, email address, password (stored only in scrambled, hashed form), the IP address and browser recorded when the account was created, and when it was last active.
- Notifications. If Studio Sojo turns on notifications on a device, Orbit stores that device's push address and browser type, so it can send alerts such as “a client asked for a change”.
- Technical logs. Times of requests, which pages were asked for, and error messages, used to find and fix problems.
How we use it
Only to run Orbit: to publish the posts we schedule, show what went out and how it did, let a business review its posts, warn us before a photo is repeated, and keep Orbit working. We do not sell any of it, use it for advertising, or build profiles of people. We use information from Facebook and Instagram only for these purposes.
Who else receives information
We share information only with the services that make Orbit work, each for the reason given here, and when the law requires it.
- Meta (Facebook and Instagram) receives the posts, captions and photos we publish, and Orbit's requests for account details and statistics.
- Cloudflare, for photo copies. When a post with photos goes to Facebook or Instagram, Orbit puts a copy of each photo in that post in Cloudflare R2 storage, at a random, hard-to-guess web address on media.orbitlaunch.app, so Meta can fetch it. Anyone who has that exact address can open the copy until it is deleted. Copies are deleted automatically, normally within 31 days, and straight away if the post definitely did not go out. The photo library itself stays on Orbit's computer.
- Cloudflare, for client links and these pages. Client review links and these pages are delivered through Cloudflare's network, which sees visitors' IP addresses in order to do that. If a client link is protected by a one-time email code (Cloudflare Access), you type your email address on a Cloudflare page and Cloudflare emails you the code. Cloudflare handles that address under its own privacy policy.
- Google (Gemini API) receives the text Orbit is working on (drafts, captions, brand notes and Studio Sojo's chat messages) and smaller copies of library photos, to write captions and alt text, describe photos and answer Studio Sojo's questions. On Google's unpaid tier, Google may use what it receives to improve its products, and people at Google may review it.
- Groq is a backup for Gemini. When it is used, it receives the same kind of text, but no photos.
- Push services. Alerts to Studio Sojo's own devices go through the push service of that device's browser, for example Apple's for an iPhone.
Orbit does not send access keys, statistics or account details from Facebook or Instagram to Google or Groq. Each service above handles information under its own terms and privacy policy.
Where it is kept, and for how long
Orbit and its database run on a computer that Studio Sojo controls. We keep backup copies on storage we control.
- Access keys and account details: while the Page or account is connected. Disconnecting it inside Orbit stops all use straight away, but does not by itself erase the stored record. We erase that record when you ask us, and within 30 days after we stop working with the business. Meta can also end Orbit's access on its own, for example after a password change or when the access is removed on Facebook.
- Statistics: not stored. Orbit asks Meta when they are viewed and holds the answer for an hour at most.
- Photo copies on media.orbitlaunch.app: normally deleted within 31 days, as described above.
- Photo fingerprints and post links: until you ask us to delete them, or until we stop working with the business.
- Posts, photos, drafts and client feedback: while we work with the business, and deleted on request.
- Technical logs: no longer than 90 days.
- Backups: when we delete something at your request, we also delete it from the backup copies we keep.
Security
Orbit's operator screens require a sign-in, and sign-up is closed. Access keys are kept in Orbit's database and its backups, and are sent only to Meta, when Orbit uses them. No system is perfectly secure. If we learn that your information was exposed, we will tell you.
Your choices
- Remove Orbit's access at any time on Facebook: Settings & privacy → Settings → Business integrations → Orbit → Remove (Meta's help page). Because Instagram connects through Facebook, this also ends Orbit's access to the Instagram account.
- Ask us to see, correct or delete your information at projectaxis@proton.me. The Data deletion page explains what we delete and how long it takes.
- Depending on where you live, you may have further legal rights over your information. Email us and we will help.
Children
Orbit is a business tool and is not meant for children to use.
These pages
These pages set no cookies, run no scripts, and load nothing from other websites.
Changes to this policy
If we change this policy, we will update this page and the date at the top. If a change affects a business we work with, we will tell that business directly.