Privacy & Data ProtectionMeta Threads API Compliant

Privacy Policy

Last Updated: August 15, 2026

This Privacy Policy explains KuroDeskโ€™s comprehensive commitment to protecting your personal data, encryption standards, zero data-resale guarantee, and our strict compliance with Meta Developer Policies and the Threads API.

1. Introduction & Overview

KuroDesk ("we", "our", "us", or the "Platform") is a personal productivity, project management, and automated social media workflow platform. We are committed to protecting and respecting your privacy.

This Privacy Policy outlines how your personal data and third-party platform credentials (including Meta Platforms, Inc., Threads API, X Corp, and OpenRouter AI) are collected, processed, encrypted, stored, and protected when you access and use our web application and services ("Services").

By registering an account or linking third-party services to KuroDesk, you explicitly acknowledge and agree to the practices outlined in this Privacy Policy.

2. Meta & Threads API Data Collection & Limited Use

When you explicitly connect your Threads or Meta account to KuroDesk via official OAuth 2.0 authentication, we request permissions such as "threads_basic" and "threads_content_publish". We collect only the minimum required data to provide our automated scheduling and publishing functionality:

  • Threads User ID (threads_user_id): A unique alphanumeric identifier assigned by Meta to identify your account.
  • Threads Username & Display Name: Used to confirm account connection and display the connected profile in your dashboard.
  • Profile Avatar URL: Displayed solely within your private workspace interface for visual account verification.
  • OAuth Access Token: A scoped, secure token used exclusively to publish and schedule user-authorized posts on your behalf.
  • Published Media & Post IDs: Post identifier strings returned after successful publication to update your content calendar status.

2.1 Limited Purpose & Zero-Resale Guarantee

We strictly adhere to the Meta Developer Policies and Threads Platform Terms.

Your Threads data and access tokens are used solely for the technical execution of publishing, scheduling, and monitoring posts that you explicitly create.

We DO NOT sell, rent, lease, monetize, or transfer any user data, Meta platform data, or Threads credentials to third parties, data brokers, or advertising networks under any circumstances.

3. General Information We Collect

In addition to social media integrations, KuroDesk collects the following categories of information to maintain platform functionality:

  • Account Credentials: Email address and securely salted hashed passwords (we never store plain text passwords).
  • User Workspace Data: Project boards, task checklists, notes, financial income/expense records, and scheduled content drafts.
  • AI & API Keys: Optional Bring-Your-Own-Key (BYOK) OpenRouter API credentials, stored strictly in encrypted format.
  • System & Dispatcher Logs: Technical timestamps, execution statuses (e.g. Published, Pending, Failed), and scheduler activity logs visible in your dashboard.

4. Data Security & Encryption Standards

We implement industry-grade technical and organizational safeguards to ensure your credentials and personal data remain confidential and secure at all times:

  • AES-256 Encryption at Rest: All social media access tokens (Threads, X, Facebook) and OpenRouter API keys are encrypted at rest in our database using advanced AES-256 encryption.
  • TLS 1.3 / HTTPS in Transit: All communications between your client browser, our servers, and the Meta Graph API are transmitted over encrypted TLS/SSL connections.
  • Database Isolation: Each user's project credentials and workspace records are strictly segregated by verified user ID tokens and protected with row-level authorization.
  • Zero Token Exposure: Raw access tokens are never logged in plain text or rendered on public-facing interfaces.

5. Third-Party Disclosures & API Partners

KuroDesk interacts with external services only when initiated by your explicit actions or automation configurations:

  • Meta Graph API (Threads / Facebook): To publish user-authorized content containers and retrieve publication confirmation.
  • X API (Twitter): To execute tweet publications via user-provided credentials or OAuth.
  • OpenRouter AI: To process AI copywriting prompts and text variations when triggered by the user.

6. User Rights & Data Deletion Instructions

You maintain full ownership and control over your personal data, connected accounts, and tokens. You may exercise the following rights at any time:

  • Instant Account Disconnection: You can disconnect your Threads, X, or Facebook account at any moment via Project Settings > Disconnect. Disconnecting immediately and permanently purges the stored OAuth access token and user ID from our active database.
  • Automated Meta Deletion Callback: When you remove KuroDesk from your Threads/Meta connected apps settings, Meta automatically notifies our webhook, which triggers immediate deletion of your tokens across all workspaces.
  • Complete Account Erasure: You may request the permanent deletion of your entire KuroDesk account and all associated workspace data by emailing privacy@kurodesk.id or support@kurodesk.id. We process all erasure requests within 48 hours.

7. Policy Changes & Contact Information

We may update this Privacy Policy periodically to reflect new features, legal requirements, or Meta platform policy updates. Material changes will be communicated via email or an in-app banner notification.

For inquiries, data protection requests, or compliance questions, please contact our Data Protection Team:

  • Email: privacy@kurodesk.id / support@kurodesk.id
  • Platform: KuroDesk Data Privacy & Compliance Office

Meta Data Deletion Request & Callback

KuroDesk supports automated Meta user data deletion callbacks. You can disconnect your Threads account instantly from the project settings page or request complete account erasure by contacting support@kurodesk.id with your Threads username.

Questions About Your Data & Privacy?

Our compliance and data security team is ready to answer any questions regarding your OAuth tokens, encryption, or deletion requests.