Privacy Policy
Last updated:
This Privacy Policy explains what Cora ("we", "us", the "app") collects, why, and the choices you have. Cora is a content-planning app for Instagram creators and small businesses: it mirrors your Instagram profile grid, lets you plan and schedule posts, and can publish them to Instagram on your behalf.
Who is responsible
The data controller is Cora. For any privacy request — access, export, correction, or deletion — contact privacy@apollotechstudio.com.
What we collect
Account information
- Email address — how you sign in and how we reach you about your account.
- Name and language — optional, taken from your sign-in provider when available.
- Sign-in identifier — if you sign in with Apple, Google or Facebook, we store the provider's opaque user identifier (never your provider password) to recognise you on return.
Cora accounts are passwordless — we do not store a password for you.
Instagram data (only when you connect an account)
Connecting Instagram is optional and uses the official Instagram API with Instagram Login. When you connect, with your authorisation we access and store:
- Your Instagram profile: user id, username, name, biography, profile picture, follower and following counts — to mirror your profile inside the app.
- Your Instagram media: images, videos, captions, permalinks and timestamps — to display and plan your grid.
- An access token, used to talk to Instagram on your behalf. The token is encrypted at rest, stored only on our server, and never sent to the app or any third party.
We request only two Instagram permissions:
instagram_business_basic (read your profile and media) and
instagram_business_content_publish (publish a post when you ask us to). We do not
read your direct messages, and we never post without an explicit action from you.
Content you create
- Planned and scheduled posts, drafts, captions, and bookmarks you save in the app.
- When you use the optional AI caption / hashtag assistant, the text you submit is sent to our AI provider (Anthropic) to generate a suggestion. It is used only to answer your request and is not used to train models. We keep a per-user usage count to enforce fair-use quotas.
Technical data
- Basic session data (IP address, device/user-agent) for security and to keep you signed in.
- If you enable notifications, a device push token so we can notify you (e.g. when a scheduled post is published).
How we use your data
- To provide the core service: show your grid, plan content, and publish to Instagram when you ask.
- To keep your Instagram connection alive (periodic token refresh) and your grid in sync.
- To send account and service messages (e.g. a sign-in code, a publish confirmation).
- To secure the service and prevent abuse.
We do not sell your personal data, and we do not use it for advertising.
Who we share it with
We share data only with the processors needed to run the service:
| Provider | Purpose |
|---|---|
| Meta / Instagram | Reading your profile and media, and publishing posts you schedule |
| Anthropic | Generating AI caption / hashtag suggestions you request |
| Apple / Google / Facebook | Verifying your identity when you sign in with them |
| Email & push providers | Delivering account emails and notifications |
| Cloud hosting | Running the servers and database that store your data |
How long we keep it
We keep your data for as long as your account exists. When you delete your account, or disconnect or remove Instagram, the associated data — including the Instagram access token, profile snapshot, grid posts and media — is deleted. Deleting Instagram data cascades to its snapshots, grid posts and media.
Your rights
- Access & export — request a copy of your data from within the app or by email.
- Deletion — delete your account and all associated data. See our Data Deletion page for the exact steps.
- Correction — ask us to correct inaccurate account data.
If you are in the EU/EEA, you may also lodge a complaint with your local data-protection authority.
Children
Cora is not directed to children under 13 (or the minimum age in your country), and we do not knowingly collect their data.
Changes
We may update this policy; the "last updated" date above reflects the latest version. Material changes will be notified in-app or by email.
Contact
Questions about this policy: privacy@apollotechstudio.com.