les Archives[ Policies ]
04

Platform Compliance

Effective September 9, 2026 · Les Archives, LLC

les Archives publishes to Instagram and Pinterest on your behalf. Both platforms set rules for apps like ours. This page says what those rules require and, plainly, how we meet them. Where we have not built a control, we say so.

Instagram (Meta)

les Archives uses the Instagram API with Instagram Login and requests two permissions: instagram_business_basic (to read the basic profile of the account you connect) and instagram_business_content_publish (to publish the posts you create). We are bound by Meta's Platform Terms and Developer Policies, both last updated February 3, 2026, and by the Instagram Platform documentation. Here is how we follow them.

What Meta requires, and what we do

RequirementOur practice
Maintain a public privacy policy that clearly explains what data is processed, how, and for what purposes (Platform Terms, section 4).Our Privacy Policy lists every category of data we hold, including the Instagram token, user ID, username, and account type, and the log of posts we publish.
Use Platform Data only for the purpose the user approved; do not sell, license, or purchase it; do not share it except with service providers under contract, with the user's consent, or as required by law (Platform Terms, section 3).We use your Instagram data for one thing: publishing the posts you create and showing you which account is connected. We do not sell it, share it with data brokers, or use it to build profiles. Our service providers are listed in the Privacy Policy.
A permission only allows access to data created by the user who granted it (Instagram Platform overview).Each connection is scoped to the workspace that made it. We read only the connected account's own profile and publish only to that account.
Delete Platform Data when the user asks, when they remove the app, when it is no longer needed, or when Meta requests it. Give users an easily accessible and clearly marked way to request deletion (Platform Terms, section 3.d).Disconnecting in the app deletes the token immediately. Removing les Archives inside Instagram triggers our deauthorize callback, which deletes the token and account details. A data deletion request from Instagram triggers our deletion callback, which also removes the publish log and returns a confirmation code you can check on our Data Deletion page. Tokens expire on their own after about 60 days if not refreshed.
Maintain administrative, physical, and technical safeguards; report security incidents promptly (Platform Terms, section 6).The app secret and all tokens live only on our server-side functions and are never sent to the browser or the Mac app. Database access is limited by row-level security per workspace. We will notify affected users promptly if we learn of a breach.
Do not confuse, deceive, mislead, spam, or surprise anyone; obtain explicit consent before taking actions on a user's behalf; provide accessible support (Developer Policies, section 1).Nothing is published unless you create the post, choose the image, write or approve the caption, and schedule or send it. Scheduled posts go out at the time you set. Support is a real inbox: hi@lesarchives.app.
Respect Instagram's functionality and limits; be clear about your relationship with Meta (Developer Policies, section 2).We publish through the official Content Publishing API, within its rate limits. les Archives is an independent product and is not affiliated with, endorsed by, or sponsored by Meta.
Respect the rights of the owners of Instagram photos and videos (Developer Policies, section 6).We only publish images that you, the photographer, upload and own. We do not import, display, or back up other people's Instagram content.
Complete App Review for Advanced Access and Business Verification when serving accounts you do not own (Instagram Platform overview).les Archives is submitted for Meta App Review and Business Verification before it is offered to accounts outside our own.

What we do not do

We do not read or send direct messages. We do not read or post comments. We do not read your followers or the accounts you follow. We do not request permissions for any of these. We do not use automation to like, follow, comment, or otherwise engage on your behalf.

Pinterest

les Archives publishes pins through the Pinterest API (v5) and is bound by Pinterest's Developer Guidelines and Developer and API Terms. Here is how we follow them.

RequirementOur practice
Have a privacy policy consistent with applicable law and link it when applying for API access ("The basics").Our Privacy Policy covers the Pinterest tokens, default board, and publish log we hold.
Do not store information accessed through Pinterest beyond what you need; call the API when you need data. Do not share or sell information from the API with third parties ("The basics").We store the minimum needed to publish: your access and refresh tokens, the board you pick as your default, and the IDs of the pins we created for you so the app can show your history. We do not cache your boards, pins, followers, or any other Pinterest content, and we never share or sell any of it.
Do not scrape or use automated means to extract information from Pinterest ("What not to do").We only call the official API, and only to create the pins you asked for and to refresh your token.
Do not offer features that let users automatically initiate actions without specifically considering each action ("What not to do").Every pin is created from an image you selected, with a title and description you can edit, and is queued only when you tell us to queue it. Scheduling spreads your chosen pins across days at the pace you set; it does not invent pins.
Link pins back to their source; do not alter Pinterest content ("Publishing Pinterest content").Pins we create carry the destination link you set, normally your own website or gallery. We do not republish or alter Pinterest content anywhere.
Honor revocation. Disconnecting in the app deletes your tokens. Revoking les Archives inside Pinterest invalidates them on Pinterest's side; email us and we will remove any remaining record.

les Archives is an independent product and is not affiliated with, endorsed by, or sponsored by Pinterest.

Honest limits

Two things we want to say out loud rather than bury. First, Pinterest publishing runs on a shared les Archives developer app; some early workspaces used their own Pinterest app credentials, which we store on their behalf. Second, we do not yet receive an automatic revocation notice from Pinterest the way we do from Instagram, so a token revoked on Pinterest's side is removed from our records when it next fails to refresh or when you ask us. We will update this page as those change.

Questions or concerns

If you are a platform reviewer, a user, or anyone else with a question about how we handle platform data, write to hi@lesarchives.app. Security researchers can use the same address to report a vulnerability, and we will respond.

Sources: Meta Platform Terms and Developer Policies (developers.facebook.com, last updated February 3, 2026); Instagram Platform overview and Data Deletion Callback documentation (developers.facebook.com/docs); Pinterest Developer Guidelines (policy.pinterest.com). Reviewed September 9, 2026.