Privacy Policy
Last updated: 31 May 2026
Heion Social (the “Service”) is a social-content publishing product operated by Heion Technologies. This policy explains what data we collect, how we use it, and the choices you have. Questions: terencemakkahei@gmail.com.
1. Data we collect
- Account email — to identify you and sign you in.
- Password (only if you sign up with email) — stored hashed with scrypt, never in plaintext.
- Google account identity (only if you sign in with Google) — your email and basic profile, used for sign-in only; we do not store Google access tokens.
- Threads access token — to publish on your behalf. Stored encrypted (AES-256-GCM), server-side only, and never sent to the browser.
- Threads account id / username — to show your connection status.
- Content you create — sources, ideas, and your tone and content preferences.
- Publish audit records — for accountability and your history.
We do not store your Meta/Threads password, and we do not sell personal data.
2. How we use data
- To authenticate you and maintain your session.
- To connect your Threads account and publish only content you have explicitly approved — there is no automatic publishing.
- To keep an audit trail of publish attempts.
- To personalize content suggestions using your stored preferences.
3. Third parties
- Meta (Threads) — we send the content you approve and receive post ids; governed by Meta’s platform terms.
- Google — sign-in identity only, if you choose Google sign-in.
- Supabase — database and authentication provider.
- Cloudflare — application hosting.
4. Data retention & deletion
You can disconnect Threads at any time (which wipes the stored token), and delete your account and associated data from Settings → Danger zone. You may also request deletion of the data we obtained via Threads; see our data deletion page. We honor Meta-initiated data-deletion requests through our deletion callback.
5. Security
- Access tokens are encrypted at rest (AES-256-GCM) and used only in server-side handlers.
- Sessions use a secure, httpOnly cookie; we never place tokens in the browser.
- All traffic is served over HTTPS.
6. Your choices
You can access, correct, or delete your data using the in-app controls, or by contacting us at terencemakkahei@gmail.com.
7. Children
The Service is not directed to individuals under 18.
8. Changes & contact
We will post any changes to this policy on this page. The Service is operated from Hong Kong. For any privacy question or request, contact terencemakkahei@gmail.com.