Keystone

Legal · Account integrations

Connected Accounts Privacy Policy

CONNECTED ACCOUNTS PRIVACY POLICY

Effective Date: August 25, 2026 | Last Updated: August 25, 2026

This Connected Accounts Privacy Policy explains how Keystone Listings, a service operated by Trusty Goat, Inc. ("Keystone," "we," "us," or "our"), handles information when a customer connects a third-party social-media or content-publishing account to Keystone. It supplements the Keystone Listings Privacy Policy. If the policies conflict concerning connected-account information, this policy controls for that information.

1. Scope

This policy applies when you connect an eligible third-party account, such as an Instagram professional account or Facebook Page, and use Keystone to prepare, publish, schedule, manage, or measure content for that account. A connection is optional. You may use other Keystone features without connecting a social account unless a particular feature expressly requires one.

Keystone only accesses an account after an authorized account administrator completes the provider's authorization flow and grants the permissions shown on the provider's consent screen. We do not ask for or store your Facebook or Instagram password.

2. Connected-Account Information We Collect

Depending on the provider, the permissions you grant, and the features you use, Keystone may receive or process:

  • Account identifiers and profile information, such as provider account ID, Page ID, username, display name, profile image, account type, and the Pages or professional accounts you are authorized to manage.
  • Authorization information, including access tokens, refresh or long-lived tokens when supplied, granted permissions, token status, connection time, and revocation or expiration information.
  • Content and publishing information, such as images, videos, captions, links, hashtags, publishing destinations, drafts, schedules, provider media-container IDs, published-post IDs and URLs, and publication status.
  • Operational information, such as API responses, rate-limit status, error codes, retry history, timestamps, audit events, and the Keystone user who initiated or approved an action.
  • Performance information, such as post or account insights, only if Keystone offers an insights feature, you enable it, and you separately grant the required permission.

Keystone does not access personal Instagram consumer accounts through Meta's publishing API. Keystone does not access direct messages, comments, advertising accounts, contacts, or unrelated account data unless we introduce a clearly identified feature, request the corresponding permission, and update the applicable disclosures.

3. How We Use Connected-Account Information

We use connected-account information to:

  • authenticate the connection and show the accounts you are authorized to manage;
  • let you select a publishing destination;
  • create, schedule, publish, and confirm content that you direct Keystone to publish;
  • display publishing history, status, errors, and, when enabled, performance information;
  • maintain connection security, prevent unauthorized use, enforce rate limits, and troubleshoot failures;
  • provide customer support and maintain an audit trail of authorized publishing actions;
  • comply with law, enforce our agreements, and protect Keystone, our customers, providers, and other people; and
  • produce aggregated or de-identified service analytics that do not identify a connected account or individual.

We do not sell connected-account information. We do not use connected-account information for cross-context behavioral advertising. We do not use private connected-account information or unpublished content to train generally available artificial-intelligence models without a separate, affirmative opt-in.

4. Your Instructions and Publishing Control

Keystone publishes only to an account you select and authorize. A post may be published immediately when you approve it or automatically at a time you schedule. You are responsible for reviewing content, confirming that you have authority to publish it, and complying with the provider's terms, intellectual-property rules, advertising disclosures, and applicable law.

Disconnecting an account stops new publishing through that connection. It does not remove posts already published on the provider. You must delete or edit published posts using the provider's tools unless Keystone offers a supported removal control for that post.

5. How We Share Information

We disclose connected-account information only as needed to provide and protect the integration:

  • The connected provider, such as Meta, receives content, account identifiers, and publishing instructions when Keystone calls its APIs at your direction. The provider handles that information under its own terms and privacy policy.
  • Service providers may process limited information for hosting, storage, job scheduling, security, monitoring, customer support, and similar operational purposes under contractual confidentiality and data-protection obligations.
  • Your authorized workspace members may see connection status, publishing destinations, drafts, schedules, published results, and related activity according to their Keystone permissions.
  • Authorities, professional advisers, and transaction counterparties may receive information when required by law or reasonably necessary to protect rights, address security or fraud, or complete a corporate transaction subject to appropriate safeguards.
  • We may disclose information with your consent or at your direction.

6. Security

We use safeguards appropriate to the nature of connected-account information. These include encrypted transport, encryption at rest where supported, access controls, secret-management systems, environment separation, logging, and limits on employee and contractor access. Access tokens are treated as credentials and are not intentionally exposed in customer-facing pages, analytics payloads, support messages, or application logs.

No service can guarantee absolute security. Notify security@keystonelistings.com promptly if you believe a connection or token has been used without authorization.

7. Retention

  • Access tokens and connection records are retained while the connection is active. When you disconnect an account, revoke Keystone through the provider, close your Keystone account, or the token becomes permanently invalid, we disable the connection and delete or render unusable active credentials within a commercially reasonable period.
  • Drafts and scheduled content are retained until published, deleted, or no longer needed to provide the feature. You may delete drafts and cancel scheduled posts before publication through available product controls.
  • Publishing history and operational logs may be retained for up to 90 days for security, troubleshooting, support, and audit purposes, then deleted or de-identified, unless a longer period is necessary for an active investigation or legal obligation.
  • Backups may retain residual copies for up to 90 additional days before routine overwrite, subject to restricted access and disaster-recovery use only.
  • Legal, fraud-prevention, and billing records may be retained longer where reasonably necessary or required by law. These records do not authorize continued publishing.

8. Your Choices and Rights

You may:

  • decline to connect an account;
  • review the permissions requested on the provider's consent screen;
  • disconnect a connected account from Keystone when a disconnect control is available;
  • revoke Keystone directly in the provider's account or business-integration settings;
  • delete drafts or cancel scheduled content before publication;
  • request access, correction, export, or deletion of connected-account information; and
  • close your Keystone account by following our Account and Data Deletion instructions.

Revoking a provider connection may take a short time to propagate to in-flight publishing jobs. Keystone will not intentionally begin new publishing after it receives and processes the revocation.

9. Account and Data Deletion

For step-by-step instructions, visit https://keystonelistings.com/account-data-deletion. You may also e-mail privacy@keystonelistings.com from an address associated with your account with the subject "Account deletion request." We verify requests to protect accounts from unauthorized deletion.

After a verified account-deletion request, Keystone disables active connected-account credentials, cancels unpublished scheduled content where technically possible, unpublishes customer-controlled Keystone pages unless they must be transferred to another authorized workspace owner, and deletes or de-identifies personal information according to the deletion page, this policy, and applicable law.

10. Provider Terms and Changes

Third-party integrations depend on provider APIs, permissions, review requirements, rate limits, and policies. Providers may change or discontinue functionality. Keystone may update or suspend an integration to remain secure and compliant.

Meta's handling of information is governed by Meta's own terms and privacy policy. Connecting an account does not make Keystone the owner or administrator of the underlying Instagram account or Facebook Page.

11. Changes to This Policy

We may update this policy as integrations or legal requirements change. If a change materially affects how we use connected-account information, we will provide notice as required by law. The Last Updated date above identifies the current version.

12. Contact

Keystone Listings, c/o Trusty Goat, Inc. 8 The Green Ste B, Dover, DE 19901

Privacy: privacy@keystonelistings.com Security: security@keystonelistings.com General: hello@keystonelistings.com