개인정보처리방침
시행일: 2026년 9월 21일 · 서비스: Orion Pilot (orionpilot.app)
Orion Pilot은 비즈니스의 콘텐츠 작성·검토·일정 관리와 SNS 연결을 위한 서비스입니다. 이 방침은 서비스 이용 정보와 연결한 SNS에서 받은 정보를 어떻게 처리하는지 설명합니다. 개인정보 문의와 요청은 Orion Pilot 운영팀의 admin@bluecakefactory.com으로 보내 주세요.
1. 처리하는 정보와 목적
- 회원 이메일, 인증 식별자, 로그인 세션 및 작업공간 멤버십: 로그인, 접근 권한 확인과 작업공간 제공에 사용합니다. 비밀번호 인증은 Supabase Auth에서 처리합니다.
- 직접 입력한 브랜드 정보, 소재, 이미지, 초안, 검토 및 일정 정보: 콘텐츠를 만들고 저장하며 팀과 검토하는 데 사용합니다.
- SNS 연결에 동의한 경우 계정·페이지 식별자와 표시 이름, 허용한 권한, 토큰 및 만료·연결 상태: 선택한 SNS 계정을 연결하고 허용된 기능을 실행하는 데 사용합니다. SNS 비밀번호나 2단계 인증 코드는 Orion에 저장하지 않습니다.
- 요청·오류·접근 기록과 보안 관련 기술 정보: 장애 확인, 악용 방지와 서비스 운영에 사용합니다.
2. SNS 권한과 게시
Instagram 계정 기본 정보와 콘텐츠 게시, Facebook 페이지 조회와 게시, Threads 기본 정보와 게시에 필요한 권한만 요청합니다. 현재 연결 흐름은 메시지 읽기, 댓글 관리 또는 광고 관리 권한을 요청하지 않습니다. 사용자가 선택한 계정과 승인한 콘텐츠에 한해 게시 기능을 제공합니다. 서비스 화면의 일정 저장 자체가 실제 게시 완료를 의미하지는 않습니다.
3. 서비스 제공업체와 정보 전달
Cloudflare는 웹 서비스와 인프라, Supabase는 인증과 데이터 저장을 제공합니다. SNS 연결·게시 요청은 해당 기능을 제공하는 Meta의 Facebook·Instagram·Threads에 전달합니다. AI 작성 기능을 사용하는 경우 사용자가 입력한 소재의 제목·설명, 브랜드명·문체 지침과 요청 언어를 OpenAI에 전달할 수 있습니다. SNS 토큰과 연결 계정 정보는 AI 작성 요청에 포함하지 않습니다. 각 제공업체가 서비스를 운영하는 국가에서 정보가 처리될 수 있습니다. Orion은 SNS에서 받은 정보를 판매하거나 광고 타기팅에 사용하지 않습니다.
4. 보관과 보호
작업공간 정보는 서비스를 제공하는 동안 보관합니다. SNS 토큰은 서버에서 암호화하여 보관하고 브라우저의 공개 데이터에 포함하지 않습니다. 작업공간 접근 권한을 확인하여 정보를 제공합니다. 연결 해제 시 해당 연결의 저장 토큰을 삭제하고 대기 중인 관련 게시 작업을 취소합니다. 연결 해제만으로 계정 표시 정보, 콘텐츠와 모든 작업 기록이 삭제되지는 않습니다.
5. 열람·정정·삭제·권한 철회
서비스 화면에서 작업공간 정보를 수정하고 SNS 연결을 해제할 수 있습니다. SNS 데이터 또는 Orion 계정·작업공간의 삭제, 정보 열람과 정정을 원하시면 admin@bluecakefactory.com으로 요청해 주세요. 요청 대상과 소유 권한을 확인하며, 비밀번호·인증 코드·토큰을 요구하지 않습니다.
Meta가 서명한 데이터 삭제 요청을 보내면 해당 SNS의 계정 식별·표시 정보, 권한, 저장 토큰과 연결 인증 데이터를 제거합니다. 직접 작성한 콘텐츠와 내부 작업 기록, 삭제 확인 및 재처리 방지를 위한 최소 기록은 별도로 남을 수 있습니다. 자세한 범위와 절차는 데이터 삭제 안내에서 확인할 수 있습니다.
6. 변경과 문의
처리 방식이 바뀌면 이 페이지의 내용과 시행일을 갱신합니다. 문의: Orion Pilot 운영팀 · admin@bluecakefactory.com.
Privacy Policy
Effective September 21, 2026 · Orion Pilot (orionpilot.app)
Orion Pilot provides a workspace for creating, reviewing and planning business content and connecting social accounts. This policy describes our handling of service information and data received from connected social networks. Contact the Orion Pilot operations team at admin@bluecakefactory.com for privacy questions or requests.
1. Information and purposes
- Account email, authentication identifiers, sessions and workspace membership support sign-in and access control. Supabase Auth handles password authentication.
- Brand details, source material, images, drafts, reviews and schedules you provide support content creation, storage and collaboration.
- When you authorize a social connection, account or page identifiers, display names, granted permissions, tokens, expiry and connection status support the selected account and authorized features. Orion does not store your social network password or two-factor authentication codes.
- Request, error, access and security-related technical records support operations, troubleshooting and abuse prevention.
2. Social permissions and publishing
We request permissions for Instagram basic account information and content publishing, Facebook page selection and publishing, and Threads basic information and publishing. Our current connection flow does not request access to read messages, moderate comments or manage ads. Publishing features use the account and content you authorize. Saving a planned date does not itself confirm delivery to a social network.
3. Service providers and disclosures
Cloudflare provides web hosting and infrastructure, and Supabase provides authentication and data storage. Connection and publishing requests are sent to the relevant Meta service: Facebook, Instagram or Threads. When AI drafting is used, your material title and description, brand name, writing instructions and requested language may be sent to OpenAI. We do not include social tokens or connected account data in AI drafting requests. Providers may process information in the countries where they operate. Orion does not sell social platform data or use it for advertising targeting.
4. Retention and protection
We retain workspace information while providing the service. Social tokens are encrypted on the server and excluded from public browser data. Workspace access is checked before providing data. Disconnecting an account deletes its stored token and cancels related pending publishing jobs. Disconnection alone does not erase account display information, your content or all activity records.
5. Access, correction, deletion and withdrawal
You can edit workspace information and disconnect social accounts in Orion. To request access, correction or deletion of social data, your Orion account or workspace, email admin@bluecakefactory.com. We verify the scope of the request and your authority without asking for passwords, verification codes or access tokens.
On receiving a signed deletion request from Meta, we remove the affected social account identifiers and display details, permissions, stored tokens and connection authorization data. Content you created, internal activity records and minimal records for confirming deletion and preventing duplicate processing may remain separately. See our data deletion instructions for the scope and process.
6. Updates and contact
We update this page and its effective date when our handling changes. Contact: Orion Pilot operations team, admin@bluecakefactory.com.