This page is about Hybrid Workspace (team.hybridcod.com) and its social scheduler — the feature that connects a Facebook Page or an Instagram business account so posts can be scheduled from your own content library.
It does not cover the Hybrid COD & Checkout Form Shopify app, which never touches Facebook or Instagram at all. For order and shopper data, see our Privacy Policy and GDPR page.
The fastest route: disconnect it yourself
- Sign in to team.hybridcod.com/settings.
- Find the account under Social accounts.
- Click Disconnect and confirm.
That is the whole process. It happens immediately, and it needs no request, no form and no waiting period. Only someone who manages the project can do it, which is the same person who connected the account in the first place.
What we hold while an account is connected
Deliberately little. The whole of it:
| What | Why we have it |
|---|---|
| The Page or Instagram account's numeric ID, name and profile picture URL | So the account can be named and recognised in a list of several |
| An access token, and a long-lived user token used to re-derive it | The only way to publish on your behalf. Both are encrypted at rest with AES-256-GCM; neither is ever shown in the interface, returned by our API or written to a log |
| The permissions you granted | So the app can say plainly when a missing permission is why something did not work |
| Which of your own images are scheduled, to which account, and for when | That is the schedule itself |
| For posts we published: the post's ID and public link, and a record of each publishing attempt | So a failure can be explained rather than just reported |
| Five numbers per published post — reach (where Meta provides it), likes, comments, shares, saves — and repeated readings of those same numbers over time | The analytics table and its curves. Counts only, never who |
What we never hold
We never copy or keep:
- Your posts, photos or videos from Facebook or Instagram — the only images involved are the ones you uploaded to Hybrid yourself
- The text of comments, replies or direct messages. We ask permission to count the comments on posts we published, and the number is all we keep
- Follower lists, or any information about the individual people who see, like or comment on a post
- Your Facebook profile beyond your name and the Pages you administer, which is what the sign-in returns
- Anything at all from a Page or account you did not explicitly select when connecting
The engagement figures above are aggregate counts handed to us by Meta. They identify nobody, and we have no route to the people behind them.
What disconnecting deletes
Three things happen, in this order, and all of them immediately:
- We ask Meta to withdraw the permission you granted. This comes first, so ordinarily there is no window in which we still hold a usable token. The permission belongs to the Facebook sign-in rather than to one account, so if another account you connected still uses the same sign-in, we leave it in place and that account keeps working; it is withdrawn when the last one is disconnected. If Meta cannot be reached at that moment the disconnect still goes ahead and steps 2 and 3 still happen; you can also withdraw it yourself, below.
- The stored tokens are deleted — not disabled, not retained as expired: the rows are removed.
- Everything attached to that account goes with them — the account record, every scheduled post for it, every publishing log, every engagement figure and every stored reading of one. Nothing is kept in a disabled state and nothing is kept for analytics.
Your own images and captions are not deleted. They are your work, they came from your content library, and they were never Facebook or Instagram data. Anything that had been scheduled simply goes back to being unscheduled, ready to be scheduled again to a different account.
There is no soft-delete, no retention window and no archive copy for this data. Routine encrypted database backups are overwritten on their normal cycle and are not used to restore deleted connections.
Removing the app from Facebook's side
You can also revoke access from Facebook directly, at Settings & privacy → Business integrations, or from Instagram under Apps and websites.
Be aware of what that does and does not do. It stops us being able to publish — our token stops working the moment you revoke it, and the next scheduled post will fail rather than go out. But Facebook does not tell us you did it, so our record of the connection stays until something tries to use it. When that happens the account is marked as needing reconnection and the people who manage the project are emailed.
If you want the stored data gone as well as the access, disconnect inside Hybrid or write to us. Revoking at Facebook alone is a lock change, not a deletion.
Asking us to delete it for you
If you cannot sign in, no longer have access to the workspace, or would simply rather we did it, email us:
Data deletion requests
Tell us which Facebook Page or Instagram account, and the email address you signed in with. We may ask one question to confirm you control the account before deleting anything.
info.hybridcodform@gmail.com →We act on these within 30 days at the latest, which is the maximum the GDPR allows, and in practice far sooner. You will get written confirmation when it is done. There is no charge.
Who you are dealing with
Hybrid is operated as a sole trader by Benjámin Márk, Hungary, 7562 Segesd, Dózsa tér 5. Data protection enquiries, including deletion requests, reach us at info.hybridcodform@gmail.com.
Related
Privacy Policy · GDPR & data protection · Terms of Service · Contact