Mosso Privacy Policy
Effective date: June 30, 2026 Last updated: July 15, 2026
1. Who we are
This Privacy Policy explains how we handle personal information when you message us on Instagram.
- Legal entity: Legion Trade Corp, operating as "Mosso Studio" (o/a Mosso Studio)
- Location: Toronto, Ontario, Canada
- Website: https://mosso.ca
- Instagram: @mosso.studio
- Contact email: hello@mosso.ca
In this policy, "we," "us," and "our" mean Legion Trade Corp o/a Mosso Studio. "You" means a person who sends a direct message (DM) to our Instagram account @mosso.studio.
We are the organization responsible for the personal information described here. We handle it in a manner consistent with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable Ontario privacy law.
2. What this policy covers
This policy covers the personal information we collect and use when you send a direct message to @mosso.studio on Instagram and our messaging assistant ("Mosso Publisher") responds.
Mosso Studio produces food and restaurant content. We run a self-hosted tool called Mosso Publisher that (a) publishes our own finished posts to @mosso.studio, and (b) answers direct messages that you start, with helpful information about our services (such as public pricing and how our service works). Sensitive topics — pricing negotiation, complaints, and contracts — are handed off to a human operator.
We only reply to messages you send first, and always within Instagram's standard 24-hour messaging window. We never send unsolicited or bulk messages.
This policy does not cover Instagram's own collection and use of your information. Instagram is operated by Meta and is governed by Meta's privacy policy. We recommend you review it: https://privacycenter.instagram.com/policy
Clients: connecting your social accounts for publishing
If you are a Mosso client and you ask us to publish content for you, you connect your own social accounts to Mosso through each platform's official, authorized login (its OAuth flow). This applies to Instagram, TikTok, Facebook, and Threads.
- What we receive and store when you connect an account: an access token (and, where the platform issues one, a refresh token) that lets us publish on your behalf; your account's basic public profile from the platform — for TikTok, the fields in the
user.info.basicscope: your open ID, display name, and avatar; and the identifiers we need to route posts to the right account. We store these securely and use them only to publish and schedule the content you have approved. - What we do with it: with the TikTok
video.upload/ Content Posting API scope, we upload the finished videos you approve to your TikTok account (as a draft for you to review and post, or as a direct post once you have authorized that). We do the equivalent through the official APIs of Instagram, Facebook, and Threads. - What we never do: we do not read your private messages, we do not scrape or export data from these platforms, we do not run engagement bots, and we do not post anything you have not approved.
- Disconnecting: you can revoke Mosso's access at any time from the platform's own settings (for TikTok, Settings → Security & permissions → Manage app permissions), or by emailing hello@mosso.ca. Revoking immediately ends our ability to post, and we delete the stored tokens for that account.
Your use of each connected platform remains governed by that platform's own terms and privacy policy — for example, TikTok's privacy policy at https://www.tiktok.com/legal/privacy-policy.
3. What we collect, and why
When you send a DM to @mosso.studio, our system receives and stores the following from Instagram's messaging platform:
- Instagram-scoped user ID (IGSID) — an app-specific identifier Instagram assigns to you for our account. It is not your username and cannot identify you outside our conversation. Why: to know which conversation a message belongs to and to send our reply back to you.
- Message content — the text of the message(s) you send us. Why: to understand your question and generate a relevant reply.
- Timestamps — when messages are sent and received. Why: to stay within Instagram’s 24-hour reply window and order the conversation correctly.
- Generated reply — the reply our assistant produces and sends back to you. Why: to keep a record of what we told you and provide context for follow-up messages.
We use this information only to:
- Reply to the messages you start, with information about Mosso Studio's services;
- Keep roughly the last 20 turns of our conversation so replies make sense in context;
- Maintain an internal operator review queue so a human can check and, where needed, take over the conversation (for example, for pricing negotiation, complaints, or contracts).
We do not use this information for advertising, profiling, or any purpose unrelated to answering your message.
Our replies are generated with the help of artificial intelligence. An AI assists in writing our replies, and a human operator can review and take over the conversation.
4. Legal basis / consent
Under PIPEDA, we rely on your consent. By starting a conversation with @mosso.studio and sending us a message, you consent to our collecting and using the information in Section 3 to respond to you, as described in this policy. You can withdraw consent at any time (see Sections 8 and 9).
5. Third-party processing (sub-processor): Google Gemini
To generate replies, we send the text of your message to Google's Gemini API, operated by Google. Gemini acts as our service provider (sub-processor) and returns suggested reply text, which our system then sends back to you.
- What is sent to Google: the text of your message and the conversation context needed to produce a sensible reply. We do not send Google your Instagram username or any payment information.
- Why: solely to generate the reply you receive.
- Google's terms: Google's handling of this data is governed by its terms and policies. See https://ai.google.dev/gemini-api/terms and https://policies.google.com/privacy
Google is the only third party to which message content is sent for processing. We do not send your information to any other third party for processing.
6. Where your data is stored, and how we protect it
- Storage location: Conversation records (your IGSID, message text, timestamps, and our generated replies) are stored in a local file (
conversations.json) on the operator's own computer, not on a public cloud database. The operator review queue holds only the most recent drafts (trimmed to the last 200). - Access token: The long-lived Instagram access token used to receive and send messages is stored locally on the same machine (
pages.json). - Security measures:
- Incoming message deliveries from Meta are cryptographically verified using an HMAC signature (
X-Hub-Signature-256) before we process them, so we can confirm a message genuinely came from Meta and was not tampered with. - Access is limited to the operator(s) who run the tool.
- Generated media we publish keeps its SynthID watermark intact, identifying it as AI-assisted.
- Incoming message deliveries from Meta are cryptographically verified using an HMAC signature (
No method of storage or transmission is perfectly secure, but we take reasonable steps to protect your information against loss, theft, and unauthorized access, use, or disclosure.
7. How long we keep your data (retention)
We keep conversation records no longer than 24 months, or until you ask us to delete them — whichever comes first. After that, the records are deleted.
We may keep a record for a shorter time at our discretion (for example, the review queue keeps only the most recent drafts).
8. We do not sell or share your data
We do not:
- Sell your personal information;
- Use it for advertising or to target ads;
- Share it with any third party, except Google Gemini for the sole purpose of generating your reply (Section 5), or where we are required to do so by law.
9. Your rights and choices
You have the right to:
- Access the personal information we hold about you;
- Correct information that is inaccurate;
- Withdraw consent and request deletion of your conversation data;
- Opt out of our automated replies at any time by replying STOP, or by blocking @mosso.studio on Instagram.
To exercise any of these rights, email hello@mosso.ca from or referencing the Instagram account you used to message us, so we can locate your records. We will respond within a reasonable time and as required by PIPEDA.
If you have a privacy concern we have not resolved, you may contact the Office of the Privacy Commissioner of Canada: https://www.priv.gc.ca
10. Deleting your data
You can have your data deleted in two ways:
- Email us: Send a request to hello@mosso.ca. We will delete your IGSID, message text, timestamps, and our generated replies from
conversations.json, and forget the related token data as applicable. See our Data Deletion page for details: https://mosso.ca/data-deletion - Through Meta: If you remove our app or request deletion through Instagram/Meta, Meta sends us a data deletion request. We honor these requests by deleting the corresponding conversation data from our records.
11. Children
Our services and our Instagram account are intended for restaurant owners and businesses, not for children. We do not knowingly collect personal information from anyone under the age required to hold an Instagram account in their jurisdiction.
12. Changes to this policy
We may update this policy from time to time. When we do, we will change the "Last updated" date above and post the new version at https://mosso.ca/privacy. Material changes take effect when posted.
13. Contact us
Questions, requests, or complaints about this policy or your information:
Legion Trade Corp o/a Mosso Studio Email: hello@mosso.ca Website: https://mosso.ca Instagram: @mosso.studio Toronto, Ontario, Canada