THE Y
SEOUL

THE-Y SOCIAL SUPPORT

Platform connection and review guide

Permissions requested by THE-Y

THE-Y requests only the minimum permissions needed for features that are approved and active. Before each connection it shows the channel, feature, purpose, and requested scopes; a future capability is not requested merely because it is planned.

Supported scope

Current availability is shown per platform and depends on provider review status and channel type. Comment, message, automation, and analytics controls stay unavailable unless their exact capability has been approved and exposed in THE-Y.

Security and deletion

Platform tokens are encrypted and stored only in THE-Y, never sent to THE-Y related services. THE-Y handles disconnect and account-deletion requests; inbox content is retained for 90 days by default.

YouTube data and uploads

THE-Y identifies YouTube API data as YouTube data and makes channel-level data available only to the channel owner or their authorized representative. It does not combine YouTube data with other sources to create replacement metrics. Before an upload, you choose the exact title, description, and visibility, then certify compliance with the YouTube Community Guidelines. THE-Y revalidates or refreshes retained YouTube API data and authorization at least every 30 days. If you request deletion or continuing authorization cannot be verified, THE-Y stops access immediately and deletes the related YouTube API data within 7 days.

PUBLIC REVIEW DISCLOSURE

Platform scopes and current limitations

These are the smallest scope groups THE-Y is designed to request for the documented features. A scope is not requested and a feature is not exposed until the matching platform review, credentials, and THE-Y capability evidence are all approved.

Instagram

Review and credentials in preparation

Scope group

  • instagram_business_basic
  • instagram_business_content_publish
  • instagram_business_manage_comments
  • instagram_business_manage_messages
  • instagram_business_manage_insights

Current limitation

  • This provider is not available yet. The listed scope and capability information is public review documentation, not an enabled feature.
  • Only Instagram Business or Creator accounts can connect.
  • Instagram Stories, if approved, are limited to eligible Business accounts.
  • THE-Y does not send unsolicited or cold messages. Any future approved reply is limited to the platform's permitted conversation window.
  • Replies are permitted only while the platform's applicable inbound conversation window is open.
  • Instagram private comment replies are restricted by the platform's recipient and time-window policy.
Provider privacy policy

Facebook

Review and credentials in preparation

Scope group

  • pages_show_list
  • pages_read_engagement
  • pages_read_user_content
  • pages_manage_posts
  • pages_manage_engagement
  • pages_manage_metadata
  • pages_messaging
  • read_insights

Current limitation

  • This provider is not available yet. The listed scope and capability information is public review documentation, not an enabled feature.
  • Only Facebook Pages are supported; personal profiles and groups are excluded.
  • THE-Y does not send unsolicited or cold messages. Any future approved reply is limited to the platform's permitted conversation window.
  • Replies are permitted only while the platform's applicable inbound conversation window is open.
Provider privacy policy

YouTube

Review and credentials in preparation

Scope group

  • https://www.googleapis.com/auth/youtube.readonly
  • https://www.googleapis.com/auth/youtube.upload
  • https://www.googleapis.com/auth/youtube.force-ssl

Current limitation

  • This provider is not available yet. The listed scope and capability information is public review documentation, not an enabled feature.
  • This platform does not provide a THE-Y direct-message feature.
  • Before Google verification, YouTube uploads may be restricted to private visibility.
  • Any approved YouTube comment synchronization uses polling rather than a real-time webhook.
  • YouTube API data is refreshed or deleted within the applicable 30-day policy period.
Provider privacy policy

TikTok

Review and credentials in preparation

Scope group

  • user.info.basic
  • user.info.stats
  • video.list
  • video.upload
  • video.publish

Current limitation

  • This provider is not available yet. The listed scope and capability information is public review documentation, not an enabled feature.
  • TikTok's commercial API does not provide comment or direct-message management in THE-Y.
  • TikTok Direct Post, if approved, requires a fresh creator check and final user confirmation for every post.
  • TikTok visibility has no default: the creator must choose one of the current allowed options.
  • TikTok comments, Duet, and Stitch stay off unless the creator explicitly enables an allowed option.
  • Before TikTok audit approval, any Direct Post capability is restricted to the creator's private/self-only visibility.
Provider privacy policy

X

Review and credentials in preparation

Scope group

  • tweet.read
  • users.read
  • offline.access
  • tweet.write
  • media.write
  • tweet.moderate.write
  • dm.read
  • dm.write

Current limitation

  • This provider is not available yet. The listed scope and capability information is public review documentation, not an enabled feature.
  • X access can incur usage-based provider cost; THE-Y uses delayed polling rather than guaranteeing real-time synchronization.
  • THE-Y does not send unsolicited or cold messages. Any future approved reply is limited to the platform's permitted conversation window.
  • X media publishing is shown only when the current app contract and approved media-upload route support it.
Provider privacy policy

Threads

Review and credentials in preparation

Scope group

  • threads_basic
  • threads_content_publish
  • threads_read_replies
  • threads_manage_replies
  • threads_manage_insights
  • threads_delete
  • threads_manage_mentions

Current limitation

  • This provider is not available yet. The listed scope and capability information is public review documentation, not an enabled feature.
  • This platform does not provide a THE-Y direct-message feature.
  • Any approved Threads reply or mention synchronization uses polling rather than a confirmed real-time webhook.
Provider privacy policy

Support and review contact

Contact THE-Y Support about channel connections, permissions, data deletion, or platform review. Do not include OAuth credentials or platform tokens in email.

Contact THE-Y Support
View social channel status