This is a summary of Meta's published documents as read on 8 October 2026, not legal advice; the originals decide.
A scheduling tool may publish what a person wrote, to accounts that person connected, through Meta's official APIs and with the permissions the person granted. That is the shape every document below points to. What controls it is technical and contractual: permissions an app must request, App Review before strangers can use those permissions, Business Verification for the higher access level, and an annual checkup. Nothing in the documents read for this page names scheduling as a forbidden use. What they do forbid is covered further down, and so is what they leave unsaid.
Who the rules apply to
Three layers apply at once, and mixing them up is the usual source of fear.
- The app and its developer. The Meta Platform Terms and the Meta Developer Policies bind whoever builds or runs an app on Meta's developer platform. The Platform Terms show "Last updated February 3, 2026" at the time of reading, and they require compliance with the applicable requirements in the Developer Policies, which makes the Policies part of what binds an app.
- The account. The Instagram Terms of Use, the Facebook terms and the Community Standards govern what an account holder does. These are the rules behind an account being limited or removed.
- The technical layer. API permissions, access levels, rate limits and review decide what a request can do in practice, whatever the contracts say.
The distinction matters for this question: a scheduler is an app, so the first and third layers bind the tool, while the second binds you. The Platform Terms say Meta may suspend or remove apps and accounts that break the terms, at any time and with or without notice, so the two can overlap in an enforcement action. They are still different rulebooks.
What an app may do with the publishing API
The table lists only what the documents read for this page cover.
| Action | Allowed under the documents | Needs | Notes |
|---|---|---|---|
| Publish an image, video, Reel, Story or carousel | Yes, through the content publishing API | Instagram professional account; publish permission | Media must sit on a public URL when Meta fetches it. A carousel holds up to 10 items |
| Schedule a post in the tool | The guide describes no scheduling parameter | Own queue in the tool | It tells apps with scheduling to enforce the daily limit themselves |
| Stay inside the daily cap | Required in practice | Check the publishing-limit endpoint | One section says 100 API-published posts per 24 hours, another says 50; the guide contradicts itself |
| Read post and account insights | Yes | Insights permission | Account metrics are stored up to 90 days; some are missing under 100 followers |
| Read, reply to, hide or delete comments on your own media | Yes, as API features | Comment-management permission | A tool must not do this on its own initiative; see the section on automation |
| Publish to a Facebook Page | Yes, through the Pages API | Page access token; post-management permission, which needs App Review | The overview page did not document scheduling parameters |
| Edit or delete a published Instagram post | Not covered by the guide read | Unknown | Do not assume either way |
Each permission has a name that differs between the Instagram Login and Facebook Login configurations. Instagram publishing uses a content-publish permission in both, plus a basic one, and the Facebook Login path adds a Page-reading permission. The detail, with the errors, is in the Instagram API publishing guide, and each network's own behaviour is on Instagram, Facebook and Threads.
Facebook Pages, per the Developer Policies, carry their own rule: do not create or claim Pages, or disclose their administrators, without consent. That is aimed at apps that manage Pages for others.
Review, verification and access levels
The Instagram Platform overview describes two access levels.
- Standard access is the default. It limits data and is meant for people with a role on the app. It is enough when the app serves only accounts its owner manages.
- Advanced access is needed to serve Instagram accounts the app owner does not manage. It requires App Review and Business Verification.
App Review is Meta's check that an app uses its permissions in an approved way. The App Review page says an app must pass it before anyone without a role on the app can use it. Permissions and features that are not approved work only for people with a role. If Meta cannot test the app at all, the whole submission is rejected; if it can test the app but not one permission, only that permission is denied.
Business Verification confirms that a business is a real entity. The page says apps asking for advanced access need it. Without it, users from other businesses cannot grant those permissions and the app's features stay inactive. An app administrator connects the app to a business in the App Dashboard, and a business administrator then completes verification in Business Manager.
Data Use Checkup is the third item. The page says app admins must complete it for apps that are live or hold advanced access, once a year, and that finishing it is a condition for keeping API access. Apps with standard access and apps in development mode do not need one, though the latter must complete it before going live.
What happens to an app that does not comply? The Platform Terms let Meta take action if it believes, at its sole discretion, that an app broke the terms or harmed users: suspend or remove apps or accounts, revoke access, require deletion of Platform Data. Meta may also remove an API, permission or feature that has gone unused for 28 days, and a material change in what an app does or what data it uses requires new review. Audits are at most yearly under normal conditions, with at least ten business days' notice, and enforcement may be automated.
Data: what an app must do with user data
The Platform Terms treat access tokens, app secrets and Meta user IDs as Platform Data, and they set duties around it.
- Tokens. Protect them; do not transfer, share or solicit them, except to a service provider that helps run the app. Do not collect people's Meta login credentials directly. Sign-in goes through Meta.
- Sharing. Allowed only for the listed reasons: law, service providers acting for the developer, or a user's express direction or consent. Service providers must agree in writing to process data only for the developer.
- Deletion. Delete or update data promptly when Meta or a user asks, and give people an easy way to ask. Delete it also when it is no longer needed or the product ends.
- Privacy policy. A public one, linked in the App Dashboard, explaining what is processed, why, and how people can request deletion.
- Deletion callback. The developer documentation says an app must offer a way to request deletion, and must set either a data deletion callback URL or a page of deletion instructions in its settings. The callback receives a signed request with the app-scoped user ID, must start the deletion, and returns a status URL and a confirmation code.
- Security. Safeguards that meet industry standards, a way to report vulnerabilities, and prompt reporting of incidents to Meta.
The Developer Policies page read for this summary does not itself cover deauthorization callbacks or token storage. Those sit in the Terms and in the developer documentation.
Automation, spam and what accounts can lose
Here the documents are less direct than the articles that rank for these searches. Two points keep the picture honest.
What the app-level documents say. The Developer Policies list, among conduct to avoid, creating bots at high frequency, inauthentic behaviour, spam, deceptive links and trading in likes, followers or similar engagement. They also ask for consent before an app acts on people's behalf. The Instagram Platform section restricts using the platform only to display content, back it up or manage relationships without permission. The Platform Terms contain no separate section on automated activity; the nearest are Meta's right to monitor and enforce automatically.
What they do not say. None of the documents read prohibits scheduling by name, and none gives an account-level ban threshold for scheduled posts. Rules on how accounts may behave, including fake engagement and automated actions, sit in the Instagram Terms of Use and the Community Standards. Those pages did not load in a readable form on 8 October 2026, so this page makes no claim about what they permit or forbid. Third-party articles that state exact limits or ban triggers are not citing the documents above.
What a scheduler should never do. The Developer Policies' bar on bots at high frequency, inauthentic behaviour and trading in engagement is the reason a responsible tool leaves out automatic likes, follows and comments. The Policies read here do not contain a rule that says "automatic likes" in those words, so the sensible wording is that these actions would sit under the inauthentic-behaviour and spam provisions, and that the account-level rules were not read. The comment API itself exists for replying, hiding and deleting comments on your own media; a person should trigger those.
What Preflight does about it
These points come from our code and privacy policy, and a review status the owner reported.
- Preflight posts only what you wrote and scheduled, to accounts you connected. It has no feature that likes, follows or comments by itself. A comment reply is sent only when you write and send it from the inbox.
- Access tokens are encrypted at rest with AES-256-GCM and never sent to your browser, according to the privacy policy.
- Disconnecting an account deletes its stored tokens immediately. You can also remove the app in Facebook or Instagram settings under Apps and websites, which stops publishing at once.
- The server has Meta deauthorize and data-deletion endpoints for Facebook, Instagram and Threads. They verify the signed request, remove the matching connected accounts and return a status page and confirmation code.
- Meta review was reported complete on 21 September 2026. After the move to the preflight.social domain, the owner reported on 22 September that updating the Meta consoles triggered no new review. Treat both as a status on those dates, not a guarantee, and check the current state with us if it matters to a decision.
Plan and pricing details are on pricing; the rest is in the documentation and the terms.
A checklist for choosing a scheduler
- Does it use the official API? A tool that asks for your Instagram password, or drives the app like a person, is outside the model the documents describe; the Terms bar collecting Meta login credentials directly.
- How are tokens stored? Ask whether they are encrypted and whether they ever reach a browser or a third party.
- How do you disconnect? There should be a button in the tool and a way to remove it from your Meta settings, and both should stop publishing.
- What happens to your data? Look for a public privacy policy, a stated deletion route and working deletion endpoints.
- What is its review status? Ask whether the app holds Advanced access for the permissions it needs, with a completed Business Verification and a current Data Use Checkup.
- Does it do anything on its own? Scraping, automatic likes, follows or comments, and fake engagement are what the Developer Policies point away from.
This is a summary of Meta's published documents as read on 8 October 2026, not legal advice; the originals decide. Sources opened: the Platform Terms, the Developer Policies, the Instagram Platform overview, content publishing and the data deletion callback. Read from the developer documentation but not linked here: App Review, Business Verification, Data Use Checkup, comment moderation, insights and the Pages API overview. Not read: the Instagram Terms of Use, the Community Standards.
Questions people ask
- Is it against Instagram's rules to use a scheduler?
- The documents read for this summary do not forbid scheduling. The publishing guide describes how an app posts through the official API and tells apps with scheduling to respect the daily limit. The Instagram Terms of Use and Community Standards did not load in a readable form, so what they say about scheduling is not covered here.
- Can Instagram ban an account for scheduled posts?
- The documents read do not say that scheduled posts lead to a ban, and they give no account-level threshold. They do say Meta may suspend or remove apps and accounts that break its terms, with or without notice. The account rules themselves were not read, so this cannot be answered more precisely from them.
- Does a scheduler need Meta's approval?
- Per Meta's App Review page, an app must pass review before people without a role on the app can use its permissions. The Instagram Platform overview adds that serving accounts the app owner does not manage needs Advanced access, which requires App Review and Business Verification. An app used only by its own team does not need review.
- What happens to my data if I disconnect a scheduler?
- Meta's documents require an app to delete data on request and to offer a deletion route, through a callback or a page of instructions. What happens in a given tool is set by its privacy policy. In Preflight, disconnecting deletes the stored tokens immediately, as the [privacy policy](/privacy) states.
- Is automating comments or likes allowed?
- The documents do not say in those words. The Developer Policies list high-frequency bots, inauthentic behaviour, spam and trading in engagement among things to avoid, and ask for consent before acting for people. The comment API lets an app reply to, hide or delete comments on your own media. Account-level rules on automated likes were not read.