Privacy Policy

Last updated: 18 July 2026

This policy explains what data Knversion Command Center collects, why we collect it, how it is stored and protected, who it is shared with, and how you can access or delete it.

1. Who we are

Knversion Command Center ("the Service", "we", "us", "our") is a client-services automation platform operated by Kuba Redzisz ("the operator"). The Service is hosted at https://knverisoncmdcenter.netlify.app.

Knversion Command Center is used by an agency to manage Instagram messaging and engagement on behalf of its clients. It is multi-tenant: the agency connects multiple client accounts, and each client's data is logically isolated so that one client cannot access another client's data.

For data collected through a connected Instagram account, the agency's client (the account owner) is the data controller and Knversion Command Center acts as a processor on their behalf. For operation of the platform itself, the operator is the controller. If you are an end user (for example, someone who sent a direct message or comment to a connected account) and want to exercise your rights, you may contact us directly using the details in Section 11.

2. What Knversion Command Center does

When a client connects their Instagram Business or Creator account, the Service can:

3. Connecting Instagram & the permissions we use

We connect to Instagram using Instagram Login (OAuth) with the Instagram API. You authorize the connection on Instagram, and we receive an access token that is limited to the specific permissions you grant. We never see or store your Instagram password. The permissions requested and exactly what each one is used to access are:

PermissionWhat it accesses and why
instagram_business_basic Reads the connected account's ID, username, and basic profile so we can identify which account is connected and route data to the correct client.
instagram_business_manage_messages Reads incoming DMs and sends DMs on the connected account, so conversations appear in the inbox and configured auto-replies and comment-to-DM flows can run.
instagram_business_manage_comments Reads comments on the connected account's media and posts replies, so the client can respond to comments and trigger comment-to-DM automations.
instagram_business_content_publish Granted as part of the messaging use case. Allows publishing content to the connected account where a client explicitly requests it. We do not publish on your behalf unless you direct us to.
instagram_business_manage_insights Reads aggregate engagement metrics for the connected account so we can display basic performance information in the dashboard.

We request only the permissions needed to provide the features above and use the data obtained through them solely for those purposes. We do not sell this data, and we do not use it for advertising targeting or to build profiles unrelated to the connected account's own messaging and engagement.

4. Connecting Google — Calendar & Drive

The Service can optionally connect a user's Google account using Google Sign-In (OAuth). You authorize the connection on Google's own consent screen, and we receive an access token limited to the specific permissions you grant. We never see or store your Google password. Google user data is used only as described here:

Google Calendar — booking pages

If you connect your calendar, your public booking page (e.g. /b/<your-name>) uses calendar.readonly solely to perform free/busy availability lookups, so visitors are only offered times when you are actually free — we read busy/free time intervals only, never the titles, descriptions, attendees, or contents of your existing events. When a visitor books, calendar.events is used solely to create that one meeting on your calendar with the visitor as an attendee, so Google Calendar sends the invitation, reminders, and Google Meet link. Availability data is computed transiently and is not stored; the details a visitor submits when booking (name, email, and their answers to your booking questions) are stored in your own workspace and included in the calendar event we create for you.

Google Drive — media library sync (optional, administrator connection)

If a Drive connection is made, drive.readonly is used solely to list and import media files (photos and videos) from the single Drive folder you choose into your own media library inside the Service. We do not access files outside the folder you point us at, and we do not modify or delete anything in your Drive.

Google OAuth tokens are stored securely on our infrastructure (Netlify Blobs), are never exposed to a browser, and are deleted when you disconnect. You can disconnect at any time from your dashboard, or revoke the Service's access at myaccount.google.com/permissions.

Knversion Command Center's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is never sold, never used for advertising, and never used to train AI or machine-learning models.

5. What data we collect

Through a connected account and your use of the Service, we collect and store:

We do not intentionally collect special-category personal data (such as health, religious, or political information). Please do not send such information through the connected account.

6. Why we use it (legal basis)

Our legal bases are the performance of our contract with each client, the legitimate interests of the client and the operator in running and securing the platform, and, where required, consent (for example, when an end user voluntarily submits their details).

7. How data is stored and secured

Application data is stored on Netlify Blobs, the managed storage provided by our hosting platform, Netlify. The Service runs as serverless functions on Netlify. Access tokens and stored content are kept per tenant and isolated by tenant so that one client's data is not accessible to another.

No method of transmission or storage is perfectly secure, but we take reasonable measures to protect data and limit access to what is necessary to run the Service.

8. Third parties we share data with

We do not sell personal data. We share data only with the service providers needed to operate Knversion Command Center, and only for the purposes below:

Meta / Instagram

The source of the connected account data. We exchange data with Instagram's API to read messages, comments, and metrics, and to send replies. Your use of Instagram is also governed by Meta's own policies.

Google

When a Google account is connected, we exchange data with Google's Calendar API (free/busy lookups, creating booked events) and, for administrator connections, the Drive API (importing media from a chosen folder) — as described in Section 4. Your use of Google services is also governed by Google's own policies.

Netlify

Our hosting and storage provider. The Service runs on Netlify Functions and data is stored on Netlify Blobs.

Anthropic

Provides the AI features of the inbox. Conversation content may be sent to the Anthropic (Claude) API to generate summaries and suggested draft replies. This content is processed to return a response to us and is not used by us to train models.

We may also disclose data if required to do so by law, or to protect the rights, safety, and security of our users or the Service.

9. Data retention

We keep connection data, messages, comments, contact records, conversation history, and metrics for as long as the relevant account remains connected and the data is needed to provide the Service. When an account is disconnected, or when a deletion request is received, the associated data is deleted as described in Section 10. We may retain limited information where necessary to comply with legal obligations or to resolve disputes.

10. Your rights

Depending on your location, you may have the right to:

To exercise any of these rights, contact us at kubaredzisz1@gmail.com. You can also disconnect Knversion Command Center at any time from your Instagram settings, which revokes our access.

11. How to delete your data

There are three ways your data can be deleted:

Once deletion is processed, we remove the stored access token, messages, comments, contact records, and conversation history associated with the account, except for any limited information we are legally required to keep.

12. Children

The Service is intended for businesses and is not directed to children. We do not knowingly collect personal data from anyone under the age required to hold an Instagram account in their jurisdiction. If you believe a child's data has been collected, contact us and we will delete it.

13. International transfers

Our service providers may process and store data in countries other than your own. Where data is transferred internationally, we rely on our providers' safeguards and applicable legal transfer mechanisms to protect it.

14. Changes to this policy

We may update this policy from time to time. When we do, we will revise the "Last updated" date above. Material changes will be reflected on this page, and continued use of the Service after an update constitutes acceptance of the revised policy.

15. Contact us

For any privacy question, request, or concern, contact:

Knversion Command Center

Operator: Kuba Redzisz
Email: kubaredzisz1@gmail.com
Service: https://knverisoncmdcenter.netlify.app