Last updated: 18 July 2026
This policy explains what data Knversion Command Center collects, why we collect it, how it is stored and protected, who it is shared with, and how you can access or delete it.
Knversion Command Center ("the Service", "we", "us", "our") is a client-services automation platform operated by Kuba Redzisz ("the operator"). The Service is hosted at https://knverisoncmdcenter.netlify.app.
Knversion Command Center is used by an agency to manage Instagram messaging and engagement on behalf of its clients. It is multi-tenant: the agency connects multiple client accounts, and each client's data is logically isolated so that one client cannot access another client's data.
For data collected through a connected Instagram account, the agency's client (the account owner) is the data controller and Knversion Command Center acts as a processor on their behalf. For operation of the platform itself, the operator is the controller. If you are an end user (for example, someone who sent a direct message or comment to a connected account) and want to exercise your rights, you may contact us directly using the details in Section 11.
When a client connects their Instagram Business or Creator account, the Service can:
We connect to Instagram using Instagram Login (OAuth) with the Instagram API. You authorize the connection on Instagram, and we receive an access token that is limited to the specific permissions you grant. We never see or store your Instagram password. The permissions requested and exactly what each one is used to access are:
| Permission | What it accesses and why |
|---|---|
instagram_business_basic |
Reads the connected account's ID, username, and basic profile so we can identify which account is connected and route data to the correct client. |
instagram_business_manage_messages |
Reads incoming DMs and sends DMs on the connected account, so conversations appear in the inbox and configured auto-replies and comment-to-DM flows can run. |
instagram_business_manage_comments |
Reads comments on the connected account's media and posts replies, so the client can respond to comments and trigger comment-to-DM automations. |
instagram_business_content_publish |
Granted as part of the messaging use case. Allows publishing content to the connected account where a client explicitly requests it. We do not publish on your behalf unless you direct us to. |
instagram_business_manage_insights |
Reads aggregate engagement metrics for the connected account so we can display basic performance information in the dashboard. |
We request only the permissions needed to provide the features above and use the data obtained through them solely for those purposes. We do not sell this data, and we do not use it for advertising targeting or to build profiles unrelated to the connected account's own messaging and engagement.
The Service can optionally connect a user's Google account using Google Sign-In (OAuth). You authorize the connection on Google's own consent screen, and we receive an access token limited to the specific permissions you grant. We never see or store your Google password. Google user data is used only as described here:
If you connect your calendar, your public booking page (e.g. /b/<your-name>)
uses calendar.readonly solely to perform free/busy availability lookups, so
visitors are only offered times when you are actually free — we read busy/free time
intervals only, never the titles, descriptions, attendees, or contents of your existing
events. When a visitor books, calendar.events is used solely to create that
one meeting on your calendar with the visitor as an attendee, so Google Calendar sends the
invitation, reminders, and Google Meet link. Availability data is computed transiently and
is not stored; the details a visitor submits when booking (name, email, and their answers to
your booking questions) are stored in your own workspace and included in the calendar event
we create for you.
If a Drive connection is made, drive.readonly is used solely to list and import media files (photos and videos) from the single Drive folder you choose into your own media library inside the Service. We do not access files outside the folder you point us at, and we do not modify or delete anything in your Drive.
Google OAuth tokens are stored securely on our infrastructure (Netlify Blobs), are never exposed to a browser, and are deleted when you disconnect. You can disconnect at any time from your dashboard, or revoke the Service's access at myaccount.google.com/permissions.
Knversion Command Center's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is never sold, never used for advertising, and never used to train AI or machine-learning models.
Through a connected account and your use of the Service, we collect and store:
We do not intentionally collect special-category personal data (such as health, religious, or political information). Please do not send such information through the connected account.
Our legal bases are the performance of our contract with each client, the legitimate interests of the client and the operator in running and securing the platform, and, where required, consent (for example, when an end user voluntarily submits their details).
Application data is stored on Netlify Blobs, the managed storage provided by our hosting platform, Netlify. The Service runs as serverless functions on Netlify. Access tokens and stored content are kept per tenant and isolated by tenant so that one client's data is not accessible to another.
No method of transmission or storage is perfectly secure, but we take reasonable measures to protect data and limit access to what is necessary to run the Service.
We do not sell personal data. We share data only with the service providers needed to operate Knversion Command Center, and only for the purposes below:
The source of the connected account data. We exchange data with Instagram's API to read messages, comments, and metrics, and to send replies. Your use of Instagram is also governed by Meta's own policies.
When a Google account is connected, we exchange data with Google's Calendar API (free/busy lookups, creating booked events) and, for administrator connections, the Drive API (importing media from a chosen folder) — as described in Section 4. Your use of Google services is also governed by Google's own policies.
Our hosting and storage provider. The Service runs on Netlify Functions and data is stored on Netlify Blobs.
Provides the AI features of the inbox. Conversation content may be sent to the Anthropic (Claude) API to generate summaries and suggested draft replies. This content is processed to return a response to us and is not used by us to train models.
We may also disclose data if required to do so by law, or to protect the rights, safety, and security of our users or the Service.
We keep connection data, messages, comments, contact records, conversation history, and metrics for as long as the relevant account remains connected and the data is needed to provide the Service. When an account is disconnected, or when a deletion request is received, the associated data is deleted as described in Section 10. We may retain limited information where necessary to comply with legal obligations or to resolve disputes.
Depending on your location, you may have the right to:
To exercise any of these rights, contact us at kubaredzisz1@gmail.com. You can also disconnect Knversion Command Center at any time from your Instagram settings, which revokes our access.
There are three ways your data can be deleted:
/auth/instagram/deauth, and we stop processing and remove the associated
connection data.
/auth/instagram/delete,
which begins deletion of the data associated with that account and returns a confirmation.
Once deletion is processed, we remove the stored access token, messages, comments, contact records, and conversation history associated with the account, except for any limited information we are legally required to keep.
The Service is intended for businesses and is not directed to children. We do not knowingly collect personal data from anyone under the age required to hold an Instagram account in their jurisdiction. If you believe a child's data has been collected, contact us and we will delete it.
Our service providers may process and store data in countries other than your own. Where data is transferred internationally, we rely on our providers' safeguards and applicable legal transfer mechanisms to protect it.
We may update this policy from time to time. When we do, we will revise the "Last updated" date above. Material changes will be reflected on this page, and continued use of the Service after an update constitutes acceptance of the revised policy.
For any privacy question, request, or concern, contact:
Knversion Command Center
Operator: Kuba Redzisz
Email: kubaredzisz1@gmail.com
Service: https://knverisoncmdcenter.netlify.app