Connected the official way. Revocable at any time.
Creonnect is a Meta Tech Provider. Instagram data is read through Meta’s Graph API under a reviewed app — this page explains exactly which permissions we request, what we do with them, and how to revoke or delete.
Meta Tech Provider
Connected account
Official Meta API
Secure OAuth connection
Creonnect
Your workspace
Permissions
What we request, and why.
As a Meta Tech Provider, these are the Instagram API permissions Creonnect asks for. What each actually returns stays controlled by Meta, your account type, and the permissions you grant.
| Meta permission | Purpose in Creonnect |
|---|---|
instagram_business_basic | Connect and identify an Instagram professional account, and display its profile and media across connected profiles and media kits. |
instagram_business_manage_insights | Retrieve account and media insights to present analytics to the account holder and authorised workspace users. |
instagram_business_manage_comments | Read, display, reply to, hide, or delete comments where supported, and run the comment-triggered responses you configure. |
instagram_business_manage_messages | Receive and display conversations for the connected account and send the replies or automations you configure, within Meta's messaging rules. |
Boundaries
What Creonnect never does.
These are commitments in the published privacy policy, not marketing language.
- Ask for or store your Instagram password
- Sell Meta Platform Data
- Use Meta Platform Data for off-platform advertising
- Build advertising profiles of the people who comment or message you
- Use your data for surveillance or eligibility decisions
- Access unrelated private accounts
Controls
How the platform is protected.
Administrative, technical, and organisational measures appropriate to the information and the risk.
Encryption in transit
Traffic between you, Creonnect, and Meta is encrypted in transit.
Restricted production access
Access to production systems is limited to the systems and people that need it, with logging and monitoring in place.
Credentials treated as sensitive
Access tokens are handled as sensitive material with access limited on the same basis.
Incident response
Documented procedures to investigate, contain, and remediate — and to notify affected people or authorities where the law requires it.
Provider due diligence
Sub-processors are reviewed before they handle personal information.
Backups
Backup procedures appropriate to the nature of the information and the risk.
No storage or transmission method is completely secure. Keep your credentials confidential, limit team access, and email hello@creonnect.com if you suspect unauthorised activity.
Your controls
Disconnecting and deleting.
Disconnecting Instagram and deleting your Creonnect account are separate actions. You can do either or both.
- 1
Disconnect Instagram
ImmediateDisconnect from Creonnect, and optionally revoke at source via Instagram → Settings and privacy → Apps and websites. New syncing and Auto DM processing stop immediately, and tokens under our control are revoked immediately.
- 2
Delete your account
Within 30 daysUse the in-product option where available, or email hello@creonnect.com from your registered address with the subject 'Data Deletion Request'.
- 3
Remove a waitlist entry
Within 30 daysEmail from the address you signed up with and ask us to remove it. Marketing can be stopped without deleting an active early-access request.