Security & data

Connected the official way. Revocable at any time.

Creonnect is a Meta Tech Provider. Instagram data is read through Meta’s Graph API under a reviewed app — this page explains exactly which permissions we request, what we do with them, and how to revoke or delete.

Meta Tech Provider

Permissions

What we request, and why.

As a Meta Tech Provider, these are the Instagram API permissions Creonnect asks for. What each actually returns stays controlled by Meta, your account type, and the permissions you grant.

Meta permissionPurpose in Creonnect
instagram_business_basicConnect and identify an Instagram professional account, and display its profile and media across connected profiles and media kits.
instagram_business_manage_insightsRetrieve account and media insights to present analytics to the account holder and authorised workspace users.
instagram_business_manage_commentsRead, display, reply to, hide, or delete comments where supported, and run the comment-triggered responses you configure.
instagram_business_manage_messagesReceive and display conversations for the connected account and send the replies or automations you configure, within Meta's messaging rules.

Boundaries

What Creonnect never does.

These are commitments in the published privacy policy, not marketing language.

  • Ask for or store your Instagram password
  • Sell Meta Platform Data
  • Use Meta Platform Data for off-platform advertising
  • Build advertising profiles of the people who comment or message you
  • Use your data for surveillance or eligibility decisions
  • Access unrelated private accounts

Controls

How the platform is protected.

Administrative, technical, and organisational measures appropriate to the information and the risk.

Encryption in transit

Traffic between you, Creonnect, and Meta is encrypted in transit.

Restricted production access

Access to production systems is limited to the systems and people that need it, with logging and monitoring in place.

Credentials treated as sensitive

Access tokens are handled as sensitive material with access limited on the same basis.

Incident response

Documented procedures to investigate, contain, and remediate — and to notify affected people or authorities where the law requires it.

Provider due diligence

Sub-processors are reviewed before they handle personal information.

Backups

Backup procedures appropriate to the nature of the information and the risk.

No storage or transmission method is completely secure. Keep your credentials confidential, limit team access, and email hello@creonnect.com if you suspect unauthorised activity.

Your controls

Disconnecting and deleting.

Disconnecting Instagram and deleting your Creonnect account are separate actions. You can do either or both.

  1. 1

    Disconnect Instagram

    Immediate

    Disconnect from Creonnect, and optionally revoke at source via Instagram → Settings and privacy → Apps and websites. New syncing and Auto DM processing stop immediately, and tokens under our control are revoked immediately.

  2. 2

    Delete your account

    Within 30 days

    Use the in-product option where available, or email hello@creonnect.com from your registered address with the subject 'Data Deletion Request'.

  3. 3

    Remove a waitlist entry

    Within 30 days

    Email from the address you signed up with and ask us to remove it. Marketing can be stopped without deleting an active early-access request.