How Closevine handles data
This policy explains how Leveromate collects, uses, shares, protects, and deletes personal data when providing Closevine.
- Effective
- 19 July 2026
- Last updated
- 19 July 2026
- Operator
- Leveromate
1. Who this policy covers
This policy applies to Closevine workspace users, people visiting our websites, and people whose Instagram comments or direct messages are processed for a business using Closevine.
The business that connected its Instagram professional account decides why and how it communicates with its customers. For that conversation data, the business is normally the data controller or equivalent decision-maker, and Leveromate processes data on its behalf. We act as the decision-maker for account administration, security, service operations, and our own legal obligations.
2. Data we collect
Workspace and account data
- Name, business email address, login method, and user identifier.
- Organisation name, website, industry, country, timezone, currency, membership, role, permissions, and subscription details.
- Security information such as session identifiers, OTP attempt records, approximate IP/device metadata, revocation events, and audit history.
Connected Instagram account and content data
- Professional account ID, username, profile image, permissions, token state, connection state, and webhook state.
- Posts and reels owned by the connected account, including media IDs, media type, captions, thumbnails, permalinks, publication time, and available metrics.
- Comments, direct messages, delivery/read events, public or API-available Instagram identifiers, usernames, and related source post information.
Conversation, customer-memory, and sales data
- Message text, language and script, intent, sentiment, moderation state, and conversation stage.
- Rolling summaries, preferences, interests, qualification fields, lead status, recommendations, tags, internal notes, and the source and confidence of stored facts.
- Approved action requests and results, tracked links, campaign and content attribution, conversion evidence, and transaction references.
Business knowledge and integration data
- Products, services, prices, policies, locations, FAQs, links, promotions, post-specific context, and documents uploaded by a workspace.
- Provider and integration configuration, encrypted credentials, allowlisted webhook definitions, and safe action results.
Service and usage data
- Webhook records, normalised events, request IDs, queue and delivery results, model/provider usage, token counts, cost, latency, validation outcomes, errors, and system health information.
- Essential session cookies and similar security technologies. We do not use Closevine customer conversations for third-party advertising.
3. How we receive data
We receive data when:
- a workspace user creates an account or configures Closevine;
- an Instagram professional account owner grants permissions through Instagram Login;
- Meta sends an authorised webhook or responds to an API request;
- an Instagram user comments, sends a message, or otherwise interacts with the connected business;
- a workspace uploads knowledge, connects a provider, or configures an action; or
- our systems create security, delivery, billing, and operational records.
4. Why we use data
We use data to:
- authenticate users and administer tenant-isolated workspaces;
- connect, maintain, and secure Instagram integrations;
- synchronise owned posts and reels and display available insights;
- receive comments and DMs, generate structured AI proposals, validate them, and send messages permitted by workspace policy;
- maintain conversation context and customer memory, with provenance and correction controls;
- execute explicitly configured actions and record verified conversion attribution;
- prevent fraud, abuse, duplicate sends, prompt injection, unauthorised access, and security incidents;
- provide support, measure service usage, improve reliability, and meet legal obligations.
Depending on the relationship and applicable law, these activities are based on performance of a contract, the workspace or customer's authorisation, legitimate interests in operating and securing the service, compliance with law, or consent where consent is required.
5. How AI processing works
Closevine uses separate comment and DM agents. It compiles relevant instructions, approved business knowledge, source-post context, conversation context, and the new customer message, then sends that controlled request to the model provider selected by the workspace.
The model returns structured JSON. It cannot directly call Meta, our database, or arbitrary business webhooks. Closevine validates the response, authoritative prices and products, safety policy, permissions, human-control state, and idempotency before a message or action can run. There are no open-ended autonomous tool loops.
Model providers process submitted data under their own terms and the workspace's provider arrangement. A workspace administrator chooses the active provider and should review that provider's data-use and retention terms before activation.
6. When we share data
We share only what is needed with:
- Meta and Instagram to authenticate accounts, receive events, fetch permitted data, and send approved messages;
- the AI provider selected by the workspace to generate structured proposals;
- infrastructure and service providers for hosting, database, storage, email delivery, authentication, monitoring, and security;
- integrations and action endpoints deliberately configured by the workspace;
- professional advisers, auditors, or authorities when legally required or necessary to protect rights and security; and
- a successor in a merger, financing, reorganisation, or sale, subject to appropriate safeguards and notice where required.
We do not sell Meta Platform Data or customer conversation data. We do not let one workspace access another workspace's customer memory.
7. Storage locations and international transfers
Closevine's primary production database and object storage are configured in India, and its current API and worker infrastructure is hosted in India. Some providers selected by us or by a workspace may process data in other countries.
Where required, we and our business customers are responsible for using appropriate contractual, organisational, or legal safeguards for international transfers.
8. Retention
Retention depends on the record, workspace configuration, contractual requirements, security needs, and applicable law. Raw events and model debugging payloads should be retained for a limited operational period. Customer memory is retained according to workspace policy and may be corrected, exported, or redacted.
When data is deleted, limited pseudonymised security, financial, conversion, or audit records may be retained when necessary for legal obligations, dispute prevention, or system integrity. Backup copies age out under protected backup schedules and are not restored to active use except for disaster recovery.
9. Security
We use tenant scoping, role-based permissions, secure sessions, encryption of Instagram and model-provider credentials, webhook signature verification, allowlisted actions, idempotency controls, audit logs, rate limits, and human takeover controls.
No system is completely secure. Please report a suspected security or privacy incident immediately to privacy@leveromate.me.
10. Your choices and rights
Depending on applicable law and your relationship with Closevine, you may have rights to request access, correction, export, deletion, restriction, objection, or withdrawal of consent. You may also complain to the competent data-protection authority.
- Workspace users should contact their organisation owner or privacy@leveromate.me.
- Instagram customers may contact the business they messaged or follow our Data Deletion Instructions.
- A workspace administrator can export or redact an Instagram customer from the Inbox privacy controls when authorised.
We may verify identity and authority before acting. Never send us an Instagram password, OTP, access token, or payment card details.
11. Children and sensitive data
Closevine is a business service and is not designed for children to create workspaces. Businesses must not use Closevine to unlawfully target children, infer protected traits, or collect unnecessary sensitive personal data. Incidental messages that contain sensitive information should be minimised, restricted, escalated, or deleted according to workspace policy and law.
12. Changes to this policy
We may update this policy as the service, providers, or law changes. We will change the “Last updated” date and provide additional notice where a material change requires it.
13. Contact
The operator of Closevine is Leveromate. Our registered or principal address is Chennai, Tamil Nadu, India.
Privacy requests: privacy@leveromate.me
General support: support@leveromate.me