levios
Privacy Policy
Last updated:
Controller and contact
This Privacy Policy explains how levios processes personal data when you use the platform to create Instagram comment-to-DM automations.
The data controller is Mazini Empreendimentos Digitais LTDA, registered under CNPJ 37.030.865/0001-00, with headquarters at Avenida Pereira Barreto, 1479, Sala 2108, Baeta Neves, São Bernardo do Campo/SP, Brazil, ZIP 09751-000, responsible for the levios product.
For questions, data-subject requests, or privacy matters, contact support@levios.app. No formal data protection officer has been appointed; the channel above handles privacy and data protection matters.
Data we collect
We collect data you provide when creating and using your account, such as email, display name, preferred language, and information needed for authentication.
We also collect technical analytics data, such as the stable account identifier, browser user agent, and URL without query parameters or fragments. When available in the browser, we collect Meta attribution cookies _fbp and _fbc to measure conversions and improve matching for events sent to Meta.
When you connect an Instagram account, we collect and store data needed to operate the integration, including professional account ID, username, public name, profile picture, follower, following and media counts, permission status, and connection metadata.
To run automations, we process Instagram comments, messages, and interaction data, such as event IDs, comment content when needed to evaluate triggers, timestamps, public identifiers of the interacting profile, follow status when available, delivery metadata, and operational automation history.
When the automation asks for it and the person shares it, we may store contact data captured in conversation, such as email, phone number, tags, and attributes related to the service or funnel configured by the user.
Purposes of processing
We use data to authenticate users, connect professional Instagram accounts, create and save automations, identify comments that match configured triggers, send eligible public replies and DMs, store contacts, and show operational metrics.
We use the email address to send authentication messages, such as signup confirmation and account-access recovery.
We also use data for security, abuse prevention, delivery deduplication, Meta policy compliance, user support, audit, failure diagnostics, campaign measurement and attribution, legal compliance, and product improvement during the beta.
We do not sell personal data and do not use imported or captured contact data for our own advertising outside the operational purpose of levios.
LGPD lawful bases
We process levios user data mainly to perform a contract or pre-contractual steps related to the service being used or tested in beta.
Authentication emails are processed to perform the service and protect account access.
We process technical logs, analytics, conversion measurement, audit records, security data, fraud prevention data, platform-policy compliance data, and service-improvement data based on legitimate interest, limited to what is necessary and balanced against the context.
We process data when necessary to comply with legal or regulatory obligations, respond to valid authority requests, and preserve minimum compliance records.
When an automation collects email or phone data from a contact inside a conversation, the user who configured the automation is responsible for having the authorization or lawful basis needed for that collection and later use.
Meta integration
levios uses the Instagram API with Instagram Login to access permissions approved by Meta, such as basic professional account data, comment management, and message management, according to the scope authorized by the user.
Automations must follow Meta Platform Policies, including the applicable messaging window, opt-in patterns, anti-spam restrictions, and the prohibition on purchased lists or contacts without legitimate context.
Meta also processes data under its own terms and policies. levios does not control Meta systems, but limits API calls to what is necessary to deliver the product functionality configured by the user.
Sharing and subprocessors
We share data only when needed to operate the service, comply with legal obligations, or respond to a valid data-subject request.
We use Meta for login, Instagram APIs, webhooks, comments, messages, and conversion measurement through the Conversions API. We use PostHog for product analytics and server-side forwarding of configured conversion events to Meta. We use Supabase for authentication, database, storage, and related services. We use Cloudflare for hosting, Workers, queues, network protection, and application delivery. We use Resend to deliver authentication emails configured through Supabase.
When a user is referred through the referral program, we share that person’s name, @handle, and email only with the affiliate who referred them, and only within that affiliate’s own referral dashboard or list.
These providers may process data on behalf of levios as subprocessors, subject to their own contracts, security measures, and processing locations.
International transfers
Because we use global providers, personal data may be processed outside Brazil, including in the United States and other countries where Meta, PostHog, Supabase, Cloudflare, and Resend maintain infrastructure or vendors.
We choose providers with contractual and technical controls compatible with personal-data protection and seek to limit transfers to what is necessary to provide the service.
Retention and deletion
We keep data while the account is active and for as long as needed to provide the service, meet legal obligations, resolve disputes, prevent abuse, and maintain proportionate audit records.
A user may disconnect an Instagram account, which revokes permissions, stops automations linked to that account, and schedules cleanup of applicable data according to the product architecture.
A user may also request deletion of the levios account. The planned model disables access immediately, revokes permissions and tokens, pauses automations, and schedules personal-data purge in about 7 days, with the ability to cancel within that window. The purge runs well before the 30-day operational reference used for LGPD request handling.
Requests from Meta, such as deauthorization or data deletion callbacks, are handled by dedicated product endpoints and linked to the Instagram account ID when available.
Data-subject rights
Under the LGPD, you may request confirmation of processing, access, correction, anonymization, blocking or deletion of unnecessary or excessive data, portability when applicable, information about sharing, review of automated decisions when applicable, and withdrawal of consent when consent is the lawful basis.
To exercise rights, send a request to support@levios.app. We may ask for additional information to confirm your identity and protect the account against unauthorized access.
When you use levios to process data about your own contacts, you may also have controller or processor responsibilities toward those people, depending on the specific context.
Security
We apply technical and organizational controls proportionate to the beta stage of the product, including authentication, access policies, audit records, data segregation by connected account, and failure monitoring.
Long-lived Meta tokens are encrypted at rest with pgcrypto in the database. Server secrets are not exposed to the client.
No system is completely risk-free. If we identify a relevant incident involving personal data, we will take the containment, investigation, and communication measures required by applicable law.
Cookies and similar technologies
levios uses cookies and local storage for authentication, session, security, product preferences, and analytics.
When present, we read the _fbp and _fbc cookies set by the Meta integration and associate them with the authenticated user in PostHog. These identifiers are sent unhashed to Meta because the Conversions API requires the original attribution value; we do not create _fbc from the internal user identifier.
We do not sell personal data or share message or contact content with ad networks for our own advertising.
Minors
levios is intended for people who are 18 or older and businesses that use professional Instagram accounts.
We do not direct the product to children or teenagers. If we become aware of improper use by a minor, we may terminate the account and delete related data.
Changes to this policy
We may update this Privacy Policy to reflect changes to the product, Meta integrations, providers, legal requirements, or security practices.
The published version will show the last updated date. Material changes will be communicated by reasonable means within the product or through available contact channels.
