Privacy Policy
Effective date: July 24, 2026
1. Who we are
Krieger Bangerz LLC ("Krieger Bangerz," "we," "us," or "our") operates KBzA iWorks Social ("iWorks Social" or the "Service").
2. U.S.-only private beta
iWorks Social is an invitation-only U.S. private beta with Meta review in progress. It is not offered to the general public. We do not invite, market to, or knowingly support users outside the United States during this private beta.
The approval build supports authorized account discovery, profile and media reads, conversation and selected-thread reads, and messaging features for eligible inbound conversations. It does not provide bulk sends, public self-service registration, scheduling, publishing, comment management, billing, or an analytics warehouse.
3. Whose information we process
The Service processes information about authorized account operators, connected Facebook Pages and Instagram Professional accounts, people who participate in conversations with those accounts, and people who contact our privacy, deletion, legal, security, or support addresses.
An account operator must have authority to connect the account and must comply with applicable law, Meta requirements, and any notice obligations owed to message participants.
4. Information we handle
- Encrypted Meta access tokens, token status, authorization timestamps, and token-expiration information.
- Meta user identifiers protected with keyed one-way HMACs for internal matching.
- Facebook Page and Instagram account identifiers retained as routing metadata.
- Authorized profile and recent-media data requested from Meta.
- Conversation and message information retrieved when an authorized operator opens a selected thread or uses messaging features.
- Opaque sessions, authorization state, metadata-only webhook receipt hashes and classifications, consent or opt-out state, and deletion status.
- Information voluntarily included in privacy, deletion, legal, security, or support correspondence.
DM content is retrieved live from Meta and is not persistently stored by the application. Webhook handling stores hashes and allowlisted operational classifications, not raw message bodies, attachment content, or raw webhook request bodies.
The schema includes idempotency, audit, and rate-limit tables, but the current runtime does not write records to those tables.
5. Meta permissions
The current review authorization requests only:
public_profile, to identify the Meta user completing authorization.pages_show_list, to identify Facebook Pages the authorizing operator is permitted to access.pages_read_engagement, to read limited Page information needed to confirm and route access to the selected connected Instagram Professional account.business_management, to access only the business-owned Pages and connected Instagram Professional accounts selected by an authorized operator through Meta's Facebook Login flow. iWorks Social does not use this permission to change business settings, roles, advertising accounts, payment methods, or unrelated assets.instagram_basic, to read authorized Instagram Professional account profile and recent-media information.instagram_manage_messages, to retrieve conversations and selected message threads and to send a manually approved response to an eligible inbound conversation.
Any new permission requires a separate product, privacy, and release review.
6. Use and disclosure
We use information only to operate messaging features, maintain and secure the Service, route authorized accounts, retrieve requested data, prepare and send responses, enforce opt-out state, diagnose failures using sanitized operational counts, prevent abuse, process privacy and deletion requests, and satisfy legal and platform obligations.
We do not use direct-message content for targeted advertising, cross-context behavioral advertising, profiling, routine internal review, unrelated product development, or product analytics. Authorized account operators may view selected conversations through the Service.
We do not sell personal information, share personal information for cross-context behavioral advertising, or use connected-account data for third-party advertising.
We may disclose information to service providers, when required by law, to address security or rights risks, or in a business transaction subject to applicable law and confidentiality protections.
7. Service providers
- Meta: account authorization, profile and media information, selected conversation data, and message delivery.
- Vercel: private-beta application hosting and limited request and operational metadata.
- Neon: encrypted authorization material and limited operational metadata.
- Cloudflare: public website hosting, network protection, and approved email forwarding.
- Google: designated business mailboxes for privacy, deletion, legal, security, and support requests.
The private beta does not use a third-party advertising pixel, behavioral analytics platform, or message-content analytics service.
8. Security
Access tokens are encrypted at rest. Application traffic uses encrypted transport. The browser receives an opaque session identifier instead of a Meta access token. Session and operational identifiers use hashes or HMACs where appropriate. Database-owner credentials are separated from the application role. Logs use allowlisted codes and sanitized counts rather than raw content, tokens, identifiers, or upstream error details.
No internet service can guarantee absolute security.
9. Revocation, deletion, and retention
| Data category | After Meta revocation | After verified deletion | Retention |
|---|---|---|---|
| Authorization and encrypted token material | Revoked; future access stops | Deleted with the user | Until revocation, deletion, or token-lifecycle removal |
| Server sessions | Immediately invalid; also invalid after 2 hours idle or 8 hours absolute | Deleted with the user | Expired sessions and sessions revoked more than 30 days earlier are removal-eligible |
| Connected-account routing | Marked disconnected | Deleted with the current single-user workspace | Until deletion or approved reconnection |
| Raw DM and attachment content | Not persistently stored | No iWorks Social archive exists | Retrieved live from Meta only |
| Webhook receipts | No new authorized processing | Tenant-linked records deleted with an orphaned workspace | 30 days when webhook processing is activated |
| Deletion-confirmation status | Not applicable | Content-free status remains temporarily | Up to 30 days |
| Opt-out state | Remains to prevent unauthorized replies after reconnection | Deleted with associated data | Until opt-in or associated-data deletion |
| Request correspondence | Not affected by Meta revocation | Handled separately from application deletion | Ordinarily up to 12 months after closure, unless longer required for security, disputes, legal hold, or law |
| Provider backups | Not used for ordinary access | May persist temporarily | Provider's ordinary backup lifecycle, subject to legal holds |
The current private beta is limited to one authorized Meta user per workspace. Shared multi-user workspaces are not offered.
Webhook processing and the custom-domain deletion callback will not be activated until scheduled expired-record removal is configured and verified.
10. Privacy requests
Account operators and people who participated in conversations handled through the Service may request access, correction, or deletion by emailing privacy@kriegerbangerz.com. Deletion requests may also be sent to deletion@kriegerbangerz.com.
Do not send credentials. We may request information reasonably necessary to verify identity, authority, and the relevant account or conversation. Authorized agents must provide written authorization.
We will acknowledge a verified request within 10 business days and respond within 45 calendar days. If applicable law permits an extension, we will explain the reason and expected completion date.
To appeal a denied request, email legal@kriegerbangerz.com with the subject "Privacy Request Appeal" within 30 days. We will respond within 45 calendar days.
These procedures do not concede that any particular privacy statute applies. We provide rights required by applicable law.
11. Children and geographic scope
The Service is not intended for anyone under 18. The private beta is offered only to invited users in the United States and is not knowingly offered in the European Economic Area or United Kingdom.
12. Changes and release control
We may update this policy as the Service, law, or platform requirements change. We will post the revised policy here and update the effective date.
Before activating a new feature, provider, Meta permission, message flow, telemetry field, or retention rule, Krieger Bangerz will review whether the data inventory and public notices must be updated.
13. Contact
Privacy
Data deletion
Security
Operator
Krieger Bangerz LLC
Public mailing address:
445 hwy 46 S Suite 29 #159
Dickson, TN 37055