Privacy Policy
This policy explains how SSG REAPER ("we," "our," or "the service") processes information when an authorized user connects a social or content account. SSG REAPER is a private, owner-operated integration that uses official platform APIs only after authorization. Its Instagram connection uses Instagram Login directly and does not depend on a Facebook Page.
1. Information we process
The information available depends on the platform, features enabled, account role, and permissions granted. It may include:
- Account identifiers, usernames, display names, profile images, professional-account type, and account statistics.
- Media and post metadata, captions, links, publishing status, and performance metrics.
- Comments, mentions, replies, moderation status, and—only when a messaging feature is enabled—messages needed to respond to account communications.
- Audience, reach, engagement, and other insights made available by the authorized platform.
- Business, Page, ad, lead, catalog, Threads, or WhatsApp data only when the user separately enables and authorizes those features.
- OAuth access and refresh tokens, granted scopes, token-expiration data, webhook identifiers, and connection status.
- Minimal operational logs such as timestamps, request outcomes, rate-limit information, and security events.
We do not request or store passwords for connected social accounts.
2. How information is used
- Authenticate the account and maintain the user-authorized connection.
- Read account and content information, prepare or publish user-directed content, retrieve analytics, and perform user-directed moderation or engagement actions.
- Operate webhooks, diagnose errors, prevent abuse, secure the service, and comply with platform rules and law.
SSG REAPER does not sell personal information or use connected-account data for third-party advertising.
3. Legal basis and user control
Processing is based on the user’s authorization, performance of the requested service, legitimate security and operational interests, and legal obligations where applicable. The user controls which accounts and permissions are connected and may revoke platform access at any time.
4. Sharing and service providers
Information may be processed by the connected platform, infrastructure and hosting providers, and security or logging providers only as needed to operate the service. We may disclose information when required by law or to protect users, the service, or others. We do not disclose platform data to data brokers.
5. Retention
OAuth credentials and connection metadata are retained while a connection remains active. Cached platform data and operational logs are kept only as long as reasonably necessary for the requested workflow, security, troubleshooting, legal compliance, or platform requirements. Data is deleted or de-identified when no longer needed, subject to backups and legal obligations.
6. Security
We use access controls, encrypted transport, secret isolation, least-privilege storage, and credential redaction. No method of storage or transmission is guaranteed to be completely secure.
7. User rights and deletion
A user may revoke access through the connected platform and may request access, correction, export, or deletion by following the Data Deletion instructions. We may request limited information to verify the request and locate the correct connection.
8. Children
The service is not directed to children under 13 or any higher minimum age required by the connected platform or local law.
9. International processing
Information may be processed in the United States or other countries where the service providers operate, subject to applicable safeguards and platform terms.
10. Changes
We may update this policy as features, platform requirements, or law change. The updated date above will identify the current version.
11. Contact
Questions or privacy requests: sargesgaming@gmail.com.