Privacy Policy

Kuro Engage is operated by Kuro Studio. This privacy policy explains how we process personal data when you visit the website, create or use an account, join a workspace, connect Instagram assets, subscribe to a paid plan, or interact with automated Comment-to-DM campaigns.

If you commented under an Instagram post and received an automated message, section 7 is written for you. Version 2.0, effective 2026-07-16.

1. Controller

Controller
Kuro Studio, Lukas Wirth
Address
Hirschberger Str. 24, 90559 Burgthann, Germany
Phone
+49 (0) 151 23476125

2. Scope and roles

We process personal data to operate Kuro Engage, secure accounts, manage access, support workspaces, bill subscriptions, and deliver Instagram automation through the official Meta API.

We are the controller for account, workspace, invite, billing, support, website, and platform operation data. For campaign content and the audience interactions triggered through a customer's connected Instagram account, the customer is the controller and we act as their processor under a data processing agreement (https://engage.kurostudio.io/dpa). The customer decides the keywords, the message copy, and who is contacted, and is responsible for having a lawful basis and for complying with Meta platform rules, advertising rules, and communication laws.

3. Data we process

  • Account data such as email address, login status, passkey metadata, workspace membership, role, invite code, and referral attribution.
  • Workspace data such as workspace name, connected social accounts, campaign settings, keywords, linked assets, and team roles.
  • Instagram and Meta integration data such as account identifiers, Instagram user IDs, webhook events, comment IDs, commenter IDs and usernames, comment text, message status, opt-out records of users who replied STOP, and Meta access tokens held in encrypted storage.
  • Lead and campaign data such as email addresses submitted through a campaign, source campaign, source event, delivery status, and timestamps.
  • Billing data such as your plan, billing interval, subscription and payment status, invoices, the billing address and VAT identification number you enter at checkout, the customer and subscription identifiers assigned by our payment provider, and the payment events that provider sends us. We never receive or store full card numbers.
  • Product analytics data collected first-party by us: event name, the surface and page path an event happened on with query strings removed, locale, a random identifier stored in your browser's local storage, and a session identifier stored for the duration of the browser session. These events deliberately contain no email addresses, names, IP addresses, tokens, or payment details.
  • Technical data such as browser and device information from the user agent, referrer, request timestamps, log entries, error diagnostics, and security events. We record the user agent and referrer when an asset link is opened and when someone subscribes to the newsletter or waitlist, as a record of that consent.
  • Communication data from email, support, legal inquiries, and product feedback.

We do not store your IP address. It is used transiently in memory to rate-limit form submissions and is not written to our database or retained.

5. Authentication and access

Users sign in with magic links and may use passkeys. Authentication is provided through Supabase. We process login data to create sessions, prevent unauthorized access, and keep workspace data isolated.

Where access to the product runs through invites, we store invite codes and referral attribution so we can see who joined through whom and manage access. Referral attribution links workspaces to each other, not private individuals.

6. Meta and Instagram automation

When a connected Instagram account receives a comment that matches an active campaign keyword, Kuro Engage processes the relevant webhook data and sends a private reply or direct message through the official Meta API. Comment IDs and delivery logs are stored to prevent the same person being messaged twice and to provide operational evidence.

Meta access tokens are held in encrypted storage, are readable only by server-side processes, and are never exposed to workspace users. Customers are responsible for campaign wording, asset links, audience targeting, and ensuring that their use of Instagram automation is lawful and compliant with Meta's platform terms.

7. Information for Instagram users who received a message

If you commented a keyword under a post of a business that uses Kuro Engage, we processed your data on that business's behalf in order to send you the automated reply you asked for. This section explains what that means and what you can do about it.

What we receive from Meta: your Instagram user ID, your username, the text of your comment, the ID of your comment, and the delivery status of the message sent to you. If you then submitted your email address in the conversation, we store that email address together with the campaign it came from.

Why: your keyword comment is the request that triggers the message, so you initiate the contact. We store the comment ID to make sure you are not messaged twice for the same campaign. The business that runs the campaign is the controller for this data; we act as their processor.

How to stop messages and have your data deleted

  • To stop automated messages, reply STOP (or UNSUBSCRIBE or CANCEL) to any message. We confirm once and record your Instagram user ID in an opt-out list so no further automated messages are sent to you. Reply START to opt back in. Commenting a campaign keyword again counts as a new request and will trigger a reply again.
  • You can also block or restrict the business account in Instagram. Our system already prevents you from being messaged twice for the same campaign.
  • To have your data deleted, write to legal@kurostudio.io with your Instagram username. We will delete the data we hold about you and forward the request to the business whose campaign you interacted with.
  • You can also request deletion through Instagram by removing the connection to the business's app in your Instagram settings, which triggers an automated deletion request to us.
  • You have the same rights as everyone else under section 13, including the right to complain to a data protection authority.

8. Billing and payments

Paid subscriptions are processed by Stripe. When you start checkout, you enter your billing details directly with Stripe. Stripe processes your payment details as its own controller under its own privacy policy; we never receive full card numbers.

We store the customer and subscription identifiers Stripe assigns, your plan and billing status, and the payment events Stripe sends us. Those event records include the payload Stripe transmits, which we keep so that billing state can be reconciled and audited. We use this data to provide the paid service, issue invoices, and meet our accounting and tax obligations.

9. Service providers

  • Supabase: authentication, database, storage, and security infrastructure.
  • Vercel: hosting, deployment, CDN, and runtime infrastructure.
  • Meta Platforms: Instagram API, webhook delivery, and message delivery for connected accounts.
  • Resend: transactional email delivery.
  • Stripe: payment processing, subscription billing, invoicing, and tax calculation for paid plans.

We choose service providers carefully and put the contractual safeguards in place that the law requires. The current list of subprocessors we use for customer campaign data is part of our data processing agreement at https://engage.kurostudio.io/dpa.

We do not use Google Analytics, Google Tag Manager, advertising pixels, or any other third-party tracking or advertising network. Our product analytics are first-party and stay with us.

10. Cookies, local storage, and analytics

We use necessary technologies for login sessions, language, theme preferences, security, and service operation. These are required for the website and app to function and are used on the basis of Art. 6(1)(f) GDPR and Section 25(2) TDDDG.

Our product analytics do not use cookies. They use a random identifier in your browser's local storage and a session identifier in session storage, so that repeated events can be grouped without identifying you. You can clear both at any time through your browser settings.

The cookie settings dialog on our website stores your preference locally in your browser. It exists so that consent is already in place before any third-party provider is ever introduced. As long as no such provider is loaded, the analytics and marketing categories have nothing to enable.

11. Retention

  • Account and workspace data is kept while the account or workspace is active. After a paid subscription ends, we keep the workspace data for 30 days so it can be exported or the subscription resumed, then delete it automatically.
  • Campaign, message, and lead data is kept while the campaign and the workspace exist, because it is the customer's operating record and prevents the same person being messaged twice.
  • Raw webhook payloads from Meta and Stripe are kept for idempotency, reconciliation, debugging, and abuse prevention, and are deleted automatically after 90 days at the latest.
  • Support and legal correspondence is kept as long as needed to resolve the request and document the interaction.
  • Invoices, accounting records, and other documents subject to commercial or tax retention duties are kept for the legally required period, which can be up to ten years. During that time the data is restricted to that purpose.

12. Security

We use TLS encryption, role-based workspace access, Supabase Row Level Security, encrypted storage for sensitive Meta tokens, least-privilege service access, and operational logging. No security measure is perfect, but security and workspace isolation are core design requirements for the product.

13. Your rights

Subject to the legal requirements, you have the right to access, rectification, erasure, restriction, portability, and objection, and the right to withdraw consent you have given with effect for the future. Where we rely on legitimate interests, you may object to the processing on grounds relating to your particular situation.

To exercise your rights, contact legal@kurostudio.io. We may need to verify your identity before acting on a request, and we answer within the statutory deadline. This right is open to everyone whose data we process, not only to our customers. If you interacted with a campaign on Instagram, section 7 describes the fastest route.

You also have the right to lodge a complaint with a competent data protection supervisory authority, for example the authority where you live or work.

14. International transfers

Some providers may process data outside the EU or EEA, in particular in the United States. Where this happens, we rely on adequacy decisions including the EU-US Data Privacy Framework, on Standard Contractual Clauses, or on other appropriate safeguards under Chapter V GDPR.

15. Updates

We may update this privacy policy when the product, providers, legal requirements, or processing activities change. The current version is always published on this page with its version number and effective date. We only describe processing that actually takes place: if a provider or a purpose is not named here, we are not using it.

Last updated: 2026-07-20