Legal

Data Deletion

Disconnect a social account, request deletion directly, or check the status of a deletion request sent through Meta.

Last updated: 8 August 2026

1. Disconnect inside KOLab

An organization administrator can open the Integrations area, select the connected account, and remove it. This prevents future publishing, synchronization, and messaging through the stored credentials. If you need all associated historical data removed as well, use one of the deletion-request methods below.

2. Delete through Facebook or Instagram

You can remove the KOLab application through your Meta/Facebook app and website settings and select the option to delete information sent to KOLab. Meta then sends KOLab a signed request identifying the authorizing user.

After validating Meta’s signature, KOLab generates a confirmation code and queues deletion for matching Facebook and Instagram integrations. The response includes a private status link on this page. The process removes or anonymizes OAuth credentials, platform identifiers, connected inbox data, and associated stored publishing data from active systems.

3. Request deletion by email

Email contact@kolab-inc.com with the subject “Social Connectors data deletion”. Include the KOLab organization name, your account email, and the connected social Page or username. Do not email access tokens, passwords, or App Secrets.

We may ask you to verify your identity, organization membership, and authority over the connected account before deleting data. We will acknowledge and complete verified requests within the period required by applicable law and will ordinarily target completion within 30 days.

4. What deletion covers

  • stored Meta access and refresh credentials;
  • connected Page, account, profile, and authorizing-user IDs;
  • Facebook and Instagram inbox contacts and message history;
  • public Threads reply data when included in the verified request;
  • stored publishing content and provider delivery references;
  • webhook subscriptions and integration-specific automation data.

We may keep a minimal, pseudonymous deletion record containing the confirmation code, request time, completion state, and a one-way subject hash. Published content already present on a social platform is controlled by that platform and may need to be removed there separately. Protected backup copies expire through the normal backup lifecycle and are not used for ordinary processing.

5. Check a confirmation code

6. Meta technical callback

Meta App Dashboard reviewers and administrators can configure the following HTTPS Data Deletion Request Callback URL:

https://socials.kolab-inc.com/api/meta/data-deletion

The endpoint accepts Meta’s `signed_request` POST field, verifies its HMAC-SHA256 signature using the server-side app secret, and returns a JSON object containing `url` and `confirmation_code`.

7. Contact

KOLab Inc.
Hong Kong
Email: contact@kolab-inc.com