← Levels Access Concierge

ACCESS PRIVACY NOTICE · 11 OCTOBER 2026

You approve the access.
We handle it with care.

The Access Concierge helps authorized clients grant Levels the access agreed for their project. A sample preview is labeled clearly and does not collect real account credentials.

What this application uses

When live connections are enabled, the application uses your approved project identity, project membership, connection status, and the dates and results of access checks. Google or Microsoft sign-in is separate from permission to read a business system. You review the provider’s consent disclosure before granting access. Business email is read-only across the agreed mail surface. Zoho authorization also covers defined record and configuration improvements; those changes require project approval and are never made as part of verification.

The secure AWS connection service handles provider authorization, token exchange, passwords and temporary verification codes. Reusable source secrets are stored in AWS Secrets Manager. They are not stored in the project database, analytics, or browser storage. Temporary Cerenade codes are used only for the active verification attempt and are not saved. The application does not collect authenticator seeds. During a separately authorized acceptance walkthrough, Cerenade uses synthetic practice credentials and a documented practice code through the same secret and challenge machinery. That test does not verify a live Cerenade account.

What an access check does

Levels reads a small sample or checks read permission to confirm the agreed data is available. Checks do not send email, change source records, delete files, or copy an entire history. The results retain limited evidence such as a date or whether a check passed. Source content is not returned in the connection dashboard. Any subsequent Metrics Engine processing is governed by the separate project agreement and approved data plan.

Optional Instagram checks use the official professional-account connection and report only the data and history the provider actually makes available. An optional Telegram connected business bot receives events for the conversations you allow. The Concierge discards message and media content, retaining only connection evidence and limited activity timing or counts. It does not import old Telegram chats, send messages, or mark them as read. A future Metrics Engine content-processing flow would require separate preparation and approval.

Helping when a step gets stuck

We record essential operational events: which connection step was opened, whether sign-in and access checks succeeded, the time taken, retries, and requests for help. Random journey, request and attempt identifiers connect these events so our authorized Levels operators can investigate a support reference. We retain only a broad device/platform category, not a full browser fingerprint.

These events never include passwords, access tokens, submitted verification codes, message or attachment content, or credential request bodies. There is no session replay or advertising tracking. Application event records are available for 30 days and expired records are removed through bounded cleanup. Hosting-provider security logs have separate administrative retention settings; Levels must review them before live acceptance.

Services involved

The client interface runs on hosted Cloudflare infrastructure. The separate AWS connection service processes sensitive authorization and protects source secrets. Your chosen identity and source providers handle their own sign-in and consent screens. When enabled, Resend delivers one-time sign-in links to the approved email address. This application uses no advertising analytics or session replay.

Your control

You can decline a connection and choose “Let Levels handle this” for help. To correct your project identity, review access, request removal, or ask about retention, contact your Levels project lead using your existing project email thread. Levels reviews retained access at project closeout; ongoing access requires an agreed purpose and owner. Removing a dashboard entry alone does not revoke a provider grant. Levels coordinates the actual revocation with the system owner.

Your project agreement determines the approved business purpose and retention arrangements. Do not send passwords or one-time codes by email.