privacy
Two people are in this policy.
Most privacy policies are written for the customer. This one has to be written for somebody else as well: the person who left a comment, never signed up for anything, and may not know this service exists.
Where this policy names a retention period or a security measure, that value is the one configured in the running system rather than an intention. The table further down is generated from the engine’s own configuration when this page is built.
Who is who
The business or creator whose Instagram account we operate. They decide which posts are automated, what the messages say, and who is written to. Under India’s DPDP Act 2023 they are the Data Fiduciary: it is their decision, and their account.
Somebody who left a comment on that account’s post. They have no account with us, they never agreed to anything with us, and they may not know we exist. Everything below is written so that they can read it and know exactly what is held.
We run the software on the client’s instruction and do not use the data for anything of our own. We do not build profiles across clients, and one client’s data is separated from another’s in the database itself.
What is collected
All of it arrives from Instagram’s official APIs, scoped to the one account the client connected. Nothing is scraped, and nothing is bought.
- The commenter’s Instagram-scoped user ID and username
- To know who to reply to, and to be able to honour it if they later say stop.
- The comment: its text, its ID, and which post it was on
- This is the trigger. Every top-level comment is answered, so the text is read whether or not it contains any particular word — the service does not filter by keyword.
- Timestamps
- Instagram allows a private reply for seven days from the comment. After that nobody can send one.
- The named outcome, and the message that went out
- So the same person is never messaged twice for the same comment, and so the client can see what was actually sent.
- Tags, where a client uses them
- A label on a contact, chosen by the client — for example, which lead magnet somebody asked for.
What is deliberately not collected
- No email addresses. No phone numbers.
- No follower lists, and no data at all about people who have not commented.
- No direct messages. The service does not subscribe to Instagram’s messaging webhooks and holds no permission to read a conversation.
- No likes, no insights, no profile scraping.
- Nothing is sold, rented, or shared with advertisers or data brokers. There is no arrangement of that kind to disclose.
Why it is held
Three reasons, and there is not a fourth.
To answer the comment
Somebody asked for something in a comment. The private reply is the answer. That is the whole of the primary purpose.
To honour a refusal
An opt-out only works if we remember who asked. So do the caps that stop one person being messaged repeatedly. Forgetting is not a neutral act here — it is what causes the harm.
To show the client the record
A client is entitled to see what their own account sent, and what it declined to send and why. That record is what makes the automation answerable rather than a black box.
What Meta sees
Meta sees the message, because Meta delivers it. Every private reply and public reply goes through the official Graph API on the client’s own account, so from Instagram’s side it is that account replying — which is exactly what it is.
Meta’s own handling of that data is governed by Meta’s terms, not by this policy. What this policy can tell you is what we ask for: comment data on the client’s own posts, and permission to send the reply. Not messages, not followers, not insights.
How long it is kept
Deletion is automatic and runs on the schedule below. A client may shorten these, and the software refuses values below a floor, because some records are still needed for the service to behave correctly — a duplicate-suppression ledger pruned too early stops suppressing duplicates.
| What | Kept for |
|---|---|
| The record that somebody asked not to be contacted | kept |
| What a person did in the console: who paused an account, who pulled the kill switch no commenter data in this table | 730 days |
| Taps on a link in a message: which link and when, a bot guess and the kind of app it was opened in (Instagram, WhatsApp, Facebook, other) — no IP address, no account, nothing that says who tapped it | 400 days |
| The record of what was decided, and the message that went out | 365 days |
| Failed sign-ins and refused sessions — no commenter appears in these no commenter data in this table | 180 days |
| A once-a-minute note that the service was running — no commenter appears in these no commenter data in this table | 180 days |
| The comment itself, exactly as Instagram sent it | 90 days |
| Attempts to notify a client’s own systems no commenter data in this table | 90 days |
| Comments a spam filter held back, with the signals that fired | 90 days |
| Sign-in sessions that have already expired or been revoked no commenter data in this table | 30 days |
Opt-out records are never deleted, and that is deliberate. Erasing the record that somebody asked not to be contacted is precisely how they start being contacted again. It is the one piece of data whose retention protects the person it is about. It survives the end of a client engagement for the same reason.
Who else sees it
The client whose account it is, through their own record of what was sent. Meta, because Meta delivers the message. The infrastructure providers who run the servers and the database. Nobody else — there is no advertiser, no data broker and no analytics partner receiving any of this.
One client cannot see another’s data. That separation is enforced in the database itself with row-level security, so it holds even where application code is wrong.
Your rights, and how to use them without an account
Under India’s Digital Personal Data Protection Act 2023, and equivalent rights elsewhere, you may ask us to tell you what is held about you, correct it, delete it, or stop contacting you.
You do not need an account, because you do not have one. Email [email protected] naming the Instagram handle you comment from and the account you commented on. We respond within thirty days. Deletion is carried out at the database level and removes every record tied to you, with the single exception of an opt-out entry, which is kept precisely so that you are not contacted again. The deletion page sets out all three routes, including the two that do not involve us.
Security
- Each client’s data is separated at the database row, using row-level security — not by a column that application code has to remember to filter on.
- Instagram access tokens are encrypted at rest with AES-256-GCM, using a key ring that supports rotation, with the key held outside the database.
- Every webhook from Meta is verified by cryptographic signature before a single byte of it is trusted.
- The record of what was sent, of what a person did in the console, and of opt-outs cannot be altered or deleted by the application. The database refuses those operations. A system that can quietly rewrite its own history cannot be audited.
- Backups are proven by restoring them into a scratch database and decrypting every token, including a deliberately wrong-key probe that has to fail.
- Client passwords are never stored — only an Argon2id hash, from which a password cannot be recovered, including by us.
Children
The service is not directed at children and we do not knowingly process the data of anyone under 18. If you believe we hold such data, contact us and it will be deleted.
Changes
If this policy changes materially, the date at the top changes with it. The retention date shown there is when the numbers were last read from the running system, which is every time this page is built.
Contact
[email protected]. Data protection queries, deletion requests and opt-out requests all go to that address, and it is read by a person.