Privacy Policy

Last updated: March 28, 2026  ·  Effective immediately upon account creation

1. Introduction & Scope

DMChat ("we," "our," or "us") is a SaaS automation platform that helps Instagram Business account holders automate comment replies and engagement workflows via the official Meta (Instagram) Graph API and Google Sign-In.

This Privacy Policy explains what personal data we collect, how we use it, how we protect it, and what rights you have as a user. By using DMChat, you agree to the practices described in this policy.

This policy complies with the Google API Services User Data Policy, the Meta Platform Terms, the General Data Protection Regulation (GDPR), and the California Consumer Privacy Act (CCPA).

2. Data We Collect

2.1 Google Account Data (via Google Sign-In)

When you sign in with Google, we receive the following from Google OAuth:

  • Your name and email address
  • Your Google profile picture URL (not stored persistently)
  • An authentication token used solely to verify your identity

Google Limited Use Policy: Our use of data obtained from Google APIs is limited to providing and improving DMChat. We do not use Google user data to develop, improve, or train generalized AI/ML models, show advertisements, or transfer data to third parties unless required by law.

2.2 Instagram / Meta API Data

When you connect your Instagram Business account, we request and process:

  • instagram_business_basic: Your Instagram username, user ID, account type, and profile details
  • instagram_business_manage_messages: Access to read and send direct messages on your behalf (for automation)
  • instagram_business_manage_comments: Ability to read and reply to comments on your posts and reels
  • instagram_business_content_publish: Publishing access (used only if you configure content automations)
  • instagram_business_manage_insights: Engagement metrics to power your analytics dashboard
  • Your connected post and reel IDs and captions (for automation targeting)
  • OAuth long-lived access tokens (encrypted at rest, AES-256)

Meta Platform Policy Compliance: We only request permissions that are strictly necessary to operate the automation features you explicitly enable. We do not scrape, bulk-download, or store Instagram content beyond what is needed for your active automations.

2.3 Usage & Technical Data

  • IP address (for security and fraud prevention only)
  • Browser type and operating system
  • Feature usage events (e.g., automation created, automation paused)
  • Error logs and crash reports

3. How We Use Your Data

We use collected data only for the following purposes:

  • To authenticate you and maintain your account session
  • To execute the automation workflows you configure (comment replies, DM responses)
  • To display your Instagram analytics and automation performance in your dashboard
  • To send critical service and security emails (no marketing without opt-in)
  • To detect, investigate, and prevent fraudulent or abusive use
  • To comply with legal obligations

We do not: sell your data, use Instagram data for advertising, share your tokens with any third party, or use your content to train machine learning models.

4. Data Storage, Security & Retention

All data is stored on infrastructure located within the European Economic Area (EEA) and/or the United States, with encryption in transit (TLS 1.3) and at rest (AES-256).

Retention Periods

Data TypeRetention
Account profile (name, email)Until account deletion
Instagram access tokensUntil revoked or account deleted
Automation configurationsUntil manually deleted or account deleted
Automation execution logs90 days rolling
Security/authentication logs30 days rolling
Billing records7 years (legal requirement)

Meta Platform Data: Instagram platform data (usernames, post IDs, comment content) obtained via the Meta Graph API is not retained beyond the operational period of your active automations. When you disconnect your Instagram account or delete your DMChat account, all Meta platform data is immediately purged from our systems.

5. Data Sharing & Third Parties

We do not sell, rent, or share your personal data. We use the following sub-processors:

ServicePurposeData Shared
Supabase / PostgreSQLDatabase hostingAccount data, automation configs
VercelApplication hosting & CDNServer logs, IP addresses
Google OAuthAuthenticationName, email (from Google)
Meta Graph APIInstagram integrationAccess tokens, API calls
Stripe (if applicable)Payment processingBilling info only

We may disclose data to law enforcement or regulatory authorities when legally required to do so.

6. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

  • Access: Request a copy of the data we hold about you
  • Rectification: Correct inaccurate or incomplete data
  • Erasure ("Right to be forgotten"): Request permanent deletion of your data
  • Portability: Receive your data in a structured, machine-readable format
  • Objection: Object to processing based on legitimate interest
  • Withdraw Consent: Revoke Instagram or Google permissions at any time

To exercise any right, email us at privacy@dmchat.io. We will respond within 30 days.

7. Data Deletion Instructions

⚠️ Required by Meta Platform Policy — User Data Deletion

You can permanently delete all your DMChat data and revoke Instagram access using any of the following methods:

  1. In-App Deletion: Go to Dashboard → Settings → Security → Delete Account. This immediately and permanently deletes your account, all automation configurations, connected Instagram data, and access tokens from our systems.
  2. Instagram / Facebook Settings: Visit facebook.com/settings → Business Integrations and remove DMChat. We will receive a deletion callback from Meta and will purge all associated data within 24 hours.
  3. Email Request: Email privacy@dmchat.io with Subject: "Data Deletion Request". We will confirm deletion within 72 hours.

After deletion, we retain only anonymised billing records as required by applicable tax law (up to 7 years). No personally identifiable information from Meta APIs is retained after deletion.

8. Google API Services — Limited Use Disclosure

✓ Required by Google API Services User Data Policy

DMChat's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • We only use Google data to provide authentication and user identification services within DMChat
  • We do not transfer Google user data to third parties for advertising purposes
  • We do not allow humans to read Google user data unless you explicitly grant us permission or it is required for security purposes
  • We do not use Google data to develop, improve, or train generalized AI or ML models

9. Cookies & Tracking

We use only essential session cookies necessary to maintain your authenticated session. We do not use advertising trackers, third-party analytics pixels, or behavioral tracking cookies. You can clear cookies via your browser settings at any time, which will log you out.

10. Children's Privacy

DMChat is intended solely for users aged 18 and over, or the minimum legal age required to operate an Instagram Business account in your jurisdiction. We do not knowingly collect data from minors. If you believe a minor has registered, contact us immediately at privacy@dmchat.io.

11. Changes to This Policy

We may update this Privacy Policy to reflect changes in law, our practices, or platform capabilities. When we make material changes, we will notify you via email and display a notice in your dashboard at least 14 days before the change takes effect. Your continued use of DMChat after that date constitutes acceptance of the updated policy.

12. Contact & Data Controller

The data controller responsible for your personal data is DMChat.

Privacy inquiries: privacy@dmchat.io

Data deletion requests: privacy@dmchat.io

Response time: Within 30 days (72 hours for deletion requests)