Privacy Policy
Last updated: March 28, 2026 · Effective immediately upon account creation
1. Introduction & Scope
DMChat ("we," "our," or "us") is a SaaS automation platform that helps Instagram Business account holders automate comment replies and engagement workflows via the official Meta (Instagram) Graph API and Google Sign-In.
This Privacy Policy explains what personal data we collect, how we use it, how we protect it, and what rights you have as a user. By using DMChat, you agree to the practices described in this policy.
This policy complies with the Google API Services User Data Policy, the Meta Platform Terms, the General Data Protection Regulation (GDPR), and the California Consumer Privacy Act (CCPA).
2. Data We Collect
2.1 Google Account Data (via Google Sign-In)
When you sign in with Google, we receive the following from Google OAuth:
- Your name and email address
- Your Google profile picture URL (not stored persistently)
- An authentication token used solely to verify your identity
Google Limited Use Policy: Our use of data obtained from Google APIs is limited to providing and improving DMChat. We do not use Google user data to develop, improve, or train generalized AI/ML models, show advertisements, or transfer data to third parties unless required by law.
2.2 Instagram / Meta API Data
When you connect your Instagram Business account, we request and process:
- instagram_business_basic: Your Instagram username, user ID, account type, and profile details
- instagram_business_manage_messages: Access to read and send direct messages on your behalf (for automation)
- instagram_business_manage_comments: Ability to read and reply to comments on your posts and reels
- instagram_business_content_publish: Publishing access (used only if you configure content automations)
- instagram_business_manage_insights: Engagement metrics to power your analytics dashboard
- Your connected post and reel IDs and captions (for automation targeting)
- OAuth long-lived access tokens (encrypted at rest, AES-256)
Meta Platform Policy Compliance: We only request permissions that are strictly necessary to operate the automation features you explicitly enable. We do not scrape, bulk-download, or store Instagram content beyond what is needed for your active automations.
2.3 Usage & Technical Data
- IP address (for security and fraud prevention only)
- Browser type and operating system
- Feature usage events (e.g., automation created, automation paused)
- Error logs and crash reports
3. How We Use Your Data
We use collected data only for the following purposes:
- To authenticate you and maintain your account session
- To execute the automation workflows you configure (comment replies, DM responses)
- To display your Instagram analytics and automation performance in your dashboard
- To send critical service and security emails (no marketing without opt-in)
- To detect, investigate, and prevent fraudulent or abusive use
- To comply with legal obligations
We do not: sell your data, use Instagram data for advertising, share your tokens with any third party, or use your content to train machine learning models.
4. Data Storage, Security & Retention
All data is stored on infrastructure located within the European Economic Area (EEA) and/or the United States, with encryption in transit (TLS 1.3) and at rest (AES-256).
Retention Periods
| Data Type | Retention |
|---|---|
| Account profile (name, email) | Until account deletion |
| Instagram access tokens | Until revoked or account deleted |
| Automation configurations | Until manually deleted or account deleted |
| Automation execution logs | 90 days rolling |
| Security/authentication logs | 30 days rolling |
| Billing records | 7 years (legal requirement) |
Meta Platform Data: Instagram platform data (usernames, post IDs, comment content) obtained via the Meta Graph API is not retained beyond the operational period of your active automations. When you disconnect your Instagram account or delete your DMChat account, all Meta platform data is immediately purged from our systems.
5. Data Sharing & Third Parties
We do not sell, rent, or share your personal data. We use the following sub-processors:
| Service | Purpose | Data Shared |
|---|---|---|
| Supabase / PostgreSQL | Database hosting | Account data, automation configs |
| Vercel | Application hosting & CDN | Server logs, IP addresses |
| Google OAuth | Authentication | Name, email (from Google) |
| Meta Graph API | Instagram integration | Access tokens, API calls |
| Stripe (if applicable) | Payment processing | Billing info only |
We may disclose data to law enforcement or regulatory authorities when legally required to do so.
6. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access: Request a copy of the data we hold about you
- Rectification: Correct inaccurate or incomplete data
- Erasure ("Right to be forgotten"): Request permanent deletion of your data
- Portability: Receive your data in a structured, machine-readable format
- Objection: Object to processing based on legitimate interest
- Withdraw Consent: Revoke Instagram or Google permissions at any time
To exercise any right, email us at privacy@dmchat.io. We will respond within 30 days.
7. Data Deletion Instructions
⚠️ Required by Meta Platform Policy — User Data Deletion
You can permanently delete all your DMChat data and revoke Instagram access using any of the following methods:
- In-App Deletion: Go to Dashboard → Settings → Security → Delete Account. This immediately and permanently deletes your account, all automation configurations, connected Instagram data, and access tokens from our systems.
- Instagram / Facebook Settings: Visit facebook.com/settings → Business Integrations and remove DMChat. We will receive a deletion callback from Meta and will purge all associated data within 24 hours.
- Email Request: Email privacy@dmchat.io with Subject: "Data Deletion Request". We will confirm deletion within 72 hours.
After deletion, we retain only anonymised billing records as required by applicable tax law (up to 7 years). No personally identifiable information from Meta APIs is retained after deletion.
8. Google API Services — Limited Use Disclosure
✓ Required by Google API Services User Data Policy
DMChat's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We only use Google data to provide authentication and user identification services within DMChat
- We do not transfer Google user data to third parties for advertising purposes
- We do not allow humans to read Google user data unless you explicitly grant us permission or it is required for security purposes
- We do not use Google data to develop, improve, or train generalized AI or ML models
9. Cookies & Tracking
We use only essential session cookies necessary to maintain your authenticated session. We do not use advertising trackers, third-party analytics pixels, or behavioral tracking cookies. You can clear cookies via your browser settings at any time, which will log you out.
10. Children's Privacy
DMChat is intended solely for users aged 18 and over, or the minimum legal age required to operate an Instagram Business account in your jurisdiction. We do not knowingly collect data from minors. If you believe a minor has registered, contact us immediately at privacy@dmchat.io.
11. Changes to This Policy
We may update this Privacy Policy to reflect changes in law, our practices, or platform capabilities. When we make material changes, we will notify you via email and display a notice in your dashboard at least 14 days before the change takes effect. Your continued use of DMChat after that date constitutes acceptance of the updated policy.
12. Contact & Data Controller
The data controller responsible for your personal data is DMChat.
Privacy inquiries: privacy@dmchat.io
Data deletion requests: privacy@dmchat.io
Response time: Within 30 days (72 hours for deletion requests)