Privacy policy
Last updated 31 August 2026. Effective from 31 August 2026.
This policy covers everyone who uses In Your DM, wherever they are. Where a country gives you stronger rights than this policy describes, those rights apply.
1. Who we are
In Your DM (operating entity to be confirmed), trading as In Your DM, established in India. Registered address: To be confirmed.
For data protection purposes we are the controller of your account data, and a processor acting on your instructions for the Instagram data your automations handle. That distinction matters: you decide what your automations say and who they reply to; we carry it out.
EU representative (GDPR Art. 27): To be appointed — see docs/OPEN-QUESTIONS.md. UK representative: To be appointed.
2. What we collect
Your account. Email address, an optional name, and a bcrypt hash of your password. If you sign in with Google we receive your email, name and Google account id. We never see your Google password.
From Instagram, when you connect an account. Meta sends us:
- your Instagram professional account id, username and profile picture URL
- the id of the Facebook Page linked to that account
- an access token, which we store encrypted with AES-256-GCM and never display, log or share
- for each comment on your posts: the comment id, its text, the post id, and the commenter's Instagram id and username
We do not receive or ask for your Instagram password. We do not read your existing direct messages. We do not access your followers list, your insights, or any post you have not connected an automation to.
People who comment on your posts. When someone triggers one of your automations we record their Instagram id, username, the keyword they matched and the time. They become a contact in your account. We collect nothing else about them and we never contact them except through the automation you configured.
Technical. Server logs including IP address and user agent, retained for 30 days for security and abuse investigation. Error reports via Sentry, configured to strip access tokens and message bodies.
Payments. Handled entirely by Dodo Payments, our merchant of record. We receive a customer reference, the plan, the amount and the country for tax purposes. We never receive or store card details.
3. Why we process it, and on what legal basis
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Running your account and your automations | Contract (6(1)(b)) |
| Sending the DMs and replies you configured | Contract (6(1)(b)) |
| Billing, invoicing and tax records | Legal obligation (6(1)(c)) |
| Security, abuse prevention, rate limiting | Legitimate interests (6(1)(f)) |
| Service emails about your account | Contract (6(1)(b)) |
| Product emails you can unsubscribe from | Consent (6(1)(a)) |
| Meeting Meta's platform obligations | Legal obligation and contract |
We do not sell personal data, and we do not share it for cross-context behavioural advertising. Under the CCPA/CPRA that means we have not sold or shared personal information in the preceding twelve months.
We do not use your data, or your commenters’ data, to train machine-learning models.
5. International transfers
Our servers are in the United States. If you are in the EEA, the UK or Switzerland, your data is transferred there under the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, or the Swiss addendum as applicable, together with supplementary technical measures: encryption in transit, encryption of access tokens at rest, and access limited to named administrators.
If you are in India, transfers are made in accordance with the Digital Personal Data Protection Act 2023 and any restrictions notified under it.
6. How long we keep it
- Raw webhook payloads from Meta: 7 days, then deleted automatically.
- Contacts, automations and send history: while your account is open.
- Server logs: 30 days.
- After you request deletion: erased within 30 days, and stopped from being used immediately.
- Billing and tax records: 7 years, because tax law requires it. These contain no Instagram data.
7. Your rights
Whoever and wherever you are, you can ask us to give you a copy of your data, correct it, delete it, restrict what we do with it, or object to it. A full JSON export is available in Settings without asking anyone, and deletion is a button.
| Where you are | Law | Rights |
|---|---|---|
| European Union / EEA | GDPR (Regulation 2016/679) | access, rectification, erasure, restriction, portability, objection |
| United Kingdom | UK GDPR and Data Protection Act 2018 | as GDPR |
| Switzerland | revised Federal Act on Data Protection (revFADP) | access, rectification, erasure, objection |
| California | CCPA as amended by CPRA | know, delete, correct, opt out of sale/sharing, limit sensitive data |
| Other US states | VCDPA, CPA, CTDPA, UCPA, TDPSA and equivalents | access, delete, correct, opt out of targeted advertising and sale |
| Canada | PIPEDA and Quebec Law 25 | access, correction, withdrawal of consent, portability |
| India | Digital Personal Data Protection Act 2023 | access, correction, erasure, grievance redressal, nomination |
| Australia | Privacy Act 1988 and the Australian Privacy Principles | access, correction, complaint |
| Brazil | LGPD (Lei 13.709/2018) | confirmation, access, correction, anonymisation, deletion, portability |
We answer within 30 days, and never charge for a first request. We will not discriminate against you for exercising a right.
Complaints. EEA: your national supervisory authority. UK: the Information Commissioner’s Office. India: the Data Protection Board, after raising a grievance with us at privacy@inyourdm.com. California: the California Privacy Protection Agency. We would rather you told us first.
8. Instagram data specifically
We use Meta’s official Instagram Graph API and nothing else. No browser automation, no scraping, no unofficial endpoints, no credential sharing.
Instagram platform data stays inside In Your DM. We do not transfer it to any other product, and we do not combine it with data from other sources to build a profile of a commenter.
If you remove In Your DM from your Facebook or Instagram settings, Meta notifies us and we delete the connected account’s data automatically. You are given a confirmation code and a status page.
10. Children
In Your DM is for businesses and creators and is not directed at children. You must be at least 18, or the age of majority where you live, to hold an account. We do not knowingly collect data from children, and we delete it if we discover it.
11. Security
- Instagram access tokens are encrypted at rest with AES-256-GCM; the key never touches the database.
- Passwords are hashed with bcrypt at cost 12 and are never recoverable.
- All traffic is TLS. Webhook payloads are verified by HMAC-SHA256 against the raw body.
- Access tokens are excluded from logs, error reports and data exports by column selection, not by filtering afterwards.
- Accounts lock for 15 minutes after 10 failed sign-in attempts.
If a breach affects your rights we will notify you and the relevant authority within 72 hours, as GDPR Art. 33/34 and equivalent laws require.
12. Changes
We will email you before any material change takes effect and post the new version here with a new date. Continuing to use the service after the effective date means the new version applies.