Legal

Privacy Policy

This policy explains how SOCIAL DM AI SYSTEM handles information when businesses use our AI-powered Instagram sales inbox and when Instagram users message a connected business.

Effective date: September 1, 2026

1. Introduction

SOCIAL DM AI SYSTEM provides businesses with workspaces for connecting their own professional Instagram accounts, managing direct-message conversations, configuring business knowledge, and generating AI-assisted replies. We are not endorsed by Meta or Instagram.

This policy distinguishes between a business customer (the account holder and its workspace members) and an Instagram user who sends a message to that business. The business controls its connected account and decides how it uses the service; depending on the circumstances, it may have its own privacy obligations to the Instagram users it communicates with.

2. Information we collect

  • Account and workspace information: email address, password-derived authentication data, email-verification status, workspace name, membership, role, and account timestamps.
  • Instagram connection information: identifiers and metadata for the professional Instagram account a business connects, connection status, OAuth authorization records, and an encrypted Instagram access token.
  • Messages and conversations: inbound Instagram text messages made available through the connection; outbound replies sent by the service; message, sender, account, and conversation identifiers; timestamps; delivery-processing status; conversation status; unread count; and whether AI or a person is handling the conversation. The service also receives authenticated Instagram webhook event data needed to process incoming messages.
  • Customer or contact information: the Instagram user identifier associated with someone who messages a connected business and conversation history. Profile fields may be stored if a supported integration supplies them; the current messaging flow may not supply a username, display name, or profile image.
  • Train Your AI and business information: business name, description, website, phone, email, products, services, descriptions, prices, currencies, inventory details, SKUs, product aliases or keywords, variations, options, FAQs, and publication settings entered by a business.
  • Service and security information: session records, CSRF tokens, request and operational logs, provider/job status, fixed failure codes, and technical information needed to secure, operate, diagnose, and prevent abuse of the service.

3. How we use information

We use information to create and authenticate accounts; organize workspace access; connect, display, and disconnect business-owned Instagram accounts; receive, store, and present conversations; send replies; let a person take over from AI; provide business-knowledge configuration; operate background message and reply jobs; secure and troubleshoot the service; and comply with applicable obligations.

The application may use conversation history and relevant published business knowledge to generate a suggested or automated response. Configuration and safety controls determine whether an automated reply is eligible to be sent. AI output can be inaccurate or incomplete, and the connected business remains responsible for reviewing its configuration and its communications.

4. Meta and Instagram

A business chooses to connect its own eligible Instagram professional account through Meta's authorization flow. Once connected, Meta may make account identifiers, webhook events, messages, and related metadata available so we can provide the inbox and reply service. We send outbound message content and recipient identifiers to Meta when delivering a reply. Meta processes information under its own terms and privacy policies. Disconnecting removes the active local connection and stored access-token ciphertext; it does not by itself delete conversation records already stored by this service or information retained by Meta.

5. AI and other service providers

We may provide the minimum information needed to vendors that help operate the service. The application currently includes an OpenAI integration for reply generation; relevant recent conversation content, system instructions, and relevant business knowledge may be sent to OpenAI when generation is enabled. Meta processes connection and messaging data. The application uses a PostgreSQL database and supports deployment using web-hosting, API-hosting, database, and email infrastructure selected by the operator. Exact production providers must be confirmed before launch and may change as the service evolves.

Providers process information on our behalf or under their own applicable terms. We do not authorize them to use information for unrelated purposes beyond the arrangements governing their services.

6. Cookies and sessions

We use an essential, secure-session cookie to keep business users signed in. The session is opaque, stored server-side, revocable, and sent as an HttpOnly cookie. We also use a CSRF cookie and matching request token to protect state-changing actions. These technologies are required for account security and core service operation; the repository does not currently implement advertising or cross-site tracking cookies.

7. How we share information

We may share information with the connected business and authorized workspace members; with Meta to connect accounts and exchange messages; with AI and infrastructure providers as needed to provide the service; when required by law or a valid legal process; to protect rights, safety, and service integrity; or as part of a business transaction, subject to appropriate safeguards. We do not sell personal information.

8. Security

We use administrative, technical, and organizational safeguards designed for the service, including workspace-scoped authorization, password hashing, revocable sessions, CSRF protection, webhook signature verification, rate limiting, and encrypted storage of Instagram access tokens. No system or transmission method is completely secure, so we cannot guarantee absolute security.

9. Retention

We retain account, workspace, business knowledge, connection, customer, conversation, message, job, and security records for as long as reasonably needed to provide and protect the service, meet legal obligations, resolve disputes, and enforce agreements. Retention can vary by record type and operational need. Disconnecting Instagram destroys the locally stored access-token ciphertext, but other records are not automatically erased. Final production retention schedules are still subject to owner review.

10. Access and deletion requests

Business customers may request access, correction, or deletion of their account or workspace information by contacting us through the support contact provided to your business account. Requests should identify the account email and workspace, but should never include a password or Instagram access token.

Instagram users who messaged a connected business may contact that business directly or contact us through the same channel. To help locate the correct records, include the connected business's Instagram handle and your Instagram identifier or handle, plus an approximate conversation date. We may need to verify the requester and coordinate with the connected business. We will evaluate requests under applicable law and may retain limited information where legally permitted or required. Requests concerning information held independently by Meta must be directed to Meta.

11. Children's privacy

The service is intended for businesses and is not directed to children. Business-account users must be legally able to enter these Terms. If we learn that a child provided personal information directly to us in circumstances requiring parental consent, we will take appropriate steps to delete it. Businesses remain responsible for using Instagram messaging lawfully with their audiences.

12. Changes to this policy

We may update this policy as the service or legal requirements change. We will post the updated policy here, revise its effective date, and provide additional notice when required.

13. Contact

For privacy questions or requests, contact SOCIAL DM AI SYSTEM through the support contact provided to your business account.