Privacy policy

Last updated 31 August 2026. Effective from 31 August 2026.

This policy covers everyone who uses In Your DM, wherever they are. Where a country gives you stronger rights than this policy describes, those rights apply.

1. Who we are

In Your DM (operating entity to be confirmed), trading as In Your DM, established in India. Registered address: To be confirmed.

For data protection purposes we are the controller of your account data, and a processor acting on your instructions for the Instagram data your automations handle. That distinction matters: you decide what your automations say and who they reply to; we carry it out.

EU representative (GDPR Art. 27): To be appointed — see docs/OPEN-QUESTIONS.md. UK representative: To be appointed.

2. What we collect

Your account. Email address, an optional name, and a bcrypt hash of your password. If you sign in with Google we receive your email, name and Google account id. We never see your Google password.

From Instagram, when you connect an account. Meta sends us:

  • your Instagram professional account id, username and profile picture URL
  • the id of the Facebook Page linked to that account
  • an access token, which we store encrypted with AES-256-GCM and never display, log or share
  • for each comment on your posts: the comment id, its text, the post id, and the commenter's Instagram id and username

We do not receive or ask for your Instagram password. We do not read your existing direct messages. We do not access your followers list, your insights, or any post you have not connected an automation to.

People who comment on your posts. When someone triggers one of your automations we record their Instagram id, username, the keyword they matched and the time. They become a contact in your account. We collect nothing else about them and we never contact them except through the automation you configured.

Technical. Server logs including IP address and user agent, retained for 30 days for security and abuse investigation. Error reports via Sentry, configured to strip access tokens and message bodies.

Payments. Handled entirely by Dodo Payments, our merchant of record. We receive a customer reference, the plan, the amount and the country for tax purposes. We never receive or store card details.

3. Why we process it, and on what legal basis

PurposeLegal basis (GDPR Art. 6)
Running your account and your automationsContract (6(1)(b))
Sending the DMs and replies you configuredContract (6(1)(b))
Billing, invoicing and tax recordsLegal obligation (6(1)(c))
Security, abuse prevention, rate limitingLegitimate interests (6(1)(f))
Service emails about your accountContract (6(1)(b))
Product emails you can unsubscribe fromConsent (6(1)(a))
Meeting Meta's platform obligationsLegal obligation and contract

We do not sell personal data, and we do not share it for cross-context behavioural advertising. Under the CCPA/CPRA that means we have not sold or shared personal information in the preceding twelve months.

We do not use your data, or your commenters’ data, to train machine-learning models.

4. Who we share it with

Only the processors below, each under a written contract that limits them to acting on our instructions.

ProcessorPurposeLocation
Neon (Postgres hosting)Primary database — accounts, automations, contacts, send historyUnited States (us-east-1)
RailwayAlways-on webhook receiver and message workerUnited States (US-East)
Upstash / Railway RedisJob queue, rate-limit counters, de-duplication keysUnited States (US-East)
VercelDashboard hosting and edge deliveryUnited States (iad1)
ResendTransactional email (account notices, withdrawal acknowledgements)United States
SentryError monitoring. Configured to scrub tokens and message bodies.United States / European Union
Dodo PaymentsMerchant of record. Independently controls payment and tax data; we never see full card details.United States / European Union
Meta Platforms, Inc.Source of Instagram comment and messaging data, and the destination for messages you send.Global

Full list with transfer mechanisms: sub-processors. We will give notice before adding a new one.

We may also disclose data where legally compelled, and we will tell you unless the law forbids it.

5. International transfers

Our servers are in the United States. If you are in the EEA, the UK or Switzerland, your data is transferred there under the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, or the Swiss addendum as applicable, together with supplementary technical measures: encryption in transit, encryption of access tokens at rest, and access limited to named administrators.

If you are in India, transfers are made in accordance with the Digital Personal Data Protection Act 2023 and any restrictions notified under it.

6. How long we keep it

  • Raw webhook payloads from Meta: 7 days, then deleted automatically.
  • Contacts, automations and send history: while your account is open.
  • Server logs: 30 days.
  • After you request deletion: erased within 30 days, and stopped from being used immediately.
  • Billing and tax records: 7 years, because tax law requires it. These contain no Instagram data.

7. Your rights

Whoever and wherever you are, you can ask us to give you a copy of your data, correct it, delete it, restrict what we do with it, or object to it. A full JSON export is available in Settings without asking anyone, and deletion is a button.

Where you areLawRights
European Union / EEAGDPR (Regulation 2016/679)access, rectification, erasure, restriction, portability, objection
United KingdomUK GDPR and Data Protection Act 2018as GDPR
Switzerlandrevised Federal Act on Data Protection (revFADP)access, rectification, erasure, objection
CaliforniaCCPA as amended by CPRAknow, delete, correct, opt out of sale/sharing, limit sensitive data
Other US statesVCDPA, CPA, CTDPA, UCPA, TDPSA and equivalentsaccess, delete, correct, opt out of targeted advertising and sale
CanadaPIPEDA and Quebec Law 25access, correction, withdrawal of consent, portability
IndiaDigital Personal Data Protection Act 2023access, correction, erasure, grievance redressal, nomination
AustraliaPrivacy Act 1988 and the Australian Privacy Principlesaccess, correction, complaint
BrazilLGPD (Lei 13.709/2018)confirmation, access, correction, anonymisation, deletion, portability

We answer within 30 days, and never charge for a first request. We will not discriminate against you for exercising a right.

Complaints. EEA: your national supervisory authority. UK: the Information Commissioner’s Office. India: the Data Protection Board, after raising a grievance with us at privacy@inyourdm.com. California: the California Privacy Protection Agency. We would rather you told us first.

8. Instagram data specifically

We use Meta’s official Instagram Graph API and nothing else. No browser automation, no scraping, no unofficial endpoints, no credential sharing.

Instagram platform data stays inside In Your DM. We do not transfer it to any other product, and we do not combine it with data from other sources to build a profile of a commenter.

If you remove In Your DM from your Facebook or Instagram settings, Meta notifies us and we delete the connected account’s data automatically. You are given a confirmation code and a status page.

9. Cookies

We set one cookie: your session token, which is strictly necessary to keep you signed in. It is httpOnly, secure and sameSite=lax.

We run no advertising cookies, no cross-site trackers and no third-party analytics on this site. That is why there is no consent banner: under the ePrivacy Directive a strictly necessary cookie does not require consent, and we do not set any other kind.

10. Children

In Your DM is for businesses and creators and is not directed at children. You must be at least 18, or the age of majority where you live, to hold an account. We do not knowingly collect data from children, and we delete it if we discover it.

11. Security

  • Instagram access tokens are encrypted at rest with AES-256-GCM; the key never touches the database.
  • Passwords are hashed with bcrypt at cost 12 and are never recoverable.
  • All traffic is TLS. Webhook payloads are verified by HMAC-SHA256 against the raw body.
  • Access tokens are excluded from logs, error reports and data exports by column selection, not by filtering afterwards.
  • Accounts lock for 15 minutes after 10 failed sign-in attempts.

If a breach affects your rights we will notify you and the relevant authority within 72 hours, as GDPR Art. 33/34 and equivalent laws require.

12. Changes

We will email you before any material change takes effect and post the new version here with a new date. Continuing to use the service after the effective date means the new version applies.