✦AutoDMuz
Privacy Policy
Last updated: October 3, 2026
AutoDMuz ("we", "the Service") is a tool that lets businesses automatically reply to direct messages,
comments and story interactions on their own Instagram professional accounts. This policy explains what data
we process and why.
1. Data we collect
- Service users (businesses): email address, name, and a hashed password used to sign in.
- Connected Instagram accounts: account ID, username, display name, profile picture URL and an access
token issued by Instagram when the business connects its account via Instagram Login. Access tokens are
stored encrypted.
- Messages and comments received by connected accounts: when a person messages or comments on a
connected account, we receive the sender's Instagram-scoped ID, username and the message/comment text from
Instagram webhooks. We use it only to decide which automatic reply to send, and keep a short activity log
(first 300 characters of the text, timestamp, result) so the business can see what the Service did.
2. How we use the data
- To send the automatic replies the business configured (direct messages, private replies to comments,
public comment replies).
- To show the business statistics and an activity log of automatic replies.
- To keep the connection to Instagram working (token refresh, webhook subscription).
We do not sell data, do not use it for advertising, do not build profiles of the people who message connected
accounts, and do not share it with third parties except Meta Platforms (Instagram), which is required to
deliver the replies.
3. Retention
Activity log entries are deleted automatically after 30 days. Account data is kept while the Instagram account
stays connected. When a business disconnects an Instagram account, its token, rules and log are deleted
immediately.
4. Your rights and data deletion
- Businesses can disconnect an Instagram account at any time from the dashboard ("Disconnect"), which deletes
all related data.
- You can remove the app's access from Instagram: Settings → Website permissions → Apps and websites. We then
receive a deauthorization notice and stop processing.
- You can request deletion of your data via Instagram (we process Meta's data deletion callback) or by
emailing us. See Data deletion instructions.
5. Security
Data is stored on a private server; access tokens are encrypted at rest, passwords are hashed with scrypt, and
all traffic uses HTTPS.
6. Contact
Questions about this policy: taaamtv@gmail.com