Privacy Policy
Last updated: 29 July 2026
Instagram AI Agent (“the Service”) helps Instagram professional account owners automate replies to direct messages and comments, and schedule content. This policy explains exactly what data we handle, why, and how you can remove it.
The Service is operated by Mirobid Usmonov. Contact: usmonovm007@gmail.com.
1. Who the data belongs to
There are two groups of people in this Service:
- Customers — people who create an account with us and connect their own Instagram professional account.
- End users— people who message or comment on our customers’ Instagram accounts. We process their data on behalf of the customer, who remains the controller of that conversation.
2. What we collect
| Data | Source | Why |
|---|---|---|
| Email, name, password hash | You, at sign-up | To create and secure your account |
| Instagram profile: username, account type, follower and media counts, profile picture URL | Instagram API, after you authorise | To show which account is connected and its status |
| Instagram access token | Instagram, after you authorise | To act on your behalf. Stored encrypted with AES-256-GCM, never shown in our interface or logs |
| Direct messages: sender ID, username, message text, timestamps | Instagram webhooks and API | To detect what a person asked and send the reply you configured |
| Comments: author, text, media ID, timestamps | Instagram webhooks and API | To apply your comment rules (reply, hide, private reply) |
| Content you schedule: captions, media URLs, publish times | You | To publish posts at the time you choose |
| Operational logs: request outcomes, error codes, timestamps | Automatic | To diagnose failures and enforce rate limits. Tokens and message bodies are excluded |
We do not collect payment card details, government identifiers, location data, or contact lists. We do not buy data from third parties and we do not build advertising profiles.
3. What we do not do
- We do not sell or rent your data to anyone.
- We do not use your messages or comments to train machine-learning models.
- We do not access accounts you have not connected, and we cannot read conversations that Instagram does not expose to us.
- We do not send unsolicited messages. Instagram only permits a reply within 24 hours of a person messaging you first, and the Service enforces this in code.
4. Automated replies
When automated replies are enabled, the first message in a conversation states that the reply is automated, and offers a way to reach a human. This is required by Meta and by law in some countries.
If you enable the optional AI reply mode, the text of the incoming message and your configured instructions are sent to a third-party model provider (OpenRouter) to generate a reply. That provider processes the text to return a response. If AI mode is off — the default — no message content leaves our servers.
5. Who else processes the data
| Processor | Purpose | What they receive |
|---|---|---|
| Meta Platforms | The Instagram API itself | The requests we make on your behalf |
| Our hosting provider | Running the servers and database | Stored data, at rest on their infrastructure |
| OpenRouter | AI reply generation — only if you enable it | Message text and your instructions |
6. How long we keep it
- Account data — until you delete your account.
- Messages and comments — 12 months, then deleted automatically. You can shorten this in settings.
- Access tokens — deleted immediately when you disconnect the Instagram account or remove the app from Instagram.
- Operational logs — 30 days.
7. Security
- Instagram access tokens are encrypted at rest (AES-256-GCM).
- Passwords are hashed with bcrypt; we never store them in plain text.
- Sessions use opaque tokens; only a SHA-256 hash is stored, so a database leak cannot be replayed as a login.
- Incoming webhooks are verified against Meta’s
X-Hub-Signature-256before being processed. - Transport is HTTPS only.
No system is perfectly secure. If we discover a breach affecting your data, we will notify you without undue delay.
8. Your rights
You can, at any time:
- See the data held about you, from your dashboard.
- Correct or export it.
- Delete it — see Data Deletion.
- Withdraw Instagram access, either in our dashboard or from Instagram under Settings → Apps and websites. Revoking there also tells us to discard your token.
To exercise any of these, or to complain, write to usmonovm007@gmail.com. We aim to respond within 7 days.
9. Children
The Service is for businesses and creators and is not directed at people under 18. We do not knowingly collect their data.
10. Changes
If we change this policy in a way that materially affects you, we will tell you by email before the change takes effect. The date at the top always reflects the current version.