EnglishO‘zbekcha

Privacy Policy

Last updated: 29 July 2026

Instagram AI Agent (“the Service”) helps Instagram professional account owners automate replies to direct messages and comments, and schedule content. This policy explains exactly what data we handle, why, and how you can remove it.

The Service is operated by Mirobid Usmonov. Contact: usmonovm007@gmail.com.

1. Who the data belongs to

There are two groups of people in this Service:

  • Customers — people who create an account with us and connect their own Instagram professional account.
  • End users— people who message or comment on our customers’ Instagram accounts. We process their data on behalf of the customer, who remains the controller of that conversation.

2. What we collect

DataSourceWhy
Email, name, password hashYou, at sign-upTo create and secure your account
Instagram profile: username, account type, follower and media counts, profile picture URLInstagram API, after you authoriseTo show which account is connected and its status
Instagram access tokenInstagram, after you authoriseTo act on your behalf. Stored encrypted with AES-256-GCM, never shown in our interface or logs
Direct messages: sender ID, username, message text, timestampsInstagram webhooks and APITo detect what a person asked and send the reply you configured
Comments: author, text, media ID, timestampsInstagram webhooks and APITo apply your comment rules (reply, hide, private reply)
Content you schedule: captions, media URLs, publish timesYouTo publish posts at the time you choose
Operational logs: request outcomes, error codes, timestampsAutomaticTo diagnose failures and enforce rate limits. Tokens and message bodies are excluded

We do not collect payment card details, government identifiers, location data, or contact lists. We do not buy data from third parties and we do not build advertising profiles.

3. What we do not do

  • We do not sell or rent your data to anyone.
  • We do not use your messages or comments to train machine-learning models.
  • We do not access accounts you have not connected, and we cannot read conversations that Instagram does not expose to us.
  • We do not send unsolicited messages. Instagram only permits a reply within 24 hours of a person messaging you first, and the Service enforces this in code.

4. Automated replies

When automated replies are enabled, the first message in a conversation states that the reply is automated, and offers a way to reach a human. This is required by Meta and by law in some countries.

If you enable the optional AI reply mode, the text of the incoming message and your configured instructions are sent to a third-party model provider (OpenRouter) to generate a reply. That provider processes the text to return a response. If AI mode is off — the default — no message content leaves our servers.

5. Who else processes the data

ProcessorPurposeWhat they receive
Meta PlatformsThe Instagram API itselfThe requests we make on your behalf
Our hosting providerRunning the servers and databaseStored data, at rest on their infrastructure
OpenRouterAI reply generation — only if you enable itMessage text and your instructions

6. How long we keep it

  • Account data — until you delete your account.
  • Messages and comments — 12 months, then deleted automatically. You can shorten this in settings.
  • Access tokens — deleted immediately when you disconnect the Instagram account or remove the app from Instagram.
  • Operational logs — 30 days.

7. Security

  • Instagram access tokens are encrypted at rest (AES-256-GCM).
  • Passwords are hashed with bcrypt; we never store them in plain text.
  • Sessions use opaque tokens; only a SHA-256 hash is stored, so a database leak cannot be replayed as a login.
  • Incoming webhooks are verified against Meta’s X-Hub-Signature-256 before being processed.
  • Transport is HTTPS only.

No system is perfectly secure. If we discover a breach affecting your data, we will notify you without undue delay.

8. Your rights

You can, at any time:

  • See the data held about you, from your dashboard.
  • Correct or export it.
  • Delete it — see Data Deletion.
  • Withdraw Instagram access, either in our dashboard or from Instagram under Settings → Apps and websites. Revoking there also tells us to discard your token.

To exercise any of these, or to complain, write to usmonovm007@gmail.com. We aim to respond within 7 days.

9. Children

The Service is for businesses and creators and is not directed at people under 18. We do not knowingly collect their data.

10. Changes

If we change this policy in a way that materially affects you, we will tell you by email before the change takes effect. The date at the top always reflects the current version.