Skip to content

Privacy Policy

Effective August 8, 2026

autoDM (“we”) sends automated replies to comments and direct messages on Instagram accounts that creators connect to the service. This policy explains what we store, why we store it, who we share it with, and how to have it deleted.

What we collect

From you, when you sign in

  • Your Google account identifier, email address and name.
  • We never receive or store your Google password. Sign-in happens on Google’s own pages.

From Instagram, when you connect an account

  • Your Instagram username and account ID.
  • An access token issued by Meta, used only to send the replies your own rules define. We store its expiry so we can tell you when reconnecting is needed.

From people who interact with your account

When a comment or direct message matches one of your rules, we store a record of it so you can see what the service did on your behalf:

  • The Instagram user ID of the person who commented or messaged you.
  • The text of their comment or message, truncated to 1,000 characters.
  • The ID of the comment or post involved.
  • The reply we sent, whether it succeeded, and any error returned by Instagram.

We do not read, store or process messages that do not match one of your active rules, and we do not build profiles of the people who contact you.

Usage and billing

  • Daily counts of replies sent, engagements and failures, used for your dashboard.
  • Your Stripe customer and subscription identifiers, plan and subscription status. Card details never reach our servers — payment happens entirely on Stripe’s checkout pages.

Why we collect it

  • To send the replies you configured — the core function of the service.
  • To show you logs and analytics of what was sent.
  • To enforce the reply and rule limits of your plan.
  • To bill you, and to keep your subscription status current.
  • To diagnose failures when a reply does not go out.

We do not sell your data, we do not sell the data of people who contact you, and we do not use any of it for advertising.

Who we share it with

Only the processors needed to run the service:

  • Meta / Instagram — to send replies and receive the events that trigger them.
  • Google — sign-in, and cloud hosting for our API.
  • Stripe — subscription payments.
  • Neon — managed PostgreSQL hosting for our database.
  • Vercel — hosting for this website.

We disclose data otherwise only where we are legally required to, and we will tell you unless we are prohibited from doing so.

How your data is separated from other creators’

Every record belongs to exactly one creator, and that separation is enforced by the database itself through row-level security policies — not only by application code. Your Instagram access token is used solely to deliver replies for rules on your own account.

How long we keep it

  • Reply logs and daily analytics are retained while your account is open.
  • When you disconnect Instagram, we delete the stored access token, username and account ID immediately.
  • When your account is deleted, your rules, logs, analytics and queued jobs are deleted along with it.
  • Records Stripe keeps for financial and tax compliance remain with Stripe under their own retention rules.

Deleting your data

You have two options, and neither requires our involvement to begin:

  • Disconnect Instagram — open Settings and choose Disconnect. This immediately removes your access token and Instagram identifiers, and stops all replies.
  • Delete everything — email support@classhai.com from the address you signed up with, with the subject “Delete my account”. We erase your account and all associated rules, logs and analytics within 30 days and confirm by email when it is done.

If you are someone who commented on or messaged a creator using autoDM and you want the record of that interaction removed, email us at support@classhai.com with the creator’s Instagram handle and we will remove it.

Your rights

Depending on where you live, you may have the right to access, correct, export or erase the personal data we hold about you, and to object to our processing of it. Email support@classhai.com and we will respond within 30 days. You may also complain to your local data protection authority.

Security

All traffic is encrypted in transit. Sessions use signed, HTTP-only cookies. Access tokens are stored in a managed database that is not reachable from the public internet. No system is perfectly secure, and we will notify affected creators without undue delay if we become aware of a breach involving their data.

Children

autoDM is not intended for anyone under 18, and we do not knowingly collect data from children. If you believe a child has given us data, email support@classhai.com and we will delete it.

Changes

If we make a material change we will update the effective date above and notify active creators by email before it takes effect.

Contact

Questions about this policy: support@classhai.com, or see our contact page.