Last updated: July 19, 2026
Privacy Policy
AutoPilotDM ("we", "us", "our") provides Instagram DM automation software. This Privacy Policy explains what information we collect when you use AutoPilotDM, how we use it, and the choices you have.
1. Information We Collect
- Account information — name, email address, and authentication identifiers when you sign up.
- Workspace data — workspace names, team members, and settings you create inside the product.
- Instagram data — when you connect an Instagram Business account, we receive your Instagram user ID, username, access tokens, and the webhook events required to operate automations (comments, direct messages, story replies, message status).
- Automation content — triggers, keywords, and message templates you configure.
- Usage & diagnostic data — logs, error reports, and webhook delivery metadata used to operate and debug the service.
2. Instagram Permissions
When you connect Instagram, AutoPilotDM requests only the permissions required to run the automations you enable, which may include:
instagram_business_basic— read basic profile info.instagram_business_manage_messages— send and receive DMs on your behalf.instagram_business_manage_comments— read and reply to comments on your posts.instagram_business_content_publish(optional) — publish content when you use that feature.
We use these permissions only to power features you explicitly configure. You can revoke access at any time from Instagram's app settings or by disconnecting the account inside AutoPilotDM.
3. How We Use Your Data
- Provide, operate, and maintain the AutoPilotDM service.
- Execute the automations you create (e.g., reply to a comment, send a DM).
- Display analytics, logs, and inbox history inside your workspace.
- Communicate service updates, security notices, and support responses.
- Detect abuse and enforce our Terms of Service.
We do not sell your personal data or your Instagram audience data, and we do not use your message content to train third-party AI models.
4. Data Security
Access tokens are encrypted at rest using AES-256-GCM. Data is transmitted over TLS. Access to production systems is restricted to authorized personnel and protected by role-based access control and row-level security in our database. Webhook payloads are verified using X-Hub-Signature-256 before processing.
5. Third-Party Services
We rely on the following processors to run AutoPilotDM:
- Meta Platforms, Inc. — Instagram Graph API and webhooks.
- Supabase — authentication, database, and storage.
- Cloud hosting providers — application hosting and delivery.
These providers process data only on our instructions and under their own security and privacy commitments.
6. Data Retention
We retain your account and workspace data for as long as your account is active. Webhook and automation logs are retained for up to 90 days for troubleshooting. You can request deletion at any time — see our Data Deletion page.
7. Your Rights
Depending on your jurisdiction (including under GDPR and CCPA), you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To exercise these rights, email us at support@autopilotdm.app.
8. Children's Privacy
AutoPilotDM is not directed to children under 13 (or the equivalent minimum age in your country), and we do not knowingly collect data from them.
9. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated inside the product or by email.
10. Contact
Questions or requests? Contact us at support@autopilotdm.app.