Privacy Policy
How DmBot collects, uses, and protects information.
Effective date: July 6, 2026 · Application: https://staging.dmbot.co · Marketing site: https://dmbot.co
Who we are
DmBot is an Instagram automation service operated by Amaran LLC. This Privacy Policy describes how we handle information when you use the DmBot web application to connect a professional Instagram account and configure comment-to-DM automations.
Information we collect
- Account information: email address and profile details supplied when you create a DmBot login.
- Workspace and automation configuration: workspace names, automation names, keywords, selected post identifiers, trigger settings, and private reply message text you enter.
- Instagram professional account information: when you connect Instagram, we receive and store account identifiers, username, account type, and profile picture URL returned by Instagram.
- Instagram media metadata: post identifiers, captions, media types, and thumbnail or media URLs used to display post selection in the automation builder. We do not maintain a separate long-term media catalog beyond what is needed for configuration.
- Webhook data: when Instagram sends comment or messaging notifications, we process event identifiers, timestamps, and comment text needed to evaluate automations. Messaging events may be recorded for processing integrity even when a product feature is not yet active.
- Operational logs: limited technical diagnostics without access tokens, signed requests, or full webhook payloads.
Instagram access tokens
Instagram access tokens are encrypted at rest using AES-256-GCM before storage. Tokens are decrypted only on the server to perform Instagram API operations you request, such as loading posts or sending an automation reply when that capability is enabled for your environment.
How we use information
- Authenticate you and provide the DmBot service.
- Connect and maintain your Instagram professional account.
- Display Instagram posts so you can configure selected-post automations.
- Evaluate incoming comments against your keyword and post rules when an automation is active.
- Send a private reply through Instagram when an automation is active and the production transport is enabled for your workspace.
- Protect the service through webhook verification and audit logs.
Comment-to-DM automations
When you activate a comment-to-DM automation, DmBot processes comments that match your configured keywords and post scope. If delivery is enabled for your environment, DmBotsends the private reply message you authored to the commenter through Instagram's messaging APIs. Staging and certain restricted environments may record automation matches without sending a real Instagram message.
How we share information
We do not sell personal information. We share information only as needed to operate the service:
- Meta / Instagram: when you connect Instagram or when an enabled automation sends a private reply, data is transmitted to Meta using Instagram Platform APIs.
- Hosting and database providers: application infrastructure identifiable from the repository includes Vercel for hosting and Supabase/PostgreSQL for authentication and data storage.
- Service providers: other subprocessors may be added for billing or infrastructure; this policy will be updated when they are introduced.
Security
We use administrative, technical, and organizational safeguards including encrypted token storage, workspace isolation, webhook signature verification, and least-privilege server access. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
Retention
- Instagram access tokens are removed when you disconnect Instagram or when Meta sends a deauthorization or data-deletion request we process.
- Comment text in automation dispatch records may be retained for a limited period (currently up to 90 days) for operational and duplicate-protection purposes.
- Data-deletion request records may be retained for compliance auditing after completion.
- Integration audit events may be retained for security and fraud prevention.
Your choices and rights
- Disconnect Instagram at any time from the Integrations page.
- Pause or delete automations you no longer want to run.
- Request deletion of Instagram-related data through Meta's data deletion flow or by contacting us using the Support page.
- Check the status of a Meta-initiated deletion request using the confirmation code and status page described on our Data Deletion page.
Contact
Amaran LLC operates DmBot. For privacy, data deletion, or support questions, contact us using the information on our Support page.
Email: support@dmbot.co
Policy changes
We may update this policy from time to time. When we make material changes, we will update the effective date above and provide additional notice when appropriate.