This Privacy Policy explains how QuickDM collects, uses, shares, and protects personal information when you use our website, dashboard, and Instagram automation services (the “Service”). By using the Service, you agree to this policy. If you do not agree, do not use the Service.
Meta / Instagram: Platform data is obtained only through the official Instagram Graph API (and related Meta OAuth). We do not scrape Instagram, do not use unofficial bots, and do not ask for Instagram passwords. Data handling for App Review is described in Section 3 below.
1. Who we are
QuickDM helps Instagram Business and Creator accounts automate comment keyword matching and direct message (DM) replies using Meta’s official APIs. Planned features (stories, live, multi-account, AI) are not live unless clearly marked otherwise.
Privacy requests:
privacy@quickdm.site
Support:
support@quickdm.site
Data deletion instructions (live link):
https://quickdm.site/data-deletion.html
2. Information you provide to QuickDM (account data)
- Name, email, password (stored hashed), and account profile fields.
- Payment-related data via Razorpay (we do not store full card numbers or UPI PINs on our servers).
- Content you configure: automation rules, keywords, public reply text, DM message templates, optional post/media IDs, and feature flags such as “require follow” (when enabled).
- Support emails and data-deletion requests.
3. Instagram / Facebook data (Graph API)
This section is separate from general account data. It describes platform data obtained when you connect Instagram via OAuth and authorize the app.
3.1 What we collect via the Instagram Graph API
Depending on permissions you grant and features you use, we may receive:
- Instagram user ID and username of the connected Business/Creator account.
- Profile name and profile picture URL (when returned by the API) for display in the dashboard.
- Access tokens and expiry metadata so we can call the Graph API on your behalf until you disconnect or tokens expire.
- Media / post IDs (and limited media metadata) needed to list posts and attach comment rules.
- Comments: comment ID, comment text, timestamp, and commenter identifiers (e.g. commenter Instagram user ID / username when provided) for keyword matching and optional public replies.
- Direct messages: content and metadata of automated DMs you configure and API responses (success/error) so we can send private replies / messages and log delivery status.
- Follow / relationship signals only if you enable a follow-gate style feature and the API exposes the required fields.
- Webhook event payloads Meta delivers to our servers for comment or messaging events (raw event stored for processing and debugging).
3.2 Why we collect each type of data (mapped to features)
- Account ID / username / profile picture: show which Instagram account is connected and prove ownership of the integration.
- Access tokens: authenticate official Graph API calls (list media, read comments, send DMs). Tokens are not used for advertising.
- Comment text + IDs: keyword matching (e.g. user comments “LINK”) and optional public comment reply.
- Commenter IDs: send a DM / private reply to the correct person and avoid duplicate DMs for the same comment.
- DM message content you configure: deliver the fixed template you set (e.g. a link or offer text).
- Follow-check fields (if enabled): decide whether to require a follow before sending a DM.
- Automation logs: show recent activity in the dashboard (what matched, whether DM was sent, error messages).
We do not sell or rent Instagram/Facebook platform data. We do not use Graph API data to build third-party advertising profiles.
3.3 Official API only — no scraping
All Instagram data processed by QuickDM flows through the official Instagram Graph API / Meta Login (OAuth) endpoints. We do not scrape the Instagram website or apps, and we do not use unofficial automation tools that violate Meta Platform Terms.
3.4 People who comment on or message your account
If someone comments on a post you automate, we process their public identifiers and comment text solely to run your rules and send the DM you configured. You are responsible for any notices or consents required for messaging people who interact with your account.
4. How we use information
- Operate comment → keyword match → auto DM and related dashboard features.
- Authenticate users, secure the Service, and process Razorpay payments.
- Send transactional email (account, billing, security).
- Comply with law and Meta Platform Terms; prevent abuse.
- Improve reliability using logs and error reports (not for selling data).
5. How we share information
- Processors: hosting, database, email, payment (Razorpay), error monitoring — under contracts, only to run QuickDM.
- Meta: when you use Instagram features under permissions you grant.
- Law / safety: when required by law or to protect rights.
We do not sell personal information. We do not share Instagram Graph API data with unrelated third parties for their independent marketing.
6. Data retention and deletion after automation
- Account data: kept while your account is open; deleted or anonymized within about 30 days after account deletion (billing records may be kept longer if required by law).
- Access tokens: stored encrypted/securely as practical; deleted or invalidated when you disconnect Instagram or delete your account.
- Comments / DM logs: retained to show “Recent activity” and debug delivery issues. They are not kept forever for marketing. Typical operational retention is on the order of 90 days for detailed automation logs, then deleted or aggregated, unless you delete your account sooner (then logs are removed with the account deletion process).
- Webhook raw payloads: processed promptly; retained only as needed for debugging and reliability, then deleted on a rolling schedule.
- Completing a single automation (match + DM) does not automatically wipe all history; deletion of stored logs follows this retention schedule or your full deletion request.
Request deletion anytime: Data Deletion Instructions or email privacy@quickdm.site.
7. Cookies and security
We use essential cookies for login and security, and may use limited analytics. Transport is HTTPS. Passwords are hashed. No method is 100% secure.
8. Your rights
Depending on your location, you may request access, correction, deletion, or export of your data. Contact privacy@quickdm.site. See also data-deletion.html.
9. Children’s privacy
The Service is not directed to children under 13 (or higher age required in your jurisdiction). We do not knowingly collect their data.
10. Changes and contact
We may update this policy and will change the “Last updated” date. Privacy: privacy@quickdm.site · Deletion: data-deletion.html