Legal
Privacy Policy
Last updated 12 August 2026
DMParrot sends Instagram direct messages on your behalf, using automations that you or your AI agent create. This policy explains what we collect, why we collect it, and how you remove it.
What we collect
Account data. When you sign in with Google we store your Google account id, email address, and name. We use this to identify your account and to contact you about the service.
Instagram connection data. When you connect Instagram we store a Facebook Page access token, your Page id and name, and your Instagram professional account id and username.
Automation data. We store the flows, triggers, keywords, message content, tags, and contact fields that you or your agent create.
Contact data. When a person comments on your post or sends you a direct message, we store their Instagram-scoped id, their username, the message or comment text that triggered a flow, and any tags or fields you set on them.
Delivery logs. We store the id, time, and result of each message we send, and the id of each webhook event we receive. We use these to prevent duplicate sends and to show you delivery history.
Billing data. Stripe processes your payment. We store your Stripe customer id and subscription status. We never see or store your card number.
How we use it
We use your data to run the automations you configure, to show you the dashboard, to bill you, and to support you. We do not sell your data. We do not use your data or your contacts data to train machine learning models. We do not send marketing messages to your Instagram contacts.
Instagram and Meta data
When you connect Instagram, DMParrot receives a Facebook Page access token and identifiers for your Page and Instagram professional account. We use these solely to subscribe to Instagram webhooks and to send direct messages and private replies that you configure. We store message delivery logs and webhook event ids to prevent duplicate sends. We do not sell this data.
We only send messages in response to a person who contacts you first, which means a comment on your content or a direct message to you. We send within the messaging windows that Meta permits. We do not send unsolicited messages.
You can disconnect Instagram in the dashboard at any time. Disconnecting deletes the stored connection and its access tokens immediately.
Who we share it with
We use these processors to run the service: Cloudflare for hosting, storage, and the database; Meta for Instagram messaging; Google for sign-in; and Stripe for payment. We share only the data that each one needs. We do not share your data with anyone else, except where the law requires it.
How long we keep it
We keep your account data while your account is open. We keep delivery logs and webhook event ids for 12 months, then delete them. We delete Instagram connection data as soon as you disconnect Instagram.
Security
We hold access tokens and secrets encrypted at rest. We transmit all data over HTTPS. Only the account that owns a flow can read or change it.
Your rights
You can ask us for a copy of your data, ask us to correct it, or ask us to delete it. Write to the support address below. We answer within 30 days.
How to delete your data
To remove your Instagram connection only, open the dashboard and select disconnect. We delete the stored connection and tokens straight away.
To delete your whole account, email support@dmparrot.com from the Google account address that you signed up with. We delete your account rows, Meta connection tokens, flows, contacts, and delivery logs within 30 days, and we confirm by email when the deletion is complete.
Contact
Email support@dmparrot.com with any question about this policy or about your data.