Privacy Policy
Last updated: August 30, 2026
1. Who we are
DaMi is a service that, on behalf of a business client, automatically replies to Instagram messages and comments to move leads toward a deal. The service is operated by a sole proprietor registered in the Russian Federation (details in the “Data controller” section). This policy explains what data we process, why, who we share it with, and how to have it deleted. For any question about data, email support@damiagent.com — it is our only official address, and we reply within 30 days.
2. Whose data we process
Three groups. (a) The business client and its operators — the people who create a dashboard account and connect an Instagram account. (b) People who message that connected account (“leads”) — Instagram users who wrote to the business in Direct or left a comment under its post. (c) Technical data about how the service runs. For lead data we act on behalf of and in the interest of the business client: the business decides the purpose of the conversation, we provide the tool. For dashboard operator data we act as the data controller ourselves.
3. What data we process
From the business client: the operator's email (for passwordless sign-in links), their role in the dashboard, language preference, and the “sales context” — the text about the business that you enter yourself and that the agent relies on. Through the official Instagram Graph API (Instagram Login for Business): the content of Direct messages between a lead and the connected business account; comments under the business account's posts; usernames, IDs, and public Instagram profile data; metadata of the posts a conversation relates to; and the connected account's access tokens (stored encrypted with Fernet/AES). Technical data: service logs containing event and account identifiers, used to diagnose failures. We do NOT ask for or store Instagram passwords — connection happens solely through Meta's OAuth consent. We do not collect payment card details through the website and do not intentionally process special categories of personal data; if a lead sends such information in a conversation, it is stored as part of that conversation and deleted together with it.
4. How data reaches us
The business client connects their Instagram Business or Creator account through Meta OAuth and grants the permissions themselves. After that, Meta sends webhook events (new messages and comments) to our server; every event's signature is verified before it is processed. We generate a reply and send it back through the Instagram Graph API. We do no scraping, no parsing of third-party profiles, and no automation through unofficial Instagram interfaces.
5. Why we process data, and on what basis
The sole purpose of processing is to deliver the auto-reply service: generate a relevant reply to a lead, carry the conversation toward a target action (call, meeting, purchase, booking), and show the operator the conversation history in their dashboard; this includes a single reminder to a person who stopped replying, sent inside Instagram's 24-hour window. The legal basis for operator data is performance of the contract with the business client; for lead data it is the instruction of the business client, who is responsible for the lawfulness of communicating with their own customers; for service logs it is our legitimate interest in keeping the service running and secure. We do not sell data, do not share it with ad networks, do not build profiles for third-party targeting, and never use one client's data for the benefit of another.
6. We do not train AI models on your data
Neither conversation content, nor sales context, nor any other data obtained through the Meta platform is used to train, retrain, or fine-tune machine learning models — not by us and not by our vendors. Under Anthropic's API terms, data sent through the API is not used to train their models. This is a direct requirement of the Meta Platform Terms, and we comply with it.
7. How long we keep data
Postgres is the source of truth: conversations, messages, and comments are stored while the business client's account is connected, and are deleted when the app is disconnected, when the account is removed in the dashboard, or upon a data deletion request. Deletion is irreversible (hard delete): related records are removed by cascade, not flagged as deleted. Redis is a temporary cache of the most recent conversation messages with a 24-hour TTL (matching Meta's 24-hour messaging window), plus a cache of Instagram media metadata kept for 4 days; both expire automatically. Sign-in links live for 24 hours, and the token itself is never stored — only its hash. Service logs are kept for a limited time and used only for diagnostics.
8. Who we share data with
We share the minimum necessary data with vendors without whom the service cannot work: Anthropic (Claude API, USA) — conversation text and sales context to generate a reply; Meta Platforms (Instagram Graph API, USA/Ireland) — to receive and send messages and comments; an email provider (SMTP) — to deliver sign-in links and operational notifications to the operator; Hetzner (hosting, EU) — servers and database. Each party processes data under its own privacy policy. Some vendors are located outside the operator's country of registration, so a cross-border transfer of data takes place — by using the service you accept this as a necessary condition of its delivery. We do not share data with third parties for advertising, and we disclose it to public authorities only to the extent expressly required by law.
9. Cookies and analytics
The damiagent.com website carries no advertising pixels, trackers, or web analytics — it sets no cookies. The app.damiagent.com dashboard uses strictly functional cookies: a signed session cookie ig_bot_session (HttpOnly, 30 days), without which signing in is impossible, and a lang cookie holding the chosen interface language (1 year). Neither is used to track you across other websites.
10. How we protect data
All traffic runs over HTTPS with automatically renewed certificates. Instagram access tokens are stored encrypted, and the encryption key is not kept in the code. There are no passwords at all: dashboard sign-in uses a one-time link, and Instagram access goes through OAuth on Meta's side. Every incoming Meta event is verified by its HMAC signature, and Meta's data deletion requests by their signed_request signature. Access to conversations is limited to operators of the dashboard account that owns the connected Instagram account. No one can guarantee absolute security; if a breach affects your data, we will notify you at the email address we hold.
11. Your rights
You may request information about what data of yours we process, ask for it to be corrected or deleted, withdraw consent and request that processing stop, and lodge a complaint with the supervisory authority where you live. Send requests to support@damiagent.com — we respond within 30 days at the latest. If you are a lead who messaged a business, you may also contact that business directly: it decides the content of the conversation. We will honour a deletion request in any case, but will inform the business client that the conversation has been removed.
12. Data deletion
Data is deleted automatically when a user disconnects our app in Instagram settings, as well as upon an explicit data deletion request via Meta. The dashboard also offers self-service deletion: disconnect the account, delete the account together with its conversation history, or delete the whole dashboard account. You may also request manual deletion at any time by emailing support@damiagent.com. Details and status check are on the “Data Deletion” page.
13. Children
The service is built for businesses and is not directed at children. Only adults acting on behalf of a business may create a dashboard account. We do not knowingly collect data of anyone under 13; if such data reaches us through a conversation, we will delete it upon request at support@damiagent.com.
14. Changes to this policy
We may update this policy — for example, when adding a vendor or changing what data we handle. The current version is always published on this page, with the last-updated date at the top. We notify active business clients by email about material changes.
15. Jurisdiction and contact
The controller is a sole proprietor registered in the Russian Federation; processing is carried out in accordance with applicable law, including Federal Law No. 152-FZ “On Personal Data”. For any question about your data, including access and deletion requests, email support@damiagent.com.