How AutoDM Uses Instagram Data
Data Use Transparency & Meta Platform Allowed Usage Policy · Updated September 19, 2026
This policy explains how AutoDM (operated by CodaiPro) accesses, uses, stores, and protects data received through the official Meta Graph API and Instagram Platform. We strictly adhere to the Meta Platform Terms and Developer Policies.
Core Principles & Data Safeguards
Permissions Requested & Purpose of Use
What we access: Professional account username, Instagram user ID, profile avatar URL, account type, and public media list (posts and reels).
Why it is needed: When a creator connects their Instagram account, this permission allows AutoDM to authenticate the account, display the connected profile in their dashboard (/dashboard/accounts), and allow them to choose which specific post or reel an automation rule should monitor.
What we access: The specific comment ID and commenter's Instagram-scoped ID needed to reply — public confirmation via POST /{comment_id}/replies, and the 1:1 DM via POST /{ig-id}/messages with the comment as recipient.
Why it is needed: Enables creators to automatically deliver requested links, guides, and resources into a commenter's direct message inbox, within Meta's messaging windows for private replies to comments. One automated response per matching comment, per the creator's rule; no unsolicited bulk messaging.
What we access: Webhook events for comments on the creator's media and replies to their stories (comment ID, commenter's Instagram-scoped ID and username, comment text, timestamp), plus delivery records of the replies we post.
Why it is needed: To parse inbound comments for creator-defined keywords (e.g., “link”, “guide”) and post public confirmation replies (e.g., “Check your DMs! 📩”) informing the user that their requested resource has arrived in their inbox.
What AutoDM Never Collects
- No Passwords or Credentials: Authentication occurs exclusively via official Meta OAuth dialogs. We never request, handle, or store Instagram login passwords.
- No Private Message Inboxes: We do not read, aggregate, or store personal direct message history outside of the delivery status of private replies dispatched through our platform.
- No Audience Scraping: We do not scrape, harvest, or export follower lists or commenter profiles for marketing or external distribution.
Data Retention & User Deletion Rights
We retain data only as long as necessary to provide our service:
30-Day Webhook Purge
Unlinked webhook logs and transient event payloads are automatically purged by scheduled sweepers after 30 days. Aggregated delivery records follow the retention schedule in the Privacy Policy.
Account Deletion
Users can erase their account, connected tokens, automations, and delivery logs in Settings → Danger zone; requests are processed within 30 days, as detailed on the Data Deletion page. Backups and third-party processors (auth, hosting, error monitoring) clear copies on their own cycles.
To submit a data deletion request through Meta or check status, visit our Data Deletion Page.
Data Protection & Inquiries
For compliance questions, data access requests, or Meta audit inquiries, contact: privacy@codaipro.com (or support@codaipro.com for product support).