How AutoDM Uses Instagram Data

Data Use Transparency & Meta Platform Allowed Usage Policy · Updated September 19, 2026

This policy explains how AutoDM (operated by CodaiPro) accesses, uses, stores, and protects data received through the official Meta Graph API and Instagram Platform. We strictly adhere to the Meta Platform Terms and Developer Policies.

Core Principles & Data Safeguards

✓Zero Data Selling: We never sell, license, or broker user or follower data. Limited service providers (hosting, auth, database, error monitoring — see Privacy Policy §6) process data only to deliver the service, under contract.
✓Encrypted Credentials: All Meta access tokens are encrypted at rest using MultiFernet AES-256 and HKDF key derivation.
✓Explicit Consent: Automation is triggered by the commenter's own interactions with the creator's content (commenting a keyword, replying to a story), under rules the creator configured.
✓Strict Opt-Out: Replying “STOP” or “UNSUBSCRIBE” adds the commenter to a creator-wide suppression list; suppressed users receive no further automated replies unless they message first.

Permissions Requested & Purpose of Use

instagram_business_basicAccount Identification & Media Selection

What we access: Professional account username, Instagram user ID, profile avatar URL, account type, and public media list (posts and reels).

Why it is needed: When a creator connects their Instagram account, this permission allows AutoDM to authenticate the account, display the connected profile in their dashboard (/dashboard/accounts), and allow them to choose which specific post or reel an automation rule should monitor.

instagram_business_manage_messagesInstagram Private Replies (DMs)

What we access: The specific comment ID and commenter's Instagram-scoped ID needed to reply — public confirmation via POST /{comment_id}/replies, and the 1:1 DM via POST /{ig-id}/messages with the comment as recipient.

Why it is needed: Enables creators to automatically deliver requested links, guides, and resources into a commenter's direct message inbox, within Meta's messaging windows for private replies to comments. One automated response per matching comment, per the creator's rule; no unsolicited bulk messaging.

instagram_business_manage_commentsComment Webhooks & Confirmation Replies

What we access: Webhook events for comments on the creator's media and replies to their stories (comment ID, commenter's Instagram-scoped ID and username, comment text, timestamp), plus delivery records of the replies we post.

Why it is needed: To parse inbound comments for creator-defined keywords (e.g., “link”, “guide”) and post public confirmation replies (e.g., “Check your DMs! 📩”) informing the user that their requested resource has arrived in their inbox.

What AutoDM Never Collects

  • No Passwords or Credentials: Authentication occurs exclusively via official Meta OAuth dialogs. We never request, handle, or store Instagram login passwords.
  • No Private Message Inboxes: We do not read, aggregate, or store personal direct message history outside of the delivery status of private replies dispatched through our platform.
  • No Audience Scraping: We do not scrape, harvest, or export follower lists or commenter profiles for marketing or external distribution.

Data Retention & User Deletion Rights

We retain data only as long as necessary to provide our service:

30-Day Webhook Purge

Unlinked webhook logs and transient event payloads are automatically purged by scheduled sweepers after 30 days. Aggregated delivery records follow the retention schedule in the Privacy Policy.

Account Deletion

Users can erase their account, connected tokens, automations, and delivery logs in Settings → Danger zone; requests are processed within 30 days, as detailed on the Data Deletion page. Backups and third-party processors (auth, hosting, error monitoring) clear copies on their own cycles.

To submit a data deletion request through Meta or check status, visit our Data Deletion Page.

Data Protection & Inquiries

For compliance questions, data access requests, or Meta audit inquiries, contact: privacy@codaipro.com (or support@codaipro.com for product support).