Official Policy · Legal & Security

Privacy Policy

Effective Date & Last Updated: September 11, 2026

This Privacy Policy explains how AutoDM ("we", "our", "us", or the "Service"), operated under CodaiPro (codaipro.com), collects, uses, stores, protects, and discloses information when you access or use our web platform at autodm.codaipro.com, our backend APIs, and our integrations with the Meta Platforms, Inc. ecosystem (including the Instagram Graph API and Messenger Platform).

🛡️ Core Privacy Commitments

  • ✓Zero Sale of Data: We never sell, monetize, or broker your personal or follower data. Service providers in §6 process data only to deliver the service, under contract.
  • ✓Encrypted Credentials: Meta access tokens are encrypted at rest using AES-256 / Fernet.
  • ✓Inbox Privacy: We do not read or store your private inbox conversations. For automations you configure, we store only the delivery record (timestamp, recipient ID, status) — never message bodies.
  • ✓Deletion on request: You can erase your account and stored tokens at any moment from Settings → Danger zone; requests complete within 30 days.

1. Overview & Purpose of the Service

AutoDM is a software-as-a-service (SaaS) workflow tool designed for content creators, agencies, e-commerce stores, and businesses. AutoDM enables users to automate direct messaging on connected Instagram Professional (Business or Creator) accounts in response to explicit audience interactions, such as post comments, reel comments, and Instagram story replies.

By connecting your Instagram account or registering an AutoDM profile, you acknowledge and agree to the data practices outlined in this Privacy Policy. If you do not agree with any part of this policy, you must refrain from using the Service and disconnect your accounts.

2. Information We Collect

We collect information only to the extent necessary to authenticate your identity, execute configured automation workflows, and ensure the performance, reliability, and security of our platform.

A. Account & Registration Information

When you register with AutoDM via our authentication provider (Clerk), we collect:

  • Full name or display name.
  • Primary email address.
  • Authentication identifier (Clerk User ID).
  • Profile avatar image URL (if provided by your sign-in provider).
  • Timestamp of registration, last login, and account status.

B. Instagram & Meta Platform Connection Data

When you authorize AutoDM through the official Meta / Instagram OAuth permissions dialog, we request exactly three permissions (see our Data Use Policy for what each one does and why):

  • instagram_business_basic: account ID, username, avatar, account type, and media list — to identify your account and let you pick posts for automations.
  • instagram_business_manage_messages: the comment ID and commenter ID needed to send a 1:1 private reply to a commenter.
  • instagram_business_manage_comments: comment and story-reply webhook events (comment ID, commenter ID/username, text, timestamp) and the delivery records of the public replies we post.
  • OAuth Access Tokens: Short-lived and exchanged long-lived authorization tokens. All tokens are encrypted immediately upon receipt using Fernet symmetric encryption and stored in secure, restricted database columns.

C. Automation Configuration & Rule Data

To deliver your automated campaigns, we store the automation definitions you configure:

  • Target Instagram post IDs and reel URLs.
  • Keyword trigger rules (e.g. matching specific trigger phrases).
  • Response templates and direct message text configurations.
  • Optional automated public comment replies (acknowledgments).
  • Delivery timing rules, rate limit caps, and scheduling conditions.

D. Webhook Event Data & Interaction Logs

When an Instagram user interacts with your posts or stories, Meta delivers real-time webhook event notifications to our secure ingestion servers. For events matching your configured automation rules, we process:

  • The interacting user's Instagram scoped ID (IGSID) or public username.
  • Comment text or story reply content (processed strictly to evaluate keyword matches).
  • Timestamp of the user interaction.
  • Message delivery dispatch logs (dispatch timestamp, recipient ID, message delivery status, and Meta Graph API error codes if delivery failed).

E. Technical Telemetry & Analytics

To maintain system uptime, detect malicious behavior, and monitor error rates, our infrastructure logs standard technical metadata:

  • Client IP addresses and geographic region.
  • HTTP request headers, browser user-agent string, and operating system.
  • Application performance metrics and error traces (managed via Sentry with personally identifiable information scrubbed).

3. Meta Platform Terms & Graph API Compliance

AutoDM operates in strict compliance with the Meta Commercial Terms, Meta Developer Policies, and Instagram Graph API Terms of Service.

Specific Meta Platform Safeguards:

  • No Unsolicited Messages (Spam Prevention): AutoDM only sends direct messages in response to an inbound action from a user (such as commenting a trigger keyword or replying to your story) under rules you configured. We do not offer scraped-list or purchased-audience cold outreach.
  • No Unauthorized Inbox Access: We do not read, index, or archive your private direct message conversations. For automations you configure, we store only the delivery record (timestamp, recipient ID, status) — never message bodies.
  • No Data Resale or Profiling: We never sell, lease, or license user data obtained through Meta APIs to any ad network, data broker, or marketing exchange. Service providers in §6 process data only to deliver the service, under contract.
  • No Model Training: Data obtained via Meta APIs is never used to train machine learning models for third-party benefit or external commercial distribution.
  • Rate Limiting & Safety: The platform implements strict token-bucket rate limiting and jitter delays to protect your accounts and comply with Meta API fair-use velocity limits.

4. How We Use Your Information

We process your data strictly under the following lawful bases and purposes:

  • Performance of Contract: To provision your user account, maintain your workspace, verify account ownership, and execute the automated messaging workflows you explicitly configure.
  • Service Delivery: To receive webhook notifications from Meta, match incoming comments against your trigger criteria, and transmit authorized direct messages via the Instagram Graph API.
  • Customer Support & Diagnostics: To investigate delivery failures, troubleshoot connection issues, and answer support inquiries submitted to our team.
  • Security & Abuse Prevention: To detect fraudulent activity, credential stuffing, webhook forgery, rate limit abuse, and platform security threats.
  • Transactional Communications: To send critical account notifications (password resets, quota depletion alerts, API expiration warnings) via transactional email.

5. Data Security & Storage Architecture

We implement comprehensive technical and organizational safeguards designed to protect your personal and business data:

  • Encryption at Rest: All database storage is encrypted at rest using industry-standard AES-256 encryption. Meta access tokens and webhook signing secrets undergo an additional application-level layer of Fernet symmetric authenticated encryption prior to database write.
  • Encryption in Transit: All traffic to and from AutoDM is served over TLS (HTTPS).
  • Network Isolation: Internal databases and message queues run in private virtual networks behind strict firewall rules, with no direct public access to the data store.
  • Access Control: Administrative access to production databases and servers is restricted to authorized operations personnel using SSH keys and multi-factor authentication.

6. Third-Party Sub-processors

To deliver the Service, we partner with reputable third-party infrastructure providers who process data on our behalf in compliance with data protection regulations:

Partner / ProviderRole & PurposeLocation
Clerk (Clerk, Inc.)User authentication, session tokens, sign-in securityUSA / Global
Meta Platforms, Inc.Instagram Graph API, OAuth authorization, webhook eventsUSA / Global
Supabase, Inc.Encrypted cloud PostgreSQL database storageAsia (AWS ap-south-1)
Vercel Inc.Frontend application hosting and edge deliveryUSA / Global
HostingerTransactional SMTP email deliveryEU / Global
Oracle Cloud InfrastructureProduction API and worker hosting (virtual machine)India (ap-mumbai-1)
Sentry (Functional Software)Application error tracking and crash reporting (PII scrubbed)Germany (EU)

7. Data Retention & User Data Deletion Instructions

In accordance with Meta Platform Rules and global privacy legislation, you maintain total control over your data retention:

How to Delete Your Data

  1. Account deletion: Log into your AutoDM dashboard, navigate to Settings ➔ Danger Zone, and select "Delete Account". This queues your account profile, all connected Instagram accounts, automation rules, and encrypted tokens for deletion, completed within 30 days. Backups and third-party processors clear their copies on their own cycles.
  2. Disconnecting an Instagram Account: You can disconnect individual Instagram accounts at any time from Dashboard ➔ Accounts. Disconnecting revokes the stored access token and pauses all associated automation tasks.
  3. Revoking Access via Meta / Instagram: You can revoke AutoDM's permissions directly from your Instagram account:
    • On Instagram: Go to Settings → Security → Apps and websites, select AutoDM, and click Remove.
  4. Written Deletion Request: You may submit an email deletion request to privacy@codaipro.com with the subject line "Data Deletion Request". We will process and confirm deletion within 30 days.

For additional details and verification status, review our dedicated Data Deletion Instructions Page.

Retention Periods

  • Account & Credentials: Stored until you disconnect your account or request account closure; deletion completes within 30 days.
  • Trigger & Delivery Logs: Automatically purged on a rolling 90-day retention cycle.
  • Unlinked Webhook Payloads: Automatically purged after 30 days.

8. Your Privacy Rights (GDPR, CCPA & Global)

Depending on your jurisdiction, you possess the following statutory rights:

  • Right of Access: You have the right to request a complete copy of the personal data we maintain about you.
  • Right to Rectification: You may correct inaccurate or incomplete information directly via your settings.
  • Right to Erasure ("Right to Be Forgotten"): You can request that we permanently delete your personal information.
  • Right to Restrict or Object: You can object to the processing of your data or request restriction under specific circumstances.
  • Right to Data Portability: You can request your automation rule sets and account data in a structured, machine-readable format.
  • Non-Discrimination: We will never discriminate against you, deny service, or alter pricing because you exercised your privacy rights.

9. Children's Privacy (COPPA)

AutoDM is strictly intended for businesses, creators, and individuals who are at least 18 years of age (or the age of legal majority in their jurisdiction). The Service is not directed to children under 13, and we do not knowingly collect personal information from minors. If you discover that a child has provided us with personal data, contact us immediately and we will delete the information.

10. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect modifications in our features, changes in regulatory frameworks, or updates to Meta Platform Terms. When material changes occur, we will update the "Last Updated" date at the top of this page and post a prominent notice within your dashboard or send an email notification. Continued use of the platform following the effective date of an updated policy constitutes acceptance of the revisions.

11. Contact & Data Protection Officer

If you have questions, feedback, or concerns regarding this Privacy Policy or wish to exercise any of your legal privacy rights, please reach out to our team:

AutoDM Privacy & Compliance Team

Brand / Operator: AutoDM by CodaiPro (codaipro.com)

Primary Support & Privacy Email: privacy@codaipro.com

Alternative Contact: hello@luckyyaduvanshi.in

General Support: support@codaipro.com

Platform URL: https://autodm.codaipro.com