Privacy Policy
Last updated: June 16, 2026
ACSoft ("we", "us") helps Instagram creators view analytics, automate replies to direct messages and comments, manage conversations, and publish content for their own professional account. This policy explains what data we access, why, and how you stay in control. This is a template — replace it with text reviewed by your legal counsel before going live.
What we access
When you connect your Instagram account, you grant us access through Meta's official Instagram API. We never receive or store your Instagram password — authentication is handled entirely by Meta. With your consent we access:
- Your profile (username, account type, follower and post counts)
- Your media (captions, like and comment counts, permalinks)
- Account insights such as reach
- Direct messages sent to your account, and story replies/mentions — so we can match your keyword rules, auto-reply, and show conversations in your Inbox
- Comments on your posts — so we can read and reply to them
- Permission to publish photos and videos to your account, used only when you create and confirm a post yourself
What we store
To provide these features, we store:
- Your Instagram user ID, username, and account type, and an access token issued by Meta (encrypted at rest, used only to act on your behalf)
- The automation rules and flows you create
- Contacts — the Instagram-scoped IDs and names of people who message you, plus any tags or attributes you or your flows assign to them
- Conversation state and message transcripts (incoming and outgoing), used for automation and your Inbox
- Logs of AI calls (usage and outputs) and link-click events
We do not sell your data or share it with third parties for advertising.
How we use it
To run the features you enable: analytics, keyword and flow-based auto-replies to DMs and comments, your Inbox (including human handoff), and — when you initiate it — publishing posts. To generate, route, or extract information from replies, message content may be sent to our AI provider (Google's Gemini API) to produce the response. We do not use your data to send unsolicited messages on your behalf; automated replies only go to people who first contacted your account, within Instagram's messaging rules.
Service providers
We rely on a small number of processors to operate the service: Meta (Instagram API), our database host, our application host and file storage, and Google (Gemini AI for the features above). They process data only to provide their service to us.
Security
Access tokens are encrypted at rest (AES-256-GCM). We transmit data over HTTPS and limit access to the data needed to run the features you enable.
Data retention & deletion
You can disconnect at any time from your Instagram app settings, which triggers deletion of your stored data, including your contacts, conversations, messages, rules, and flows. You may also request deletion directly — see our Data Deletion page.
Contact
Questions about this policy? Email blueroom.acsoft@gmail.com.