Autogram

Privacy Policy

Last updated 22 September 2026

Autogram ("we", "our", "us") operates autogram.co.in and the Autogram Instagram automation service. This policy explains what we collect, why we collect it, and how you get rid of it. We comply with Meta's Platform Terms and Developer Policies, the Information Technology Act, 2000, and the Digital Personal Data Protection (DPDP) Act, 2023.

Information we collect

Account information

  • Email address, used for login and service notifications
  • Name, optional, used only for personalisation

Instagram data of the connected account

Collected through Meta's official Instagram API with Instagram Login, only after you authorise Autogram:

  • Instagram username, user ID, display name, and profile picture URL
  • Access tokens issued by Meta, encrypted at rest
  • Comments on your own posts and reels — read in memory to match the keywords you configured. We store the comment id and the keyword that matched, not the full comment text
  • Delivery status of the private replies we send on your behalf
  • Account and post insights (reach, views, and similar metrics), fetched on demand when you open analytics. We do not keep a separate copy

Instagram data of people who comment or message you

These people did not sign up for Autogram. We keep only what the product needs to send one private reply and to show you the lead:

  • Instagram user ID and username of the commenter
  • The keyword that matched, and which of your posts it was on
  • Inbound message text is read only to honour STOP / opt-out, a request for a human, or a follow-gate reply. We do not store the message body as a conversation history

Usage and files you upload

  • Number of DMs sent per campaign
  • Dashboard activity needed to operate the service
  • Images or PDFs you attach to a campaign, stored until you remove them
  • A reel you upload for an AI check, held at most 24 hours and deleted as soon as the check finishes

Autogram Studio (video editor)

Our free video editor at studio.autogram.co.in runs entirely in your browser. No account is needed, and your projects, media files, and transcripts stay on your own device — they are stored in your browser's local storage and never uploaded to us.

  • If you open Studio from the dashboard, we pass your email address with a 5-minute handoff token so the editor can show who is signed in. It is kept in that tab's session storage only, and cleared when you disconnect or close the tab
  • Transcription runs on your device when you request it; your audio never leaves the browser. The transcription model itself is downloaded from a public host when first needed, and fonts you use are loaded from their provider
  • The editor never checks for updates on its own. If you open the extension catalogue, it shows the last synced copy without contacting the catalogue server
  • Studio is open-source software (AGPL-3.0): you may also download and run your own copy instead of using ours

Payment information

Payments are processed by Razorpay. We never receive or store your card number, UPI ID, or netbanking credentials.

How we use your information

  • To match keywords in comments and deliver private replies
  • To show you analytics and campaign performance
  • To process payments and manage your plan
  • To send you service-related notifications (sign-in codes, billing)
  • To diagnose faults and keep the service running

We do not use Meta-sourced data for advertising, profiling, or training machine learning models. We do not sell personal data. If the account owner turns on the automated-reply notice in Settings, every DM we send for that account ends with “This is an automated reply.”

Who we share it with

We share only what is necessary to run the service:

  • Meta / Instagram — to send private replies through the official API
  • Razorpay — to process payments
  • Cloudflare — hosting, storage, and delivery of the app
  • Resend — delivery of sign-in codes and service email, when Cloudflare Email Sending is not available
  • Google (Gemini) — only when you ask for an AI reel check: your uploaded video is streamed to Google's API for analysis and deleted from our storage right after. Google processes it on a tier where it is not used to train models
  • An AI assistant you connect — optional. If you connect Autogram's MCP server to a tool you choose, that tool can read and write your workspace at your direction. We do not send Instagram data to any AI provider on our own
  • Law enforcement — only where we are legally required to

Storage and security

  • Data is stored on Cloudflare's encrypted infrastructure
  • Meta access tokens are encrypted at rest using AES-256-GCM
  • All data in transit is encrypted with TLS
  • We never ask for or store your Instagram password

How long we keep it

  • Account data — for as long as your account is active
  • Campaign and message logs — 90 days from when each message was logged
  • Webhook events — 7 days, for debugging
  • Lead contacts — 365 days, or until you unstar / delete them. A starred lead is kept until you remove the star or ask us to erase the account
  • Campaign attachments — until you remove them from the campaign, then 30 days
  • Reels uploaded for AI analysis — deleted right after the analysis completes. Uploads nobody analyses are removed within 24 hours
  • After a deletion request — we complete erasure within 30 days

Your rights

You can, at any time:

  • Export your contacts from the dashboard as a CSV file
  • Disconnect your Instagram account, which stops all automation immediately and destroys the access token we hold
  • Ask us to delete everything we hold — see data deletion

People who received an automated DM can reply STOP to opt out, or ask for a human. Both stop further automated messages to them.

Meta platform data

We access only the Instagram data you explicitly authorise, and use it solely for the purposes above. Disconnecting your Instagram account — from the dashboard, or by removing Autogram under Instagram's Settings → Apps and websites — immediately stops all automation and destroys the access token we hold. Records already captured (contacts and delivery logs) age out on the windows listed above. To have them erased sooner, use the data deletion page. We complete that within 30 days.

If you request deletion through Instagram itself, Meta sends us a signed request. We acknowledge it with a confirmation code and a status URL, stop automation immediately, and erase the Instagram user data we hold for that person within 30 days.

Children

Autogram is not intended for anyone under 18, and we do not knowingly collect data from children.

Changes to this policy

We may update this policy. If a change is significant, we will tell you by email or in the dashboard before it takes effect.

Contact

Privacy queries
[email protected]