← Back

Privacy Policy

Last updated: June 14, 2026

1. Overview

InstaDesk ("we", "our", "the Service") is a web application that allows Instagram Business and Creator account owners to view, manage, and respond to their Instagram Direct Messages through a unified dashboard. This Privacy Policy explains what data we collect, how we use it, and your rights regarding that data.

2. Data We Collect

Account Information

Name, email address, and hashed password when you register on InstaDesk.

Instagram Profile Data

Username, profile picture, biography, follower/following/post counts, account type, and website URL — fetched from the Instagram Graph API when you connect your account.

Instagram Messages

Direct Message conversations and message content from your connected Instagram account, fetched via the Instagram Messaging API when you choose to sync. This data is stored in our database so you can view it in the dashboard.

Access Tokens

Instagram API access tokens, stored encrypted in our database, used solely to make API calls on your behalf.

3. How We Use Your Data

  • To display your Instagram conversations and messages in the dashboard
  • To send replies to Instagram messages on your behalf when you use the reply feature
  • To authenticate you and maintain your session
  • To sync new conversations when you request it

We do not sell, rent, or share your data or message content with any third parties. We do not use your messages for advertising, training AI models, or any purpose other than displaying them to you.

4. Instagram / Meta Data

InstaDesk uses the Instagram Graph API. By connecting your Instagram account, you authorize us to access your account data as permitted by the scopes you approve during the OAuth flow. The data we access is governed by both this Privacy Policy and Meta's Data Policy.

We only request permissions that are necessary for the Service:

  • instagram_business_basic — profile information
  • instagram_business_manage_messages — read and send DMs

5. Data Storage & Security

Your data is stored in a secure database hosted on Turso (LibSQL). Access tokens are stored in the database and only used server-side to make API calls — they are never exposed to the browser. We use HTTPS for all communications.

6. Data Retention

We retain your data for as long as your account is active. When you remove an Instagram account from the dashboard, the associated access token is deleted. When you delete your InstaDesk account, all associated data is permanently deleted within 30 days.

7. Your Rights

  • You can disconnect your Instagram account at any time from the Accounts tab
  • You can request deletion of all your data by emailing us
  • You can revoke our app's access in Instagram Settings → Apps and Websites

To request data deletion, visit our Data Deletion page or email us directly.

8. Cookies

We use a single session cookie to keep you logged in. We do not use advertising cookies or third-party tracking.

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify users of significant changes by updating the "Last updated" date at the top of this page.

10. Contact

For any privacy-related questions or data deletion requests, contact us at: support@messagevault.2fasolver.com