InstaDesk ("we", "our", "the Service") is a web application that allows Instagram Business and Creator account owners to view, manage, and respond to their Instagram Direct Messages through a unified dashboard. This Privacy Policy explains what data we collect, how we use it, and your rights regarding that data.
Account Information
Name, email address, and hashed password when you register on InstaDesk.
Instagram Profile Data
Username, profile picture, biography, follower/following/post counts, account type, and website URL — fetched from the Instagram Graph API when you connect your account.
Instagram Messages
Direct Message conversations and message content from your connected Instagram account, fetched via the Instagram Messaging API when you choose to sync. This data is stored in our database so you can view it in the dashboard.
Access Tokens
Instagram API access tokens, stored encrypted in our database, used solely to make API calls on your behalf.
We do not sell, rent, or share your data or message content with any third parties. We do not use your messages for advertising, training AI models, or any purpose other than displaying them to you.
InstaDesk uses the Instagram Graph API. By connecting your Instagram account, you authorize us to access your account data as permitted by the scopes you approve during the OAuth flow. The data we access is governed by both this Privacy Policy and Meta's Data Policy.
We only request permissions that are necessary for the Service:
instagram_business_basic — profile informationinstagram_business_manage_messages — read and send DMsYour data is stored in a secure database hosted on Turso (LibSQL). Access tokens are stored in the database and only used server-side to make API calls — they are never exposed to the browser. We use HTTPS for all communications.
We retain your data for as long as your account is active. When you remove an Instagram account from the dashboard, the associated access token is deleted. When you delete your InstaDesk account, all associated data is permanently deleted within 30 days.
To request data deletion, visit our Data Deletion page or email us directly.
We use a single session cookie to keep you logged in. We do not use advertising cookies or third-party tracking.
We may update this Privacy Policy from time to time. We will notify users of significant changes by updating the "Last updated" date at the top of this page.
For any privacy-related questions or data deletion requests, contact us at: support@messagevault.2fasolver.com