Privacy Policy

Effective date: September 2, 2026

1. Who we are

DMisland (“the Service”, “we”) is a comment-to-DM automation service for Instagram professional accounts, available at https://dmisland.com. This policy explains what data we collect, why, and how you can delete it.

2. Information we collect

  • Account information: your email address (and basic profile information if you sign in with Google).
  • Instagram connection data: your Instagram account ID, username, and an API access token. Access tokens are stored encrypted (AES-256-GCM) and are never exposed to the browser.
  • Automation activity: comment IDs, comment text, commenter usernames, and DM delivery results, kept so you can review what the Service sent on your behalf.

3. How we use information

We use the collected data solely to run the automations you configure — detecting comments on your posts, sending the DMs you set up, and showing you delivery logs. We do not sell your data or use it for advertising.

4. Third-party services

We rely on the following processors to operate the Service: Meta Platforms (Instagram API), Supabase (database hosting), Vercel (application hosting), and Resend (transactional email). We do not share your data with any other third party unless required by law.

5. Data retention and deletion

You can delete your data at any time, in any of these ways:

  • In the app: use “Delete account” in Settings to remove your account and all associated data.
  • From Instagram: removing the DMisland app in your Instagram settings stops all automation immediately and invalidates our access token. Requesting data deletion from Instagram triggers our deletion callback — we delete your Instagram connection data and issue a confirmation code you can check at dmisland.com/deletion-status.
  • By email: contact us at the address below and we will delete your data without undue delay.

Data is retained only while your account exists. When your account or Instagram connection is deleted, the associated automation rules and conversation data are deleted as well.

Message delivery logs (which comment triggered which message, and whether it was sent) are kept for up to 180 days and then deleted automatically; the app shows the most recent period allowed by your plan. For each rule we also keep a minimal record of which Instagram users have already received a message (Instagram user ID only) for as long as that rule exists, so the same person is never messaged twice by the same rule.

6. Security

All traffic is served over HTTPS. Instagram access tokens are encrypted at rest, database access is protected by row-level security, and webhook requests are verified with cryptographic signatures.

7. Contact

For any privacy questions or requests, contact us at dmisland.app@gmail.com.

8. Changes to this policy

We may update this policy as the Service evolves. Material changes will be announced on this page with a new effective date.