In short
We use your Instagram data only to run the automations you set up, show you your results and keep the Service secure. We never sell it, use it for ads or use it to train AI.
You can delete your data at any time from Settings, from Instagram, or by email. This policy follows the Information Technology Act, 2000, the Digital Personal Data Protection Act, 2023 and Meta’s Platform Terms.
Who we are and who this covers
Triggerfy (the “Service”, at triggerfy.xyz) is operated by [Your full legal name], an individual based in India, at [Your full postal address], India (“Triggerfy”, “we”, “us”).
This policy covers two groups of people:
- Creators: people who sign up for Triggerfy and connect an Instagram Professional account. For your account data, we decide how it is used, so we are its Data Fiduciary.
- Audience members: people who comment on, reply to or message a creator’s Instagram account. Their data reaches Triggerfy only because that creator turned on an automation. We process it on the creator’s behalf and on their instructions: the creator is the Data Fiduciary and we are the Data Processor.
Instagram data and permissions
You connect Instagram through Meta’s official Instagram API with Instagram Login. You choose to grant the permissions below, and we use each one only for the features listed. We never see or store your Instagram password.
| Permission | What we access and why |
|---|---|
| instagram_business_basic | Your account ID, username, name, profile photo, account type and follower count, and your posts, reels and stories (with their like and comment counts), so you can pick which post an automation runs on and see your follower count and engagement rate. |
| instagram_business_manage_comments | Comments on your posts and reels, to check them against the keywords you set and to post the public reply you wrote. |
| instagram_business_manage_messages | Messages and story replies sent to your account, to start or continue an automation you set up, to send the DMs you wrote, and to check whether someone follows you when you use a follow-to-unlock step. |
The access token Instagram gives us is encrypted at rest (AES-256-GCM) and used only by our servers. It is deleted the moment you disconnect the account or remove Triggerfy from Instagram.
What we collect
About creators
- Account: email address, and your name and profile photo if you sign in with Google (Google shares only these, through the “openid email profile” scopes). One-time sign-in codes are stored only as a hash.
- Sessions: a session token in a secure cookie, with the IP address and browser of each session, to keep you signed in and protect your account.
- Connected Instagram accounts: the data described in section 2.
- What you set up: automations, keywords, messages, buttons and links, images you upload for DMs, and your notification preferences.
- Payments: handled by Razorpay. We receive and keep the payment ID, amount, status, plan, billing period, payment method type and, for cards, the network and last four digits. We never receive or store full card numbers, CVVs, UPI PINs or bank credentials.
- Support: messages you send us and our replies.
About audience members
- Instagram-scoped ID, username, name and profile photo of a person an automation reached.
- The comment or message that triggered the automation, held only until it has been processed (failed ones are kept for 7 days so we can fix the problem), then deleted. Comments and messages that don’t match any of the creator’s automations are not stored at all.
- The progress of each conversation: which DM was sent, whether they tapped a button, followed, opened a link, and when.
- An email address, only if they type it into a creator’s email-capture step themselves.
Technical data
Server logs (IP address, browser, pages requested, errors) to run the Service and keep it secure. We don’t use advertising trackers or third-party analytics on the website or the app.
How we use data
- To run the automations you set up: match comments and messages, and send the replies and DMs you wrote.
- To show you your contacts, conversations and analytics, and your connected account’s follower count.
- To sign you in, keep your account secure, and prevent spam, abuse and fraud.
- To process payments and send service emails (sign-in codes, billing, automation alerts you can turn off).
- To answer support requests and meet legal, tax and accounting obligations.
What we never do
We follow Meta’s Platform Terms and Developer Policies for every piece of data that comes from Instagram. In particular, we never:
- sell, rent or license personal data, or share Instagram data with data brokers or advertising networks;
- use Instagram data for advertising, profiling, building audiences, credit or eligibility decisions, or surveillance;
- use Instagram data or audience messages to train AI models;
- message anyone who hasn’t interacted with the creator first: every DM answers that person’s own comment, story reply or message, inside the 24-hour window Instagram allows, and each comment gets at most one private reply;
- share audience members’ identities in reports: analytics exports for brands contain totals only, never usernames, IDs or emails.
AI features
On plans with AI message rotation, we send the text you wrote for a DM or public reply to Google’s Gemini model, through Google Cloud Vertex AI, and get back reworded versions so people don’t all receive the exact same message. Only your own message text is sent, once each time you save it, with any links and @mentions removed. No audience data, comments or conversations are ever sent to the AI. Under Google Cloud’s terms, Google does not use this data to train its models.
Who we share data with
Only with the service providers we need to run Triggerfy, each bound by contract to protect the data:
| Provider | Why |
|---|---|
| Meta (Instagram API) | Reading comments and messages, and sending replies and DMs, for your automations. |
| Google Cloud (Mumbai, India) | Hosting our servers, database, file storage and task queues; Vertex AI for AI rewrites. |
| Vercel (Mumbai, India) | Hosting the website and app. |
| Razorpay | Payments and subscriptions. |
| Resend | Sending sign-in codes and service emails. |
| Google Sign-In | Signing you in, if you choose “Continue with Google”. |
We may also disclose data when the law requires it, to protect people’s safety or our rights, or to a buyer in a merger or sale of the business (we’ll tell you first, and this policy keeps applying).
How long we keep data
| Data | Kept for |
|---|---|
| Account, automations, contacts and conversations | Until you delete them or your account |
| Activity events (taps, clicks, follows, DMs sent) | 90 days |
| Daily analytics totals (no personal data) | 400 days |
| Comment and message text that triggered an automation | Until processed; failed ones 7 days |
| Processing records (status only, no message text) | 30 days |
| Sessions and sign-in codes | Until they expire |
| Images uploaded for DMs | While an automation uses them |
| Invoices and payment records | As long as Indian GST and income-tax law requires (generally up to 8 years) |
Deleting your data
You can delete your data at any time, in any of these ways:
- Remove Triggerfy from Instagram (Settings → Website permissions → Apps and websites → Remove) and request deletion: Meta tells us, and we delete everything we hold about that Instagram account right away and give you a confirmation code.
- Delete your whole Triggerfy account: Settings → General → Delete account. This removes your account, connected Instagram accounts, automations, contacts, conversations and analytics, and cancels any active subscription.
- Email support@triggerfy.app from your registered address with the subject “Delete my data”.
Disconnecting an Instagram account only deletes its access token and pauses its automations, so you can reconnect later; delete the account or your Triggerfy account to remove its data. Full steps, and the status of a deletion request, are on our Data Deletion page.
Audience members’ choices
If you received a DM from a creator through Triggerfy, you can ask that creator to stop messaging you (they can unsubscribe you, and no automation will DM you again), or email us at support@triggerfy.app with your Instagram username. We’ll unsubscribe you and delete your data from the creator’s account, and let the creator know.
Security
- All traffic uses HTTPS. Instagram access tokens are encrypted at rest; sign-in codes are stored only as hashes.
- Secrets are kept in Google Secret Manager; internal services only accept authenticated requests.
- Every database query is limited to the signed-in creator’s own data.
- No system is perfectly secure. If a breach affects your data, we’ll notify you and the Data Protection Board of India as the law requires.
Your rights
Under the Digital Personal Data Protection Act, 2023 you can ask to access a summary of your data, correct or update it, erase it, withdraw consent (this stops the features that need it), and nominate someone to act for you. Email support@triggerfy.app. We acknowledge requests within 48 hours and resolve them within 30 days.
Cookies and browser storage
We use only what the Service needs to work:
- a secure, HTTP-only session cookie that keeps you signed in;
- short-lived cookies that protect the Google and Instagram sign-in steps;
- browser storage for small conveniences, such as a referral code from a friend’s link or the email a code was sent to.
No advertising or analytics cookies are used.
Where data is stored
Our servers, database and files are in Google Cloud’s Mumbai region and the website is served from Vercel’s Mumbai region. AI rewrites run on Google Cloud Vertex AI, which may process the message text outside India. We transfer data outside India only as Indian law permits.
Children
Triggerfy is for people aged 18 and over. We don’t knowingly collect data from children. If you believe a child has given us data, email support@triggerfy.app and we’ll delete it.
Changes to this policy
We’ll update the date at the top when this policy changes. For material changes, we’ll tell you by email or in the app before they take effect.
Grievance Officer and contact
Under the Information Technology Act, 2000 and the rules made under it, our Grievance Officer is [Your full legal name], [Your full postal address], India. Email: support@triggerfy.app.
If you’re not satisfied with our response, you can complain to the Data Protection Board of India.
Related policies