Privacy Policy
Last updated October 4, 2026
DMFa.st helps Instagram creators and businesses reply automatically to comments, Story replies and direct messages, and publish the posts they schedule. This policy explains what we collect to do that, why, and the control you have over it. We wrote it in plain language on purpose.
Who this covers
- Customers: people who sign in to DMFa.st and connect an Instagram account.
- People who interact with our customers: someone who comments on, replies to, or messages a customer's connected Instagram account.
What we collect
From customers:
- Your name, email address and profile photo from Google when you sign in.
- For each connected Instagram account: the account ID, username, profile photo, and an access token Instagram gives us. Tokens are encrypted at rest and never shown in logs.
- The automations you create: keywords, messages, links and settings.
- Posts you schedule: the photos, videos and caption you upload, and when to publish them.
From people who interact with a connected account, as delivered to us by Instagram:
- Their Instagram-scoped user ID and username.
- The text of the comment, Story reply or message that reached the automation.
- Whether they tapped a button, clicked a link, or replied STOP.
From people who join the waitlist: your name, email address and social handle, entered in our waitlist form.
We do not collect passwords, we do not buy data, and we do not read anything Instagram doesn't send to the app.
How we use it
- To run the automations a customer set up, and to avoid messaging the same person twice.
- To publish the posts a customer scheduled, at the time they picked, to their own Instagram account.
- To show customers their activity log, contacts and analytics.
- To keep the service secure and within Instagram's rate limits.
- To tell waitlist signups when DMFa.st opens. We don't use waitlist details for anything else.
We never sell personal data, never use it for advertising, and never use Instagram data for any purpose other than providing the service to the customer whose account it came from.
Who we share it with
Only the infrastructure providers that run DMFa.st (Cloudflare for hosting and storage, Google for sign-in, Tally for the waitlist form) and Meta, when we call Instagram on a customer's behalf. Each processes data only to provide their service to us.
How long we keep it
- Account and automation data: until you delete your account.
- Waitlist details: until you ask us to remove them.
- Activity history, including comment and message text: 90 days, then deleted. Daily totals in analytics stay.
- Photos and videos uploaded for a scheduled post: deleted once the post is published or you cancel it. Files you upload but don't schedule are deleted within about 3 days.
- Instagram access tokens, plus that account's automations, contacts, activity and scheduled posts (with their files): deleted as soon as you disconnect the account.
Your choices
- Disconnect Instagram at any time from Integrations; automations stop immediately.
- Delete your account and all data from Settings in the app, or see data deletion.
- Anyone messaged by an automation can reply STOP and will never be messaged by it again.
- People who interacted with a DMFa.st customer can ask us to delete their data by emailing privacy@dmfa.st with their Instagram username.
Security
All traffic uses HTTPS. Access tokens are encrypted at rest. Each customer's data is isolated to their own workspace, and webhooks from Instagram are verified before we process them.
Contact
Questions about privacy: privacy@dmfa.st.