Legal
Privacy policy
Last updated October 10, 2026
dmkit sends automatic Instagram DMs for the creators and businesses who use it. This page explains what we collect to do that, what we do with it, and how to have it deleted. Questions go to team@dmkit.co.
Two kinds of people
Customers sign up for dmkit and connect their own Instagram professional account. Their followers comment on those posts or message those accounts, and get the replies our customers set up. For followers’ data, the customer decides how it’s used and we process it on their behalf.
What we collect from customers
- Your login: name, email address and the sign-in method you chose. Sign-in is handled by Clerk.
- Your workspace: its name, time zone, settings, team members, and the automations you build.
- Billing: your plan, subscription status and the customer and subscription IDs from Dodo Payments, who handle payment as merchant of record. We never see or store card details.
- Your Instagram account, once you connect it through Instagram’s own login: account ID, username, name, profile picture, follower count, and a login token Instagram issues so we can act for you. The token is encrypted at rest (AES-256-GCM). We never ask for or see your Instagram password.
- Your posts and stories: captions, thumbnails and links of the ones you pick for an automation.
What we process about followers
When someone interacts with a connected account, we receive it from Instagram and keep what’s needed to reply and to show the customer their inbox:
- Comments on the customer’s posts and reels, replies to their stories, and DMs sent to them, including button taps.
- Their Instagram-scoped ID, username and, for “follow to unlock”, whether they follow the account.
- An email address or phone number, only if they type one in reply to a question the customer’s automation asked.
- The messages dmkit sends them, and messages the customer sends from dmkit or the Instagram app.
- Taps on tracked links: the time, a one-way hash of who tapped (so repeat taps count once), a one-way hash of the IP address, and the browser’s user agent. We don’t store IP addresses themselves.
How we use it
- To run the automations our customers set up: reply to comments, send DMs, check follows, record answers and send reminders.
- To show customers their inbox, contacts, activity and stats.
- To keep dmkit secure, fix problems, and handle billing and support.
We don’t sell personal data, we don’t use it for advertising, and we don’t use Instagram data for anything other than providing dmkit to the customer who connected the account.
Who we share it with
Only the services we need to run dmkit, each for its own part:
- Meta (Instagram): to read comments and messages and to send replies, through Meta’s official API.
- Clerk: sign-in and account security.
- Supabase: our database hosting.
- Our web hosting provider: runs the app and processes requests.
- Dodo Payments: payments, invoices and sales tax.
- Google Analytics: how visitors use our website, through cookies. It isn’t used inside the dashboard’s Instagram data.
We may also disclose data when the law requires it.
How long we keep it
- Customer and Instagram data is kept while the account is in use.
- Disconnecting an Instagram account deletes its contacts, inbox and activity from dmkit straight away.
- Deleting your dmkit account deletes your workspace and everything in it.
- Raw notifications from Instagram are kept for 14 days for troubleshooting, then deleted.
Deleting your data
See how to delete your data. Customers can do it themselves in Settings; followers can ask the account they messaged, or write to team@dmkit.co.
Security
Data travels over HTTPS. Instagram tokens are encrypted at rest, webhook deliveries are checked against Meta’s signature, and only members of a workspace can see its data.
Your rights
Depending on where you live, you can ask to see, correct, export or delete your personal data, or object to how it’s used. Write to team@dmkit.co and we’ll answer within 30 days.
Children
dmkit isn’t meant for anyone under 16, and we don’t knowingly collect their data.
Changes
If this policy changes, we’ll update this page and the date at the top.