[ LEGAL // PRIVACY ]
[ UPDATED 27 JULY 2026 ]
Privacy Policy
This policy explains precisely what data the AutoChat application collects, what it deliberately does not collect, how that data is protected, how long it is kept, and how you can have it deleted.
Last updated: 27 July 2026
1. Who we are
AutoChat is a self-hosted application operated by Rahul Simi ("we", "us", "the operator"). It is not a public multi-tenant service; it is run by the operator for the operator's own Instagram professional account.
For any privacy question, data request, or deletion request, contact: irahulsamyal@gmail.com
2. What AutoChat does
AutoChat watches comments on our own Instagram professional account. When a comment arrives, it sends that commenter one private reply containing a tracked link. If the recipient later places an order on our Shopify store, AutoChat attributes that order back to the originating post.
Its purpose is measuring which posts generate orders. It does not build advertising profiles, and it does not sell, rent, or share data with third parties.
3. Instagram data we collect
Through the Instagram Graph API we collect only the following:
Connected account
- The connected account's id and username
Per comment
- Comment id
- Media id
- The commenter's Instagram-scoped id and username
- The comment text
- Timestamps
Messages we send
- Message id
- Delivery status
- Timestamps
Instagram data we do not collect
We do not collect, request, store, or process any of the following:
- Profile data
- Follower lists
- Message history
- Email addresses
- Phone numbers
4. Shopify data we collect
The only Shopify permission AutoChat uses is read_orders. From an order we store:
- Order id and order name
- Currency
- Totals
- Financial status
- Landing URL and referring URL
- A test-order flag
Shopify data we do not collect
We do not collect, store, or process any of the following:
- Customer name
- Customer email address
- Shipping or billing address
- Phone number
- Line items
5. Click tracking
When someone follows a tracked link, we record only what is needed to attribute a later order to the originating post:
- An anonymous first-party visitor cookie
- An opaque click id
- Keyed cryptographic hashes of the IP address and user-agent
The IP address and user-agent are never stored in raw form. Only keyed cryptographic hashes are retained, so the original values cannot be recovered from our records.
6. Cookies
AutoChat sets first-party cookies only. There are exactly two:
- A login session cookie for the operator's dashboard
- An anonymous visitor id used for click attribution
We use no third-party cookies, no advertising cookies, and we perform no cross-site tracking.
7. How your data is protected
- Access tokens are encrypted at rest using AES-256-GCM and are never exposed to the browser
- All incoming webhooks are signature-verified before being processed
- Sessions are database-backed with hashed tokens
- Access to data is role-restricted
8. How long we keep data
The following retention periods are the defaults and are configurable by the operator. Data past its retention period is removed by an automatic daily purge.
| Data type | Retention |
|---|---|
| Raw webhook payload copies | 7 days |
| Comment events | 180 days |
| Click events | 365 days |
| Webhook logs | 30 days |
| Audit logs | 365 days |
| Job history | 14 days |
9. Deleting your data
Disconnecting the Instagram account removes the stored credentials for that account from AutoChat.
You may also request deletion of your data by emailing irahulsamyal@gmail.com. Requests are actioned within 30 days.
Step-by-step instructions are on the Data Deletion page.
10. Sharing
We do not sell, rent, or trade data. Data is not shared with third parties for advertising or any other commercial purpose. Data is processed only by the Instagram and Shopify platform APIs described above and by the operator's own hosting infrastructure.
11. Changes to this policy
If this policy changes, the updated version will be published at this URL with a revised "last updated" date.
12. Contact
Operator: Rahul Simi
Email: irahulsamyal@gmail.com