Legal

Privacy Policy

Last updated: 2026-01-01

1. Overview

This Privacy Policy describes how SmartEcho Automate (“we”, “us”) collects and uses information when you use our console to connect an Instagram professional account and run comment-to-DM automation campaigns.

2. Information we collect

  • Account information you provide: email address and password (stored as a salted hash, never in plain text).
  • Workspace and team data: workspace name, connected Instagram account identifiers, and teammate email/role.
  • Follower/commenter data collected through the Instagram Graph API when your automation runs: the follower's Instagram-scoped ID, public username, comment text that matched a campaign keyword, and Direct Message content exchanged as part of the automation.
  • Usage and execution logs: which campaign matched, whether a reply/DM succeeded, and links clicked, retained for reporting and audit purposes.
  • Session data recorded at login: IP address, browser/device type, and a coarse location derived from your IP address. This powers the Active Sessions view in the console (so you can see and revoke your own logins) and helps us detect suspicious access to your account.

3. Cookies

We use one strictly-necessary cookie, smartecho_session, to keep you signed in — it's HttpOnly (invisible to page scripts), sent only over HTTPS in production, and expires after 7 days or when you sign out. Platform staff sign in through a separate smartecho_admin_sessioncookie that expires after 12 hours. We don't use analytics, advertising, or third-party tracking cookies.

4. How we use information

We use this information solely to operate the automation you configure (posting replies, sending DMs, tracking delivery), to provide the analytics and audit log inside the console, to secure your account, and to communicate with you about your workspace or subscription. We do not sell follower or commenter data.

5. Data retention

Execution and audit records are retained for as long as your workspace is active so you can review campaign history. You can delete a workspace and its associated data at any time from the workspace settings; deletion is immediate and permanent — campaigns, linked accounts, and automation history are removed as soon as you confirm.

6. Who can access your data

We share data with Meta/Instagram only as required to send replies and messages through the official Graph API, and with any integration (Google Sheets, or a custom webhook endpoint you provide) that you explicitly connect from the Integrations page. Authorized SmartEcho staff can access account and session data (such as email, IP address, device, and login activity) through our internal admin console, solely for customer support, account security, and abuse prevention — never for marketing or resale.

7. Children's privacy

SmartEcho Automate is intended for business use and is not directed at individuals under 16. We do not knowingly collect personal information from children; if you believe a child has provided us data, contact us and we'll remove it.

8. Your rights

You may request a copy or deletion of the data we hold about your account or workspace by contacting us at privacy@smartechoautomate.dev.

9. Changes to this policy

We'll update the date at the top of this page when this policy changes and, for material changes, notify workspace owners by email.