Privacy Policy
Last updated: September 2026
Tawlki ("we", "our", "the service") provides an AI-assisted reply tool for Instagram Direct Messages, connected via Meta's official Instagram Messaging API. This policy explains what data we collect from connected accounts, how it is used, and how it is protected.
What we collect
- Your Instagram Business Account ID, username, and Facebook Page ID, obtained via Meta's OAuth login when you connect your account.
- A long-lived access token issued by Meta, used only to send and receive messages on your behalf via the official Instagram Messaging API.
- Incoming and outgoing Instagram Direct Message content, processed to generate and send automated replies.
- Basic account metadata you provide us directly (e.g. login email) to operate your dashboard account.
How we use it
Message content is used solely to generate and send replies on your behalf, and to maintain short-term conversation context so replies stay coherent. Access tokens are used only to call Meta's Instagram Messaging API for your own connected account — never to act on any account you have not explicitly connected.
Storage and security
Data is stored in an access-controlled Postgres database. Access tokens and message content are never sold, shared with advertisers, or used for any purpose outside operating the service for the connected account's owner.
Your controls
You can disconnect your Instagram account at any time from the dashboard, which revokes our access. To request deletion of your account data, contact us at the address below.
Contact
Questions about this policy: imainulhaq@gmail.com