What this policy covers
This Data Policy applies to information we receive from Meta / Instagram when you connect an Instagram Business or Creator account, and to information we receive from Instagram webhooks while that account stays connected. Our broader practices are in the Privacy Policy.
Platform data we access
- Instagram user ID, username, name, and profile picture of the connected Professional account.
- OAuth access tokens and the permissions you granted, stored encrypted.
- Comments on that account’s media: comment ID, text, timestamp, commenter ID/username, and media ID.
- Message send results when we post a private reply to a matching comment.
- Webhook delivery metadata needed to process each event once.
We request these Instagram permissions:
instagram_business_basic— Read your Instagram Business or Creator profile so we can connect the right account.instagram_business_manage_comments— Read comments on your media so we can match keywords and start a conversation.instagram_business_manage_messages— Send a private reply or DM on your behalf when a comment matches a flow you configured.
Why we process it
We process this data only to operate features you turn on:
- Identify which Instagram account belongs to your Speddle workspace.
- Receive comment events in near real time.
- Match comment text against keywords in your active flows (contains or exact match).
- Send the private reply template you wrote, including any link you included.
- Optionally capture the commenter as a lead and show activity in Inbox, Leads, and Stats.
If a comment does not match an active flow, we may still record that it was received and ignored so you can see why nothing sent. We do not scrape Instagram. We only process events Meta delivers for accounts you connected.
What we do not do with platform data
- We do not sell Meta or Instagram platform data.
- We do not use it to advertise on our own behalf or to target ads for other companies.
- We do not share it with other Speddle customers.
- We do not use it to decide eligibility for unrelated products.
- We do not train public or third-party AI models on your comments or DMs.
- We do not post publicly on your Instagram profile through this product.
Who can see it
Platform data stays inside the Speddle workspace that connected the Instagram account. Workspace owners, admins, and members can view leads, comments, and send history for that workspace. Encrypted tokens are not available to browsers or to ordinary database roles.
End users (people who comment) do not get a Speddle login. Their public comment and Instagram username are visible to the creator who connected the account, the same way a comment is visible on Instagram.
Retention of platform data
We keep Instagram tokens only while the account is connected. Comment events and leads stay until you delete the lead, disconnect and remove the account, delete the workspace, or we complete a deletion request. After deletion, tokens are destroyed and Instagram identity fields are removed from our systems, subject to short-lived backups.
Your controls
- Disconnect Instagram in Settings at any time. We then delete stored tokens and stop receiving webhooks for that account.
- Pause or delete a flow to stop new replies immediately.
- Turn off lead capture on a flow if you only want replies, not stored leads.
- Delete a workspace to remove its Instagram accounts, flows, events, and leads.
Deletion of platform data
Customers and Instagram users can request deletion as described on Data deletion. When Meta sends a signed data-deletion callback for a user who connected Speddle, we delete that user’s Instagram tokens and related platform records and return a confirmation code.
Email privacy@speddle.com if you need help.