legal, but readable

Data Policy

Speddle uses Instagram APIs (Instagram API with Instagram Login) to automate comment replies and capture leads. This page is the data-use policy for that Meta platform data.

Effective August 17, 2026

What this policy covers

This Data Policy applies to information we receive from Meta / Instagram when you connect an Instagram Business or Creator account, and to information we receive from Instagram webhooks while that account stays connected. Our broader practices are in the Privacy Policy.

Platform data we access

  • Instagram user ID, username, name, and profile picture of the connected Professional account.
  • OAuth access tokens and the permissions you granted, stored encrypted.
  • Comments on that account’s media: comment ID, text, timestamp, commenter ID/username, and media ID.
  • Message send results when we post a private reply to a matching comment.
  • Webhook delivery metadata needed to process each event once.

We request these Instagram permissions:

  • instagram_business_basicRead your Instagram Business or Creator profile so we can connect the right account.
  • instagram_business_manage_commentsRead comments on your media so we can match keywords and start a conversation.
  • instagram_business_manage_messagesSend a private reply or DM on your behalf when a comment matches a flow you configured.

Why we process it

We process this data only to operate features you turn on:

  • Identify which Instagram account belongs to your Speddle workspace.
  • Receive comment events in near real time.
  • Match comment text against keywords in your active flows (contains or exact match).
  • Send the private reply template you wrote, including any link you included.
  • Optionally capture the commenter as a lead and show activity in Inbox, Leads, and Stats.

If a comment does not match an active flow, we may still record that it was received and ignored so you can see why nothing sent. We do not scrape Instagram. We only process events Meta delivers for accounts you connected.

What we do not do with platform data

  • We do not sell Meta or Instagram platform data.
  • We do not use it to advertise on our own behalf or to target ads for other companies.
  • We do not share it with other Speddle customers.
  • We do not use it to decide eligibility for unrelated products.
  • We do not train public or third-party AI models on your comments or DMs.
  • We do not post publicly on your Instagram profile through this product.

Who can see it

Platform data stays inside the Speddle workspace that connected the Instagram account. Workspace owners, admins, and members can view leads, comments, and send history for that workspace. Encrypted tokens are not available to browsers or to ordinary database roles.

End users (people who comment) do not get a Speddle login. Their public comment and Instagram username are visible to the creator who connected the account, the same way a comment is visible on Instagram.

Retention of platform data

We keep Instagram tokens only while the account is connected. Comment events and leads stay until you delete the lead, disconnect and remove the account, delete the workspace, or we complete a deletion request. After deletion, tokens are destroyed and Instagram identity fields are removed from our systems, subject to short-lived backups.

Your controls

  • Disconnect Instagram in Settings at any time. We then delete stored tokens and stop receiving webhooks for that account.
  • Pause or delete a flow to stop new replies immediately.
  • Turn off lead capture on a flow if you only want replies, not stored leads.
  • Delete a workspace to remove its Instagram accounts, flows, events, and leads.

Deletion of platform data

Customers and Instagram users can request deletion as described on Data deletion. When Meta sends a signed data-deletion callback for a user who connected Speddle, we delete that user’s Instagram tokens and related platform records and return a confirmation code.

Email privacy@speddle.com if you need help.