Privacy policy
Last updated: September 10, 2026
What we collect
Account information — your email address and the business profile you configure (offer, pricing, qualification criteria, voice samples).
Instagram data — when you connect your Instagram professional account, we receive and process direct messages sent to your account so our service can respond on your behalf. We access Instagram only through Meta's official APIs, under the permissions you grant, and in accordance with Meta's Platform Terms. We never ask for your Instagram password.
Lead contact details — names, phone numbers, and email addresses that people voluntarily share in conversations with your account (for example, to receive a booking confirmation).
How we use it
Solely to provide the service: responding to your DMs, qualifying leads, booking calls on your calendar, emailing you about activity in your own account, and showing you reporting. Booking confirmations and calendar invites are sent by your connected calendar provider, not by us — we do not send SMS or text reminders. We do not sell personal data. We do not use your conversations to train models for other customers.
Who processes it
We rely on a small set of processors to run the service: Supabase (database and authentication), Anthropic (AI message generation), Meta Platforms (Instagram messaging), Cal.com and Calendly (calendar booking), Dodo Payments (our merchant of record — it processes payments and holds your billing details; card numbers never reach our servers), Resend (transactional email to you), Sentry (error monitoring), and Railway (hosting). Access tokens and API keys are encrypted at rest.
Retention & deletion
We keep data while your account is active. You can request deletion of your account and associated data — including conversation history and lead contact details — at any time by emailing hello@smoothdm.com. Disconnecting your Instagram account stops the service immediately: we unsubscribe from your account's message webhooks and delete the stored access token, so we stop receiving and sending messages. That token is issued by Meta, and removing our copy does not cancel it on Meta's side — it stays valid there until it expires. To revoke it at Meta as well, remove SmoothDM from Instagram → Apps and websites (or Business integrations in your Facebook settings, if your account is linked to a Page).
Contact
Questions about this policy: hello@smoothdm.com.