Instagram Auto Studio (the “Service”) is a tool that helps operators of Instagram professional (Business or Creator) accounts create posts from their photos and topics and publish them, review post performance, and automatically respond to comments. The Service takes the privacy of its users seriously and processes only the minimum information necessary to provide the Service.
1. Information We Process
| Category | Data | Source |
|---|---|---|
| Account information | Member: name, date of birth, phone number and email. Linked accounts: Instagram user ID, username, name, profile picture, follower, following and post counts, the list of permissions granted, and your Facebook name and Page names (if you link Facebook) | The user at sign-up; Meta when an account is linked |
| Authentication data | Password (stored only as an irreversible hash), email verification codes (hashed, expire after 10 minutes), Instagram and Facebook access tokens (stored encrypted) and token expiry times | Meta |
| Content | Photos uploaded by the user, post images edited from them or newly generated or composited, the topics and caption styles entered, generated captions and hashtags, and publishing results (post ID and link) | Uploaded by the user; generated by the Service and Gemini |
| Insights | Aggregate metrics such as reach, views and engagement, follower/non-follower ratios, and aggregate statistics such as age, gender and location distribution | Meta (Instagram Graph API) |
| Comments and messages | Comments on the user's posts (commenter username, text and time); the username, name, profile picture, follower count and follow status of accounts that have sent the user a DM; and auto-reply processing records | Meta (Webhooks, Instagram Graph API) |
| Analysis results | Sentiment classification of each comment (positive, neutral or negative) and the reason for the classification | Generated by the Service |
| Session | A signed cookie used to keep the user logged in (containing only internal member and selected account numbers) | Generated by the Service |
The Service does not collect information about the individual accounts that viewed or individual accounts that liked a post (Instagram does not provide this). We do not collect payment information, and passwords are stored only in a form that cannot be reversed.
2. How We Use Information
- Sign-up, log-in and identifying members, checking that members are at least 14 (date of birth), and contacting members about inquiries and notices (phone number and email)
- To create post images and captions from the topic and photos the user provides, publish them to the user's account, and check the publishing limit
- To make post images available at unguessable public URLs for publishing (Instagram fetches the images from these URLs)
- To show post and account performance on a dashboard and keep a daily history
- Only when the user turns it on: to reply to new comments with a fixed message, send the commenter a DM, and send different messages depending on whether they follow the account
- To classify comments as positive, neutral or negative and provide statistics
- To keep users logged in, diagnose errors, and secure the Service
We do not use the information we collect for advertising, the sale of profiles, or third-party marketing, and we do not sell it.
3. Third-Party Sharing and Processors
- Meta Platforms — Instagram login, publishing, retrieving insights and comments, and sending replies and DMs (API calls made to carry out the user's requests)
- Google (Gemini API) — Uploaded photos and reference images, together with the topics and reference information entered, are sent to design posts, research topics and art-direct images; comment text and part of the post caption are sent to classify comment sentiment. If Gemini is not configured, processing takes place on our server and nothing is sent externally.
- Vercel (hosting), Neon (database) and Resend (sending sign-up and password reset emails — your email address and the code are passed to it) — infrastructure used to operate the Service
Except where required by law, we do not provide personal information to third parties for any purpose other than those described above.
4. Data Retention
- When a user disconnects their account or requests data deletion, all information related to that account is deleted immediately.
- While the account remains connected, information is retained to provide the Service; historical insight records that Meta no longer provides are also retained until the user deletes them.
- Uploaded photos and post images are retained together with the job history and are deleted along with it when the user disconnects or deletes their data.
- To confirm that a deletion request was processed, we keep only a confirmation code and the time of processing; these contain no personally identifiable information.
5. How to Delete Your Data
You can delete your data at any time using ‘Disconnect and delete data’ in the Service, by removing the app in your Instagram settings, or by contacting us. For detailed steps, see Data Deletion Instructions.
6. Security
- Access tokens are stored encrypted (Fernet, AES), and session cookies are issued as signed, HttpOnly and Secure.
- Webhooks from Meta are processed only after their signature (X-Hub-Signature-256) has been verified.
- All communication is encrypted with HTTPS.
7. Your Rights
You may request access to, correction or deletion of, or suspension of the processing of your information. Send your request to the contact below and we will handle it without delay.
8. Contact
Privacy inquiries: a direct message to @juiceistravel on Instagram
If this policy changes, the updated version will be posted on this page together with its effective date.