Legal
Privacy Policy
prtner is an AI assistant that helps small businesses manage their social media — copywriting, comment moderation, and direct-message replies on Instagram accounts they own or manage. This policy explains what data we process, why, and the choices you have.
prtner ("prtner", "we", "us") is operated by Limited Liability Partnership DNF (DNF Marketing), Almaty, Kazakhstan. For any privacy question or request, contact [email protected].
1. Who this policy is for
It covers two groups:
- Clients — businesses that connect an Instagram professional (Business or Creator) account to prtner.
- End users — people who comment on, or send messages to, a connected account. We process the content you send to a connected account only to help its owner respond to you.
2. Data we process
| Category | Examples | Source |
|---|---|---|
| Account profile | Instagram username, account ID, account type, follower & media counts | Meta (Instagram Graph API) |
| Content | Captions, comments, and direct messages on the connected account | Meta (Instagram Graph API / webhooks) |
| Access tokens | OAuth tokens that authorize prtner to act on the connected account | Meta, during connection |
| Operator identifiers | Telegram user, group, and topic IDs used for the human-approval interface | Telegram |
| Usage metadata | AI model, token counts, and cost estimates per request | Generated by prtner |
We do not sell personal data, and we do not use it to build advertising profiles or train third-party foundation models.
3. How we use it
- Read recent comments and messages on a connected account.
- Generate draft replies in the brand's voice using AI.
- Present every draft to the client's team for review — nothing is published without a human approval ("human in the loop").
- Post approved replies back to Instagram through official Meta APIs.
- Measure AI usage for cost and reliability.
4. Service providers (sub-processors)
We share the minimum data needed with infrastructure and AI providers that process it on our behalf under their own terms:
| Provider | Purpose |
|---|---|
| Meta Platforms | Instagram Graph API — read/publish content on connected accounts |
| Google Cloud (Vertex AI / Gemini) | Primary AI model for drafting replies |
| OpenRouter | Fallback AI model provider |
| Supabase (PostgreSQL) | Encrypted application database |
| Telegram | Operator interface for notifications and for reviewing and approving drafts |
| Hetzner | Server hosting (EU) |
5. Storage & security
- Access tokens used by database-backed services are encrypted at rest
(PostgreSQL pgcrypto). The Instagram notification monitor stores its current and previous
token records in access-restricted server files (
0600) inside an access-restricted directory (0700). These files are not stored in PostgreSQL and are not encrypted with pgcrypto; protection relies on host filesystem access controls. - All database access uses parameterized queries; secrets live in protected environment configuration and are not intentionally written to application logs.
- Traffic is served over HTTPS/TLS.
6. Retention
- Access tokens — kept while an account is connected. Revoking access at Meta immediately invalidates the token; local token records are removed after a verified deletion request or when the service is decommissioned.
- Comments & messages — in the notification monitor, a complete inbound event is held locally only while delivery to the authorized Telegram group is pending and is deleted after confirmed delivery. A delivery ledger retains only the Instagram message ID, delivery time, and Telegram message ID for deduplication and reliability. Failed pending events may remain until the delivery problem is resolved or the data is deleted. Other prtner workflows may retain drafts for a short operational window; lead records follow a configurable retention period (default 365 days).
- Telegram copies — notifications delivered to Telegram are not automatically deleted by prtner. Their retention is controlled by Telegram and the administrators of the configured group.
- Usage metadata — retained for accounting and reliability.
7. Deleting your data
You can have your data removed at any time:
- Disconnect the Instagram account, or revoke prtner in Instagram → Settings → Apps and websites. This immediately invalidates the token at Meta.
- Email a deletion request to [email protected] with the account username. We will delete associated local token records and personal data within 30 days and confirm by email. If relevant content remains in the configured Telegram group, its administrators must delete that copy separately.
8. Your rights
Subject to applicable law, you may request access to, correction of, or deletion of your personal data, and you may withdraw consent by disconnecting the account. Contact [email protected].
9. Children
prtner is a business tool and is not directed to children under 13 (or the minimum age in your jurisdiction). We do not knowingly collect their data.
10. Changes
We may update this policy; material changes will be reflected by the "Last updated" date above and, where appropriate, communicated to connected clients.
11. Contact
Limited Liability Partnership DNF (DNF Marketing) · Almaty, Kazakhstan · [email protected]
Data Deletion · Удаление данных
Data Deletion Instructions
You can have your data deleted at any time. No login is required — an email request is enough. Choose whichever applies to you:
- Clients (you connected an Instagram account): disconnect or revoke prtner in Instagram → Settings → Apps and websites. This immediately invalidates the token at Meta. To erase locally stored token records and associated records (drafts, logs, lead data), email [email protected] from the account's contact address with the Instagram username. We delete the data within 30 days and confirm by email. Copies already delivered to Telegram are subject to Telegram and group administrator retention controls.
- End users (you commented on or messaged a connected account): email [email protected] referencing the account and your username/handle. We remove your content from prtner and confirm.
Инструкция по удалению данных
Ты можешь удалить свои данные в любой момент. Вход не требуется — достаточно письма. Выбери подходящий вариант:
- Клиенты (подключили Instagram-аккаунт): отключите или отзовите доступ prtner в Instagram → «Настройки → Приложения и сайты». Это сразу аннулирует и делает токен недействительным в Meta. Чтобы стереть локальные записи токена и связанные данные (черновики, логи, данные лидов), напишите на [email protected] с контактного адреса аккаунта, указав Instagram-логин. Мы удалим данные в течение 30 дней и подтвердим письмом. Копии, уже доставленные в Telegram, хранятся по правилам Telegram и администраторов соответствующей группы.
- Конечные пользователи (комментировали или писали подключённому аккаунту): напишите на [email protected], указав аккаунт и свой ник/handle. Мы удалим ваш контент из prtner и подтвердим.