PostEngage replies to Instagram comments and DMs on accounts their owners connect to us. Doing that means holding messages other people wrote, so this notice is specific about what is held, why, and for how long.
This service is operated from India by POSTENGAGE.AI ("PostEngage", "we"). India's Digital Personal Data Protection Act, 2023 applies to us, and this notice is written against it.
Two different people are described here
The distinction matters, because our obligations differ.
You, the creator. You signed up, you connected an Instagram account, you pay us. For your data we are the Data Fiduciary — we decide why it is held and we answer to you for it.
The people who comment on your posts and message you. We hold their messages because you asked us to reply to them. For their data you are the Data Fiduciary and we are your Data Processor: we act on your instructions, we do not use their data for our own purposes, and we do not sell it, profile it, or move it into any other account.
If someone who messaged you asks us to delete what we hold about them, we tell them to ask you, and we help you do it.
What we collect
Your account
| Data | Why | Basis |
|---|---|---|
| Name, email address, timezone | To identify your account, send service email, and know when your quiet hours fall | You provided it to sign up |
| An irreversible hash of your password | To sign you in. The password itself is never stored, and cannot be recovered from the hash — see Security for how | You provided it to sign up |
| Sessions: IP address, browser user agent, last-seen time | To keep you signed in, to show you your own devices, and to let you end a session you do not recognise | Necessary to run the service securely |
| Sign-in events, including failed attempts | Security. You can see them on your own security page | Necessary to run the service securely |
Your Instagram connection
When you connect an account, Instagram sends us an access token and the basic profile of the account you authorised.
| Data | Why |
|---|---|
| Instagram user id, username, account type, profile picture URL | To show you which account is connected and to confirm it is a Business or Creator account, which the messaging endpoints require |
| The access token, encrypted at rest | To read comments and messages and to send your replies. It is encrypted with AES-256-GCM under a versioned key and appears in no log, no API response and no error message |
| The permissions you actually granted, and the token's expiry | So that when something fails we can tell you whether Instagram refused it or you never granted it, and so we can warn you seven days before the connection lapses |
| Connection history: connected, refreshed, expiring, revoked, disconnected | So a connection that stops working is visible to both of us instead of failing silently |
The basis is your consent, given in Instagram's own permission dialog. You can withdraw it at any time, from PostEngage or from Instagram, and we stop.
Conversations on your connected accounts
We receive comments and messages by webhook from Meta. We do not poll your account and we do not read anything Instagram does not send us for the permissions you granted.
For each one we store the message text, the sender's Instagram id and username and profile picture, the timestamp, the media it relates to, and what we did about it. We store the replies we send and the replies you send by hand from our inbox.
We build a contact record per person who talks to your account, holding their Instagram handle, when they last messaged, and facts they stated themselves — so that your automation does not ask a returning customer the same question twice.
We build a lead when someone types an email address or a phone number into a message. We extract what the person themselves typed. We do not look up, buy, guess, or enrich contact details, and we do not have a directory of people to look them up in.
Your automations and what they produced
Automation definitions and templates you write. Knowledge documents you upload. Run records and action records. A row for every decision the policy gate made — allowed or refused, which check decided it, and the sentence you see in your Blocked view. Held replies waiting for your approval.
Your voice profile
If you use AI replies, we build a voice profile from replies you wrote — their length, their punctuation, the phrases you actually use. It is derived from your own words and nothing else. It is not shared between accounts, it is not used to train a general model, and it is deleted when you delete your account.
Payments
Name, billing country, GSTIN if you give us one, the processor's payment id, amount, currency, the invoice, and the credits it bought. No card number, UPI PIN or bank credential ever reaches our servers — both processors run their own hosted checkout and we never see those fields.
Where a language model comes into it
An AI reply is generated by a language model, which means the incoming message and the relevant part of your voice profile are sent to our model provider for the length of that one request. Our provider is Anthropic PBC, reached through the Claude API and processing in the United States. Separately, when we build the search index that finds the relevant part of your voice profile, the text being indexed is sent to Voyage AI, also in the United States, to be turned into a vector.
Both are cross-border transfers under the Act, and both are limited to the text needed for that one operation.
The provider does not receive your account credentials, your Instagram token, your contact list, or your payment details. Message content is sent for generation only, not for training.
Where it is stored
On servers in India, in one PostgreSQL database, on infrastructure rented from Hostinger. Media and uploaded documents sit in our own object storage on the same machines rather than in a third-party bucket. Traffic is encrypted with TLS in transit.
Who else sees it
| Recipient | What they get | Why |
|---|---|---|
| Meta Platforms (Instagram Graph API) | The reply text we send on your behalf, and the API calls needed to read comments and messages | It is the only way to act on your Instagram account. Meta's own handling is governed by their terms, not ours |
| Razorpay Software Private Limited | Name, email, amount, currency for INR payments | To take the payment |
| Stripe, Inc. | Name, email, amount, currency for payments outside India | To take the payment |
| Our hosting provider (named above) | Everything, as the infrastructure it runs on | The servers have to be somewhere |
| Anthropic PBC (United States) | The message being answered and the relevant part of your voice profile | To draft an AI reply |
| Voyage AI (United States) | The voice-profile and knowledge text being indexed | To turn it into a vector so the right passage can be found |
| Hostinger | Your email address and the contents of service email | Sign-in links, receipts, connection warnings |
Our transactional email provider is Hostinger, over authenticated SMTP.
That is the complete list. There is no advertising network, no analytics broker, no data enrichment service, and no affiliate pixel.
What we never do
- Sell personal data, or share it for anyone else's marketing.
- Use one creator's conversations to train anything another creator sees.
- Track you across other websites. The product sets one session cookie, which is why there is no cookie banner.
- Read anything on Instagram that the permissions you granted do not cover.
- Post content, run ads, or follow accounts on your behalf.
How long we keep it
Retention is enforced by the database, not by a reminder. Tables are partitioned by month and old partitions are dropped on schedule.
| Data | Kept for |
|---|---|
| Messages, conversations, automation runs and actions, lead activity, AI generation records | 396 days |
| Held replies awaiting your review | 90 days |
| Raw webhook deliveries, policy gate decisions, model service logs | 30 days |
| Records of administrative access to your account | 400 days |
| Account, connection, contact, lead, automation and voice profile data | Until you delete it, or until the account is deleted |
| Invoices and payment records | Eight years, as Indian tax law requires. After erasure these hold an account id rather than your name |
Your rights
The Act gives you four, and each one is a real function rather than an email address that goes to a queue.
Access. Export everything we hold about you, as a file you can open — the conversations, the contacts, the leads, the runs, the ledger, the sessions. Not a database dump.
Correction. Your name, email and timezone are editable in the app. Derived data — the voice profile, contact facts, details pulled out of a message — is corrected by deleting it and letting it rebuild, because editing a derived value would be overwritten by the next run. The app says so where it applies rather than offering a text box that quietly does nothing.
Erasure. Delete your account from Settings. Instagram disconnects immediately, the deletion runs after seven days, and you can cancel during those seven days. The detail of what goes and what stays is on the data deletion page.
Nomination. You may nominate one person, by email, to exercise these rights if you die or become incapable of exercising them yourself. It is in Section 14 of the Act, almost nobody offers it, and it is in your account settings.
To use any of them, sign in and go to Settings, or write to the grievance officer below. We answer within 30 days and usually within two working days.
Grievance officer
If we get something wrong, this is the person responsible for putting it right.
- Name: Sanjeev Sharma
- Designation: Founder and proprietor, POSTENGAGE.AI
- Email: grievance@postengage.ai
- Post: Delhi, India. Email reaches the same desk, faster.
At this size the grievance officer and the person who writes the code are the same person, which is worth saying plainly: there is no escalation tier above this one and no queue in front of it.
If you are not satisfied with our answer, you may complain to the Data Protection Board of India.
If there is a breach
We keep a breach register with a clock on it. When we become aware of a personal data breach we assess it immediately, notify the Data Protection Board within 72 hours, and notify every affected person without delay, telling them what happened, what was exposed, and what to do about it.
We built the query that answers "who was affected" before we needed it, because writing it during an incident is how the number comes out wrong.
Children
PostEngage is for people aged 18 and over, and we do not knowingly open accounts for anyone younger. We do not profile, track, or target advertising at anyone, which includes children who may comment on a creator's post.
If you believe a child's data has reached us, write to the grievance officer and we will remove it.
Changes
When this notice changes materially we email account holders before it takes effect and change the date at the top. Older versions are available on request.