How POROTTA handles Instagram comment and message data — what it collects, why, how long it keeps it, and how to have it deleted.
This policy explains how POROTTA ("POROTTA", "we", "us") collects, uses, stores and deletes information in connection with the POROTTA application (the "App"), a tool that replies to comments and sends direct messages on Instagram business accounts that have explicitly connected themselves to it.
POROTTA is a proprietorship registered in India under Udyam Registration Number UDYAM-KL-04-0089053, with its registered office at Ktp House, Kt pakkar haji nagar, kakkad, edechovva, Arayalthara, Kannur, Kerala 670005, India.
It applies to the App and to porotta.app.
Two groups are described here, and they are treated differently:
Connection runs through Meta's official OAuth flow. We never see or store an Instagram password. We receive and store:
When someone interacts with a connected account, Meta sends the App a webhook. We process and may store:
The App requests only what it needs to function:
instagram_business_basic — identify the connected account and confirm the connection is validinstagram_manage_comments — read comments on the connected account and post repliesinstagram_manage_messages — send and receive direct messages on the connected accountWe do not request advertising data, follower lists, insights, or access to any account other than the one the owner explicitly connects.
porotta.app may set standard cookies and collect ordinary server log data such as IP address, browser type and pages visited, for security and basic analytics. We do not use the website to build advertising profiles.
We do not sell personal data. We do not share it with advertisers. We do not use message or comment content to train machine learning models. We do not use it for any purpose unrelated to delivering the automation the account owner set up.
Disconnecting an Instagram account removes our ability to act on it and revokes the stored token.
Access tokens and application secrets are held in server-side configuration and are never exposed to the browser. Traffic between the App and Meta runs over HTTPS. Incoming webhooks are verified with an HMAC-SHA256 signature and rejected outright if the signature is missing or invalid, so the App will not act on a forged request. Administrative access is password protected.
No system is perfectly secure, and we cannot guarantee absolute security — but we do not retain more data than the App needs to function.
You may request access to, correction of, or deletion of the personal data we hold about you. You may also object to processing or withdraw consent at any time.
If you commented on, or messaged, an account that uses the App and want that record deleted, email us with your Instagram username and, if you have it, a link to the post or comment. You do not need an account with us to make this request.
We confirm and action a verified deletion request within 30 days, and sooner where we reasonably can. We may ask for information sufficient to confirm the request genuinely comes from you or from the account owner.
The App is intended for business use and is not directed at children under 13, or the minimum age required by local law. We do not knowingly collect personal data from children. If you believe a child's data has reached us, contact us and we will delete it.
We operate from India. Information processed by the App, and by Meta, may be transferred to and stored on servers outside your country. Where that happens we rely on appropriate safeguards and process no more than is needed to deliver the service.
We may update this policy as the App changes. The date at the top always reflects the current version. Material changes affecting how we use personal data will appear here before taking effect.
For any privacy question, or to make an access or deletion request:
If you are in a region with a data protection authority and believe we have not resolved your concern, you have the right to complain to that authority.