Privacy Policy
Last updated: September 6, 2026
1. Introduction
This Privacy Policy explains how DMDroid ("we," "us," or "our") collects, uses, stores, and protects information when you use the DMDroid Chrome extension and the DMDroid dashboard. By installing or using DMDroid, you consent to the practices described in this policy.
DMDroid is an Instagram direct-message automation tool designed for agencies and founders. It runs as a Chrome browser extension that automates sending follow-up messages on your behalf.
2. Information We Collect
2.1 Account Information
- Email address (used for login authentication)
- DMDroid account password (transmitted to our backend for authentication only; not stored by the extension)
- DMDroid user ID (internal account identifier)
2.2 Instagram Account Data
- Your Instagram username and user ID (detected from your active Instagram session)
- Your Instagram profile picture URL
- Instagram authentication data read from your active browser session is used only in-memory to operate the extension and is never uploaded to our servers
2.3 Campaign and Contact Data
- Target lists you create or upload (list names, descriptions)
- Contact information you provide (Instagram usernames, full names)
- Contact data enriched from your Instagram account: display names, profile picture URLs, conversation thread IDs, reachability status
- Follower and following lists from your Instagram account, used for building target lists
2.4 Message and Conversation Data
- Instagram direct-message content (text, timestamps, sender information) from your campaign conversations
- Read receipt status (whether a contact has seen your message, and when)
- Reply detection data (whether a contact has replied)
- Recent conversation history (rolling window for unified inbox sync)
2.5 Browser and Device Data
- Browser instance identifier (unique ID, persisted across sessions)
- Browser display label (your Instagram username)
- Chrome extension version number
- Operating platform and browser user agent string
- Chrome tab IDs for managed Instagram tabs
2.6 Engine and Diagnostic Data
- Task execution logs (success, failure, timing)
- Engine diagnostic events (session state, errors)
- Heartbeat signals (sent periodically to confirm browser is active)
2.7 Data Collected Automatically
When the extension or our websites communicate with our backend, our infrastructure provider automatically receives and records standard technical information, including:
- IP address (transmitted as part of every network request and recorded in server logs)
- Server request logs (timestamps, request types, response status)
- Device and browser information (user agent, operating system)
This data is used only to operate, secure, and troubleshoot the service.
2.8 Local Storage Data
The extension stores the following locally on your device using Chrome's built-in storage API:
- Authentication tokens (access token, refresh token)
- Browser identity keys
- Task statistics (completed/failed counts)
- Tab management IDs
- Engine state flags (paused, disconnected)
- Diagnostic logs and events
- Conversation watermark timestamps (per thread, per browser instance, used to avoid re-syncing messages you have already sent)
3. How We Use Your Information
We use the collected data for the following purposes:
- Campaign Execution: Sending and scheduling Instagram direct messages on your behalf, tracking message delivery, and managing follow-up sequences.
- Reply Detection: Monitoring your Instagram conversations to detect when a contact replies, so we can pause follow-ups and mark the contact as replied.
- Read Receipt Tracking: Checking whether your messages have been seen by contacts.
- Collision Prevention: Ensuring the same message is not sent twice to the same contact.
- Safety Limits: Respecting work-hour settings and rate limits to protect your Instagram account.
- Unified Inbox: Synchronizing conversation data to enable viewing your messages across devices.
- Account Pairing: Linking your DMDroid account to your Instagram username for multi-account management.
- Troubleshooting: Debugging engine errors and resolving support requests.
4. How Your Information Is Shared
4.1 We Do Not Sell Your Data
We do not sell, trade, or rent your personal information to third parties.
4.2 Data Shared With Your Consent
- Your campaign data is shared with Instagram's servers when DMDroid sends messages on your behalf (this is how DM automation works).
- You may share your DMDroid dashboard with team members if you use the multi-user features.
4.3 Legal Requirements
We may disclose your information if required by law, court order, or governmental request.
4.4 Service Providers
We use Supabaseas the backend infrastructure provider for the DMDroid extension and dashboard. Supabase hosts our database and authentication services, and your extension and dashboard data is stored on Supabase's cloud infrastructure. Supabase operates under strict data processing agreements.
4.5 No Other Third Parties
The DMDroid extension does not integrate with analytics services, error tracking services, advertising networks, or any other third-party data processors. All data the extension handles goes only to our own backend (Supabase-hosted) and to Instagram as needed to perform the actions you request.
5. Browser Extension Permissions
DMDroid requests the following Chrome permissions:
- storage: Stores your authentication tokens, browser identity, task statistics, and engine configuration locally on your device.
- tabs: Opens and manages Instagram browser tabs for campaign execution. Reads tab URLs to verify you are on Instagram.
- alarms: Schedules recurring tasks: heartbeat signals, task polling, token refresh, message collection, and conversation sync.
Host Permission: Instagram
The extension runs on Instagram pages to:
- Read your logged-in Instagram account information (username, user ID)
- Access your direct-message threads to send and read messages
- Compose and send messages through Instagram's messaging interface
- Read message read receipts
- Access your follower and following lists to build target lists
6. Data Stored Locally on Your Device
The extension stores data locally on your device using Chrome's built-in storage API. This data never leaves your device unless it is sent to our backend via API calls described in this policy.
Data stored locally includes:
- Supabase authentication tokens (access token, refresh token)
- Your browser instance ID and display label
- A persistent browser identity key that identifies your physical browser across sessions
- Task completion statistics
- Chrome tab IDs for managed Instagram tabs
- Engine state (paused, disconnected, sleep/wake configuration)
- Diagnostic logs and structured event data
- Conversation watermark timestamps (used to avoid re-syncing messages you have already sent)
No cookies are set or read by the extension. Authentication is handled via secure tokens in HTTP headers.
7. Data Retention
7.1 Server-Side Data
We retain your data on our servers for as long as your account is active. This includes campaign and contact data, message and conversation data, browser instance records, and account settings.
7.2 Local Data
Data stored locally on your device persists until you uninstall the extension (all local data is removed) or clear the extension's storage manually via Chrome settings.
7.3 Account Deletion
When you delete your DMDroid account:
- We will remove your server-side data within 30 days
- Local data on your device will remain until you uninstall the extension
- Watermark data (conversation timestamps) will persist in local storage
8. Your Rights Under GDPR (EEA Users)
If you are located in the European Economic Area (EEA), you have the following rights under the General Data Protection Regulation:
- Right to Access: Request copies of all personal data we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete data.
- Right to Erasure: Request deletion of your personal data (subject to legal retention requirements).
- Right to Restrict Processing: Request that we limit how we use your data.
- Right to Object: Object to our processing of your personal data for specific purposes.
- Right to Data Portability: Request your data in a structured, machine-readable format.
To exercise these rights, contact us at support@dmdroid.app. We will respond within 30 days.
9. Your Rights Under CCPA (California Users)
If you are a California resident, the California Consumer Privacy Act (CCPA) grants you the following rights:
- Right to Know: Request disclosure of the categories and specific pieces of personal data we have collected about you.
- Right to Delete: Request deletion of personal data we have collected about you.
- Right to Opt-Out of Sale: We do not sell your personal data. You have the right to opt out of any future sale, which we will honor.
To exercise these rights, contact us at support@dmdroid.app. We will respond within 45 days.
10. Instagram Data Access
DMDroid accesses Instagram through your browser session to provide its automation features. We do not store your Instagram password. The extension accesses Instagram data by:
- Reading your active session: Detecting your logged-in Instagram username and user ID.
- Accessing DM threads: Reading your direct-message threads to send follow-up messages and detect replies.
- Sending messages: Composing and sending messages through Instagram's messaging interface.
- Reading read receipts: Checking whether your contacts have seen your messages.
- Accessing followers/following: Reading your follower and following lists to build target lists for campaigns.
This data access occurs entirely within your browser. The extension does not use Instagram's official API. It interacts directly with Instagram's web interface.
Important: By using DMDroid, you authorize the extension to access and act on your Instagram account. You are responsible for ensuring your use complies with Instagram's Terms of Service.
11. Data Security
We implement the following security measures:
- Encryption in transit: All API communication uses HTTPS/TLS encryption.
- Token-based authentication: Your DMDroid password is transmitted to our backend (Supabase) for authentication only. After login, we use secure tokens for ongoing API authentication. Passwords are never stored by the extension or in any local storage.
- No remote code: DMDroid contains no remote code execution. All extension code is bundled locally in the Chrome extension package.
- Local-first data: Sensitive data (auth tokens, watermarks, logs) is stored locally on your device.
However, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security of your data.
12. Children's Privacy
DMDroid is not directed to individuals under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that we have collected data from a child under 13, we will delete it promptly. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at support@dmdroid.app.
13. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last Updated" date at the top of this page and notify you via the DMDroid extension or email (if you have provided one). Your continued use of DMDroid after any changes constitutes acceptance of the updated policy.
14. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us:
- Email: support@dmdroid.app
- Website: https://dmdroid.app
15. Chrome Web Store Compliance and Limited Use
DMDroid complies with the Chrome Web Store Developer Program Policies:
- Single Purpose: DMDroid automates Instagram direct-message follow-up sequences.
- No Remote Code: The extension contains no remote code. All functionality is bundled in the extension package.
- No Deceptive Practices: The extension does not misrepresent its functionality or data collection.
- User Disclosure: This Privacy Policy fully discloses all data collected, stored, and transmitted.
- Permission Justification: Each requested permission (storage, tabs, alarms) is necessary for core functionality as described in Section 5.
- Secure Transmission: All data is transmitted over HTTPS/TLS. No data is transmitted over insecure HTTP connections.
Limited Use of User Data
Your use of DMDroid is subject to the Chrome Web Store Limited Use Requirements, and DMDroid's use of your data complies with them as follows:
- Allowed use only: DMDroid uses the permissions and the data it collects only to provide and support its single purpose: automating and managing your Instagram direct-message outreach. Your data is never used for unrelated purposes such as profiling or market research.
- Allowed transfer only: Your data is transferred only as necessary to provide the extension's features (to our backend and to Instagram), to comply with applicable laws, or to protect security and investigate abuse. We do not sell, rent, or trade your personal information, and we do not transfer it to data brokers or advertising networks.
- No advertising use: Your data is never used or transferred to serve personalized, re-targeted, or interest-based advertisements.
- No human reading of your data: We do not read your messages, contacts, or campaign content except (a) with your explicit consent when you request support, (b) as necessary for security or abuse investigation, (c) as required by law, or (d) in aggregated, anonymized form for internal operational statistics.
16. Data Collection Summary
| Data Category | What We Collect | Where It Is Stored | How It Is Used |
|---|---|---|---|
| Account info | Email, password, DMDroid user ID | Supabase (server) | Authentication (password transmitted for login only, not stored) |
| Instagram account | Username, user ID, profile pic | Local + Supabase | Account pairing, task execution |
| Campaign data | Target lists, message templates | Supabase (server) | Campaign configuration |
| Contacts | Usernames, full names, thread IDs, reachability | Supabase (server) | Message targeting, collision prevention |
| Followers/following | Follower and following lists | Supabase (server) | Target list creation |
| Messages | DM text content, timestamps, sender info | Supabase (server) | Unified inbox, reply detection |
| Read receipts | Seen status, seen timestamps | Supabase (server) | Reply detection |
| Browser metadata | Platform, user agent, extension version, IP address (server logs) | Supabase (server) | Compatibility, heartbeat, service operation |
| Auth tokens | Access/refresh tokens | Local (device storage) | API authentication |
| Watermarks | Per-thread timestamps | Local (device storage) | Prevent re-syncing messages |
| Diagnostic logs | Task outcomes, errors, events | Local (device storage) | Troubleshooting |
| Engine state | Pause, sleep/wake, tab IDs | Local (device storage) | Engine management |