dmrabbit.
BlogDocsPricing
Get started

legal

Privacy Policy

Last updated: September 2, 2026

This policy explains what dmrabbit does with personal information: whose it is, why we have it, who else sees it, and how long we keep it. It applies to our website, the dmrabbit dashboard, and the public bio pages our customers publish.

1. Who we are

dmrabbit is a service operated by Spexoid Tech Pvt. Ltd., a company registered in India. We are the data controller for the information described in section 3. You can reach us about anything in this policy at privacy@dmrabbit.com.

2. Two different sets of people

This matters more than it looks, because your rights depend on which one you are.

Customers. If you signed up for dmrabbit, we decide how your account information is handled and we are responsible for it. Sections 3 to 10 are about you.

People who interact with a customer's Instagram account. If you commented on a post or sent a message to a business that uses dmrabbit, the business decides what happens to that conversation. We only store and process it on their instructions, as their service provider. We do not use it for our own purposes, and we never sell it. If you want that conversation deleted, ask the business directly; you can also write to us at privacy@dmrabbit.com and we will pass it on and help them act on it.

3. What we collect about customers

  • Your account. Email address, name, and a profile photo if you upload one. There is no password on a dmrabbit account. If you sign in with Google, we store the permanent account identifier Google gives us, plus the name and photo on your Google profile.
  • Your sign-ins. For each active session: browser and device description, IP address, country, and when it was last used. This is what powers the device list in your security settings, so you can see and end a session you do not recognise.
  • Billing. Your plan, billing country and currency, and a record of each payment. Card and bank details go straight to our payment providers and never reach us.
  • Support. The tickets and messages you send us.
  • How you found us. The site that linked you to us and any campaign tags on the link. We do not collect this at all from visitors in the EEA or the UK. See section 9.
  • Technical records. Server and error logs, which include an account identifier and the page an error happened on, so we can find and fix faults.

4. What we handle on your behalf

When you connect an Instagram professional account, we use the official Instagram API and only the permissions you granted on Instagram's own consent screen. Through it we receive your Instagram profile details, the comments and direct messages on that account, your media and its insights, and an access token that lets us act within those permissions. We never ask for your Instagram password, and we never touch an account you have not connected.

The conversations this produces are personal information about the people who wrote them. You are responsible for that data and we handle it for you, as described in section 2.

5. Why we use it, and on what legal basis

  • To run the service you asked for - your automations, your inbox, your bio pages, your dashboard. Basis: performance of our contract with you.
  • To take payment and keep accounting records. Basis: performance of our contract, and our legal obligations under Indian tax law.
  • To answer your support requests. Basis: performance of our contract.
  • To keep the service secure and working - detecting abuse, rate limiting, diagnosing errors, and alerting us when something breaks. Basis: our legitimate interest in operating a service that stays up and is not abused.
  • To understand where our customers come from. Basis: our legitimate interest in knowing which of our own efforts work. We do not do this for visitors in the EEA or the UK.

We do not sell personal information, we do not use it for advertising, and we do not use your Instagram data for anything except providing the service to you, in line with the Meta Platform Terms.

6. Who else sees it

We use a small number of specialist providers to run the service. Each one gets only what it needs for its job, under a contract that requires it to protect the data and use it for nothing else.

  • Meta Platforms - Instagram itself, which is where the automation happens.
  • Razorpay and Polar - payments. They handle card and bank details so that we do not.
  • PurelyMail - sending the emails we send you.
  • ImageKit - storing and serving images you upload for bio pages.
  • Axiom - storing our server and error logs.
  • OpenAI - the assistant that answers first on a new support ticket. It receives your ticket and a short summary of your plan and usage. It is not used anywhere else in dmrabbit.
  • Our hosting provider - the servers dmrabbit runs on.

We also disclose information if the law requires it, and to a buyer if the business is ever sold, in which case this policy continues to apply until you are told otherwise.

7. Where your information is held

dmrabbit is operated from India, and our staff access personal information from there. Several of the providers in section 6 are outside India and hold data in their own regions.

If you are in the EEA or the UK, this means your information is transferred outside it. India has not been recognised by the European Commission as providing an equivalent level of protection, so such transfers must rely on approved contractual safeguards. Write to privacy@dmrabbit.com if you would like details of the safeguards that apply to your data.

8. How long we keep it

  • Your account information - for as long as your account exists. Delete your account and it goes, as described on our data deletion page.
  • Conversations and contacts from a connected Instagram account - while it is connected, and for 90 days after you disconnect it. Reconnect within those 90 days and everything is still there. After that it is deleted and cannot be recovered.
  • Automation activity history - 12 months.
  • A note that an account was deleted, and when - 12 months, in our security and operations logs. It is not used to contact you or to rebuild your account.
  • Payment records - 8 years, because Indian tax law requires it. After you delete your account these records are no longer connected to your name or email.

9. Cookies and similar storage

dmrabbit does not use advertising cookies, third-party tracking, or an analytics service that follows you between sites. There is nothing here to opt out of, which is why you have not been shown a cookie banner. What we do store on your device is:

  • A sign-in cookie, which is what keeps you signed in.
  • Two short-lived security cookies, set while you are connecting Instagram or signing in with Google, which protect those steps from being hijacked.
  • A cookie holding the email address you just typed, so the second half of signing in knows who asked for the code.
  • A referral cookie, only if you arrived on a link containing a referral code, so the person who referred you is credited when you sign up.
  • A cookie recording which site sent you to us, so we can tell which of our own efforts work. This one is not set at all if you are in the EEA or the UK.

The dashboard also remembers small preferences in your browser's own storage, such as your having dismissed the prompt to install the app. Those never leave your device.

10. Your rights

You can exercise most of these yourself, without asking us:

  • Get a copy of your data. Settings has a download that gives you everything we hold, in a machine-readable file.
  • Delete your data. See the data deletion page.
  • Correct your details. Your name and photo are editable in Settings.

If you are in the EEA or the UK you also have the right to object to or restrict processing based on our legitimate interests, to withdraw consent where we relied on it, and to have your data transferred to another provider. Email privacy@dmrabbit.com and we will answer within one month. If you are not satisfied with our answer, you can complain to the data protection authority in the country where you live or work.

11. Security

Instagram access tokens and session identifiers are stored so that they cannot be read back out of a data export, and the export is deliberately built to exclude every credential. Traffic is encrypted in transit. Sensitive and expensive actions are rate limited. No system is perfectly secure, but if a breach affects you we will tell you and the relevant regulator as required.

12. Children

dmrabbit is for businesses and is not intended for anyone under 18. We do not knowingly collect information about children.

13. Changes

If we change this policy we update the date at the top of this page, and for anything significant we tell you inside the app or by email.

14. Contact

Spexoid Tech Pvt. Ltd.
Email: privacy@dmrabbit.com

dmrabbit.

Automated Instagram comment replies and DMs. Set your rules once and let them run.

Product

  • How it works
  • What it does
  • Biopages
  • Inbox
  • Referrals
  • Pricing

Company

  • Blog
  • Docs
  • Contact
  • Status

Legal

  • Terms of service
  • Privacy policy
  • Refunds and cancellation

Your data

  • Delete your data
  • Cookies
  • Acceptable use
  • Sub-processors

© 2026 dmrabbit

  • llms.txt
  • llms-full.txt
  • sitemap.xml

Not affiliated with, endorsed by or sponsored by Instagram or Meta.