Privacy Policy
DMForge · Last updated: 21 August 2026
DMForge is an automation tool that responds to direct messages sent to an Instagram business account. This page explains what it collects when you send such a message, why, and who else sees it.
What is collected
Data is collected only when you send a direct message to the Instagram account operating this instance and that message contains the configured trigger phrase. Messages without the trigger phrase are not stored.
- Your Instagram user ID
- Your Instagram username, where the platform makes it available
- The text of the message you sent
- The trigger phrase that matched
- The date and time of the message
- Whether the automated reply, notification email, and record sync succeeded
No passwords, payment details, contact lists, or message history beyond the triggering message are collected. DMForge cannot read messages sent to other accounts, and it does not read your profile beyond the fields listed above.
Why it is collected
To send you the automated reply you asked for, and to let the account operator follow up with you about that request.
Who it is shared with
The data is passed to the following service providers, each acting on the operator's behalf:
- Supabase — database storage
- Notion — record keeping
- Resend — delivery of the notification email
- Meta / Instagram — delivery of the reply back to you
Your data is not sold, rented, or used for advertising, and it is not shared with anyone else.
How long it is kept
Records are kept until they are deleted, either by the operator or at your request. There is no automatic expiry while the account stays connected.
Your rights
You can ask for a copy of the data held about you, ask for it to be corrected, or ask for it to be erased. Requests are handled by the operator at the contact address below. To stop any further collection, simply do not send messages containing the trigger phrase.
Deleting your data
Removing DMForge from your Instagram settings sends us a deletion request automatically. On receipt, everything stored about you is taken out of use at once: it stops being readable by the service, by the dashboard, and by anyone operating them. You are given a confirmation code and a link showing exactly what was removed.
The records are then held, unused, for 14 days before being erased permanently. That window exists so an account disconnected by mistake can be recovered: reconnecting it within the 14 days restores the records. After the window closes they are destroyed and cannot be recovered by anyone, including the operator.
If you would rather not wait for that window, or want your data destroyed immediately, ask the operator at the contact address below.
Security
Incoming requests are authenticated with a cryptographic signature from Meta, and credentials for the services above are held only on the server and never exposed to visitors.
Contact
For any request concerning your data, contact antongrytsenok@gmail.com.