Privacy Policy: HitDM
Last updated: 2026-10-05
AD Tech Services, India ("we") runs HitDM at https://hitdm.com. HitDM helps creators and businesses send Instagram comment-to-DM automations on Meta's official Instagram Graph API path. This policy explains what we collect, why, and your choices.
We act as the data controller (or "data fiduciary" under India's DPDP Act) for your HitDM account data. For Instagram contacts, comments, DMs, and lead responses collected through your automations, you are the controller and we are the processor.
Status note: HitDM has not completed Meta App Review. Instagram messaging features depend on Meta approving the app and granting the permissions we request. We do not claim Meta Partner, Tech Provider, or App Review approval until that is true.
1. Information we collect
| Data | Why | Legal basis |
|---|---|---|
| Account information: name, email, and profile picture (Google sign-in or magic link) | Create and secure your account | Contract |
| Instagram account information: handles, profile pictures, Instagram Business or Creator account ids, Facebook Page ids, connection status, and access tokens (stored encrypted, never in plaintext) | Connect your Professional Instagram account and run automations | Contract |
| Contacts and messages: comment text, Instagram scoped ids, DM delivery status, and related Meta event data delivered to HitDM | Match keywords, send DMs, meter usage, and show results | Contract |
| Automation configuration and run logs: keywords, target posts/Reels, DM templates, tracked links, lead questions, and send history | Run and debug your automations | Contract |
| Optional lead responses people send in DM after your automation asks | Store leads you choose to collect for your business | Contract (you as controller) |
| Billing information: plan, dates, and subscription status via Dodo Payments. We never store full card details | Give you access to paid features | Contract |
| Usage and device data: pages visited, clicks, feature use, web vitals, browser, and salted or truncated IP for rate limits and abuse prevention (PostHog EU; no advertising IDs or session recordings) | Improve the product, fix bugs, keep the Service secure | Legitimate interest / consent where required |
| Error events (exception type/message/stack, scrubbed of emails and tokens) via PostHog | Keep the Service working | Legitimate interest |
We do not sell or rent your data. We do not use your data or your contacts' messages to train AI models. We do not use session recording or heatmaps.
2. How we use your information
- Run comment-to-DM and related automations you configure
- Bill Free and Pro plans through Dodo Payments
- Prevent abuse and stay within Meta platform rules
- Respond to support and send transactional product updates
- Measure product usage in aggregate
3. Meta Platform and Instagram data
HitDM uses Meta's Graph API and Instagram messaging APIs (official path only; not password or browser bots). When you connect Instagram:
- Meta shares account and messaging data with us under Meta Platform Terms and your Meta login consent
- We store access tokens encrypted at rest and use them only to run your automations and show account status
- Comment and DM events arrive from Meta (including webhook deliveries). We verify authenticity before processing
- Disconnecting Instagram in Settings or deleting your HitDM account removes stored Meta tokens from active systems as described on https://hitdm.com/data-deletion
You must only connect accounts you own or are authorized to manage. You are responsible for notices and consent for people you message or whose lead data you store.
4. Who we share data with (sub-processors)
We share data only as needed to run the Service:
- Meta (Instagram / Facebook): API calls and event notifications required for automations
- Dodo Payments: subscription checkout, tax, and invoices (merchant of record)
- Cloudflare: Workers hosting, D1 database, R2 storage, KV
- Resend: transactional email
- PostHog EU: product analytics and error tracking (no session recording)
- Google: sign-in when you choose Google OAuth
They process data only to provide their service to us.
5. AI processing
We don't send your content to AI providers.
6. Data retention
| Item | Retention |
|---|---|
| Account information | While your account is active |
| Access tokens | Until you disconnect Instagram in Settings, or delete your account |
| Messages, contacts, automation configs, and run logs | While active; deleted from active systems within 30 days of account closure |
| Server / analytics operational logs | Up to 90 days where applicable |
| Payment and tax records | As long as tax law requires (held by Dodo Payments and us) |
| Encrypted backups | Purged within 90 days after deletion |
Instagram access tokens are removed when you disconnect in Settings or delete your account. Automation rules, contacts, leads, and run logs are deleted from active systems within 30 days of account closure. See /data-deletion for Meta App Review instructions.
7. Your rights
You can access, correct, export, or delete your data, withdraw consent, and complain to a data protection authority. Ways to act:
1. Disconnect Instagram in HitDM Settings (Connected accounts → Disconnect). This removes active Meta tokens and pauses automations. 2. Correct profile details in Settings / Profile where available. 3. Delete your HitDM account from Settings when available, or email hello@hitdm.com. 4. Follow the full instructions on https://hitdm.com/data-deletion (also the URL for Meta App Review data-deletion instructions).
We reply within 30 days. For Instagram contacts and leads you collected as controller, email us and we will delete processor copies we hold or help you clear them from your account.
8. Cookies
We use necessary cookies to keep you logged in. Product analytics (PostHog EU) may use a first-party cookie or local storage for an anonymous id. We do not use session recording or heatmaps. Respect Do Not Track when your browser sends it. We do not use third-party advertising cookies.
9. Security
Data is encrypted in transit (HTTPS/TLS). Access tokens are encrypted at rest. Access is limited to what is needed to run the Service. Paid access is granted only after Dodo Payments confirms the purchase. No system is perfectly secure; if a breach affects your data we will tell you promptly.
10. International transfers
Our providers may process data outside your country (for example in the US or EU) under their standard data protection terms. PostHog processes analytics in the EU cloud region. Meta may process Instagram data per Meta's terms.
11. Children's privacy
The Service is not directed to anyone under 18.
12. Changes
We will post updates here. For material changes we aim to give about 14 days' notice by email or in-app when we can.
13. Contact
hello@hitdm.com