Privacy policy
What we hold, and how to get rid of it.
In effect 26 August 2026
FollowerCRM reads the comments on your own Instagram posts so you can answer them one at a time. That is the only reason we hold anything. This page says exactly what lands in the database, who else can see it, and how to make it go away.
The short version
- We hold your account, your Instagram posts and their comments, and the contact files built from them.
- We use it to run the product for you. Nothing else.
- We do not sell it, advertise against it, or train models on it.
- Disconnecting Instagram deletes the token and the synced posts and comments. Email us and the whole workspace goes.
01
What we collect
Four kinds of thing, and no more than these.
- You give us
- Your name and email address, a password (stored only as a bcrypt hash, never in readable form), the name of each workspace you create, and the email address of anyone you invite to it. Sign in with Instagram instead and you give us none of that: Instagram tells us no email address, and there is no password to store.
- Instagram gives us
-
When you connect an account, we ask Meta for the
instagram_business_basicandinstagram_business_manage_commentspermissions and nothing else. With those we sync: your Instagram user ID, username, display name, account type, profile picture, and follower, following and media counts; your posts, with their captions, media and thumbnail URLs, permalinks, like and comment counts and timestamps; and the comments on those posts, with their text, timestamps, like counts, and the user ID and username of whoever wrote them. We also hold the access token itself, encrypted. - Instagram signs you in
- If you sign in with Instagram, we keep the Instagram user ID, username, display name and profile picture of the account you signed in with. That record is your way back in — it is what recognises you next time — and it is all we get: the sign-in carries no email address and no password.
- We build
- Everyone who comments becomes a contact file: their username, Instagram user ID, display name, bio, profile picture, whether they follow you, and a timeline of every comment and reply. On top of that sits whatever you add by hand — stage, tags, notes, an email address or phone number you know from somewhere else — and the replies you write, with their delivery status.
- The server records
- Each sign-in stores the IP address and browser user agent of the session, so you can see and revoke it. Ordinary web server logs keep request paths and timestamps for a short period.
02
What we do with it
We use it to run the product you asked for: to show you a queue of unanswered comments, to post your reply back to Instagram as you, to build and display contact files, to keep your workspace and its members separate from everyone else's, and to email you about your account — password resets, invitations, and the rare notice that something has broken or changed.
In legal terms: we process this data to perform the contract you have with us, and, for security and abuse prevention, on the basis of our legitimate interest in keeping the service standing up.
03
What we never do
- Sell or rent your data, or anyone's, to anybody.
- Use it to target advertising, here or anywhere else.
- Train machine learning models on your posts, comments or contacts.
- Ask for direct message access. The permissions we request cannot read DMs.
- Post anything to your account except a reply you typed and sent yourself.
- Read or sync comments on posts that are not yours.
04
Who else touches it
A short list, and each one only handles what it needs to do its job.
- Fly.io
- Hosts the application and the PostgreSQL database it writes to, in the United States.
- Meta
- The source of the Instagram data and the destination of your replies. Their handling of it is governed by Meta's own privacy policy.
- Email delivery
- Our email provider processes the recipient address and body of transactional mail — password resets and workspace invitations.
- Google Fonts
- Our pages load their typeface from Google's font service, which sees your IP address in the process.
We will also hand over data where the law genuinely requires it, and we would tell you unless we were forbidden from doing so. If the service is ever sold or merged, your data moves with it under this same policy, and you would be told before anything changed.
05
Instagram data specifically
FollowerCRM is not affiliated with, endorsed by or sponsored by Meta or
Instagram. We use Instagram's official API, under Meta's Platform Terms and
Developer Policies, with permissions granted by you and revocable by you at any
time — from this app's disconnect button, or from Instagram's own
Settings → Website permissions → Apps and websites.
Revoking from Instagram's side stops all future syncing immediately. To also remove what has already been synced, use the section below.
06
Keeping and deleting it
We keep what you hold for as long as your workspace exists. There are three levers for getting rid of it.
-
Disconnect Instagram
In the app, open
Instagramand press Disconnect. The access token is deleted, syncing stops, and every synced post and the comments on it are deleted with it. Contact files and your own notes and tags are deliberately kept — they are your records, not Instagram's. Deleting a contact removes its notes, tags and timeline too. -
Delete a workspace
Email leo.majowka@gmail.com from the address on the account, naming the workspace. Everything belonging to it — the Instagram connection and token, posts, comments, contacts, notes, tags, replies and members — is deleted within 30 days, and sooner in practice.
-
Delete your account entirely
Same address, say so, and your user record and every workspace you alone own goes with it. We will confirm by email when it is done. Asking Meta to delete your data also deletes the Instagram sign-in, which is the only way back in for an account that has no password — that is what deleting it means.
Encrypted database backups may hold deleted rows for up to 30 more days before they roll off. Nothing is restored from them except to recover the service from failure.
07
If you commented on someone's post
Then you may be in this database without ever having signed up, because the creator whose post you commented on connected their account to us. They are the controller of that record; we hold it on their behalf.
Ask them, or write to leo.majowka@gmail.com with your Instagram handle and we will find the record, tell you what it contains, and delete it on request. Deleting your comment on Instagram also removes it here at the next sync.
08
Security
- In transit
- HTTPS everywhere, forced. There is no unencrypted route into the app.
- Tokens
- Instagram access tokens are encrypted at rest with application-level encryption, separate from the database's own.
- Passwords
- Hashed with bcrypt. We cannot read yours, and neither can anyone who takes the database.
- Separation
- Every record belongs to exactly one workspace, and every query is scoped to it. No workspace can read another's queue.
No system is perfect. If you find a hole, write to leo.majowka@gmail.com and we will take it seriously and act quickly.
09
Your rights
Wherever you live, you can ask us for a copy of what we hold about you, ask us to correct it, ask us to delete it, or object to us holding it. Write to the address below and we will answer within 30 days. We do not charge for this and we will not make the service worse for you for having asked.
If you are in the UK or EU, our lawful bases are set out in section 02, and you have the right to complain to your local data protection authority. If you are in California, we do not sell or share personal information as those terms are defined by the CCPA, and we have not done so in the past twelve months.
Data is stored and processed in the United States. If you are writing to us from elsewhere, that is where your data goes.
10
Changes and contact
When this policy changes, the date at the top changes with it. If a change materially affects what we do with your data, we will email account owners before it takes effect rather than quietly reposting the page.
FollowerCRM is run by Leo Majowka. Questions, requests and complaints all go to the same place:
The service is not intended for anyone under 13, and we do not knowingly collect data from children. If you believe a child's data is here, tell us and we will remove it.