Last updated August 30, 2026
Privacy Policy
i8chat helps businesses send Meta-compliant private replies when people comment on connected Instagram posts or reels.
Who Is Responsible
i8chat is operated by Admov llc, which is the data controller for personal data processed through the service, including data received from Meta. Privacy enquiries can be sent to privacy@i8chat.com.
Data We Collect
We collect account email addresses for authentication, workspace and billing metadata, connected Instagram account identifiers, encrypted Instagram access tokens, campaign settings, webhook payloads, comments needed to process campaigns, delivery logs, and operational diagnostics.
How We Use Data
We use this data to authenticate users, connect Instagram integrations, match comment keywords, send private replies through the official Meta APIs, prevent duplicate sends, troubleshoot failures, and protect the service.
Instagram And Meta Data
i8chat does not ask for Instagram passwords, scrape Instagram, or use browser automation. Instagram tokens are encrypted at rest and are used only to perform actions authorized by the connected business account.
Tracked Links
Links we deliver on a customer's behalf pass through i8chat so the customer can see how their campaign performed. When someone opens one, we record the time, a hashed version of their IP address, the browser user agent, and the referring page. We do not store the raw IP address, and these identifiers are removed after 90 days while the click itself is kept as an anonymous total.
Subprocessors
The production service uses Vercel (application hosting), Railway (background worker, database and queue hosting), Google (sign-in), Resend (transactional email), and Stripe (payments). These providers process data only as needed to run the service. Data received from Meta is held only by Vercel and Railway; it is not sent to Resend or Stripe.
Retention And Deletion
Customers can disconnect an account from settings. That deletes the stored access token, tells Meta to stop sending us events for the account, and stops its campaigns.
Raw webhook payloads received from Meta are deleted after 30 days. Operational diagnostics are deleted after 90 days. Tracked-link identifiers are removed after 90 days. Campaign and delivery logs are kept while the workspace is active, because they are the customer's own record of their campaigns, and are deleted when the connection or workspace is deleted.
If you remove i8chat from your Instagram or Facebook account, or submit a data deletion request through Meta, we act on it automatically. See the Data Deletion page linked from the footer.
Contact
For privacy questions, including access and deletion requests, contact Admov llc at privacy@i8chat.com.