Privacy Policy
What MuChat collects, why, and the choices you have.
This document is a working draft and hasn’t been reviewed by a lawyer yet. It will be finalised before MuChat’s public launch.
Who we are
MuChat is built and operated by SFDIFY LLC (“we”, “us”).
What MuChat does
MuChat connects to your Instagram professional account through the official Instagram API to read comments and messages sent to your account and to send the automated replies you configure.
What we store
- Your email address, name (if you give one) and the workspaces you belong to.
- Your Instagram account id, username and an encrypted access token.
- The Instagram-scoped ids, usernames and messages of people who interact with your account, and the tags, labels and fields you add to them.
- Your automation settings and statistics, such as runs and link clicks.
- If you subscribe: the customer and subscription identifiers from our payment provider. Card details are handled by the payment provider, not stored by MuChat.
How we use it
Data is used only to operate the service: to run your automations, show your inbox and contacts, send you sign-in links and service emails, and bill paid plans. We do not sell personal data.
Who else processes it
We rely on service providers to run MuChat: hosting, email delivery for sign-in links, and payment processing — plus Instagram (Meta) itself, whose API we use to read and send messages.
Keeping and deleting data
You can disconnect Instagram at any time from Settings, which deletes that account’s contacts and conversations from MuChat. See Data deletion for all the ways to delete your data.
Security
Instagram tokens are encrypted at rest, sign-in links and sessions are stored only as hashes, and incoming webhooks are signature-checked. More on our Privacy & security page.
Your choices
You can ask us to access, correct or delete your data by emailing the address below.