Last updated September 24, 2026

Privacy Policy

What MuChat collects, why, and the choices you have.

Draft

This document is a working draft and hasn’t been reviewed by a lawyer yet. It will be finalised before MuChat’s public launch.

Who we are

MuChat is built and operated by SFDIFY LLC (“we”, “us”).

What MuChat does

MuChat connects to your Instagram professional account through the official Instagram API to read comments and messages sent to your account and to send the automated replies you configure.

What we store

  • Your email address, name (if you give one) and the workspaces you belong to.
  • Your Instagram account id, username and an encrypted access token.
  • The Instagram-scoped ids, usernames and messages of people who interact with your account, and the tags, labels and fields you add to them.
  • Your automation settings and statistics, such as runs and link clicks.
  • If you subscribe: the customer and subscription identifiers from our payment provider. Card details are handled by the payment provider, not stored by MuChat.

How we use it

Data is used only to operate the service: to run your automations, show your inbox and contacts, send you sign-in links and service emails, and bill paid plans. We do not sell personal data.

Who else processes it

We rely on service providers to run MuChat: hosting, email delivery for sign-in links, and payment processing — plus Instagram (Meta) itself, whose API we use to read and send messages.

Keeping and deleting data

You can disconnect Instagram at any time from Settings, which deletes that account’s contacts and conversations from MuChat. See Data deletion for all the ways to delete your data.

Security

Instagram tokens are encrypted at rest, sign-in links and sessions are stored only as hashes, and incoming webhooks are signature-checked. More on our Privacy & security page.

Your choices

You can ask us to access, correct or delete your data by emailing the address below.

Contact

privacy@muchat.app