Privacy & security

Your account, your audience, protected

MuChat handles two kinds of trust: yours, as the account owner, and your followers’, as the people you’re talking to. Here’s exactly how we look after both.

How it’s built

Security you can check

No passwords

You connect Instagram on Instagram’s own login screen through its official API. We never see or store your Instagram password.

Encrypted tokens

The access token Instagram gives us is encrypted at rest with AES-256-GCM.

Verified webhooks

Messages from Instagram and our payment provider are accepted only with a valid signature, checked in constant time.

Hashed sign-in links

Sign-in links work once and expire after 30 minutes. We store only a hash of them — and of your session — never the secret itself.

Your own login

Teammates sign in with their own email. Nobody on your team needs the Instagram password.

Deletion that deletes

Disconnecting Instagram permanently removes that account’s contacts, conversations and automations from MuChat.

Privacy

What we store, and what we never do

To run your automations we store your email address; your Instagram account id, username and encrypted access token; the Instagram-scoped ids, usernames and messages of people who interact with your account; and your automation settings and results.

We don’t sell personal data, and we use it only to run the service. MuChat only answers people who contacted you first, inside Instagram’s messaging rules.

Details are in our privacy policy and data deletion page.

Found a security issue?

Please tell us privately at support@muchat.app with “Security” in the subject, and give us a chance to fix it before sharing it publicly.

Your next customer is already in your comments

Set up your first automation in the time it takes to write one reply by hand.