Your account, your audience, protected
MuChat handles two kinds of trust: yours, as the account owner, and your followers’, as the people you’re talking to. Here’s exactly how we look after both.
Security you can check
No passwords
You connect Instagram on Instagram’s own login screen through its official API. We never see or store your Instagram password.
Encrypted tokens
The access token Instagram gives us is encrypted at rest with AES-256-GCM.
Verified webhooks
Messages from Instagram and our payment provider are accepted only with a valid signature, checked in constant time.
Hashed sign-in links
Sign-in links work once and expire after 30 minutes. We store only a hash of them — and of your session — never the secret itself.
Your own login
Teammates sign in with their own email. Nobody on your team needs the Instagram password.
Deletion that deletes
Disconnecting Instagram permanently removes that account’s contacts, conversations and automations from MuChat.
What we store, and what we never do
To run your automations we store your email address; your Instagram account id, username and encrypted access token; the Instagram-scoped ids, usernames and messages of people who interact with your account; and your automation settings and results.
We don’t sell personal data, and we use it only to run the service. MuChat only answers people who contacted you first, inside Instagram’s messaging rules.
Details are in our privacy policy and data deletion page.
Found a security issue?
Please tell us privately at support@muchat.app with “Security” in the subject, and give us a chance to fix it before sharing it publicly.
Your next customer is already in your comments
Set up your first automation in the time it takes to write one reply by hand.