Jinu legal
Privacy Policy
How Jinu collects, uses, shares, retains, and deletes information when providing Instagram comment-to-message automation.
1. Who we are and how to contact us
Jinu is operated by [LEGAL ENTITY NAME], with an address at [LEGAL ADDRESS] ("Jinu," "we," "us"). Questions and privacy requests may be sent to [PRIVACY CONTACT EMAIL].
This draft describes the current MVP. The operator identity, contact channel, governing privacy laws, age threshold, and effective date require owner and legal counsel approval before publication.
2. Scope and privacy roles
This policy covers the Jinu website, dashboard, API, and support for the service. It does not replace the privacy terms of Instagram or Meta products.
For a customer's Instagram audience data, the customer generally decides why an automation runs and what it says. Jinu processes that data to provide the customer's configured service. Jinu separately determines how it uses account, billing, support, security, and service analytics data. These role descriptions must be confirmed against the launch jurisdictions and customer agreement.
3. Information we process
- Jinu account and workspace data: name, email address, password hash, session metadata, workspace membership, role, and audit records.
- Instagram connection data received through official Meta APIs: professional account ID, username, account type, granted permissions, token status and expiry, and encrypted access credentials.
- Automation configuration: selected posts or Reels, trigger keywords, reply text, optional links, rule status, and public-reply settings.
- Interaction data needed to run automations: comment and message identifiers, Instagram-scoped recipient identifiers, comment or message content, timestamps, conversation-window state, and attachment type.
- Delivery and reliability data: webhook events, automation runs, delivery status, retry state, Meta trace or message identifiers, bounded error details, and queue state.
- Technical and support data: IP-derived request and security information, device/browser data normally present in HTTP requests, structured application logs, aggregate metrics, and information a customer chooses to provide to support.
4. Where information comes from
We receive information directly from customers, from workspace members, automatically when the service is used, and from Meta through OAuth, Instagram APIs, and signed webhooks. Customers are responsible for giving required notices and having authority to configure messages sent from their professional account.
5. Why we process information
- Authenticate users, administer workspaces, and enforce tenant access controls.
- Connect an authorized Instagram professional account and maintain its token state.
- Match comments to enabled rules, send permitted replies, continue eligible conversations, and prevent duplicate sends.
- Provide event, delivery, conversation, and aggregate performance records to the relevant workspace.
- Secure, debug, monitor, and improve service reliability; prevent abuse; and respond to support requests.
- Comply with binding law, protect rights and safety, and enforce the Terms of Service.
7. Retention and deletion
- Raw webhook payloads are scheduled for redaction after 30 days; the minimum event and delivery metadata needed for reliability and audit may remain while the workspace is active.
- Expired or revoked authentication sessions are removed by the retention job.
- Deleting a workspace removes its active-database tenant records through a cascading deletion. A valid signed Meta deletion request removes the associated Instagram connection data.
- After deleting every workspace they own, a Jinu user can delete the global account. That operation removes the user record, email, authentication sessions, and remaining workspace memberships from the active database.
- Production backup, infrastructure-log, support-ticket, legal-record, and aggregate-metric retention periods are [OWNER TO SELECT; COUNSEL TO APPROVE]. Backup copies may persist until their documented rotation expires.
8. Security
The current design uses tenant-scoped backend authorization, PostgreSQL row-level security, hashed session tokens, encrypted OAuth credentials, signed-webhook verification, restricted logs, rate limiting, and bounded retention. No system is completely secure, and production hosting, key management, access review, backup security, and incident contacts must be verified before launch.
9. International transfers
Jinu and its providers may process information outside a person's country. Hosting locations, transfer mechanisms, and regional supplements are [OWNER/COUNSEL TO CONFIRM AFTER PROVIDER AND MARKET SELECTION]. We do not claim participation in any certification framework in this draft.
10. Privacy choices and rights
Depending on location and Jinu's role, a person may have rights to access, correct, delete, restrict, object to, or receive a copy of personal information, and to appeal or complain to a regulator. Send requests to [PRIVACY CONTACT EMAIL]. We may need to verify identity and authority and may direct an Instagram recipient to the customer that controls the relevant professional account.
Workspace owners can permanently delete a workspace using Jinu's authenticated deletion operation. Removing Jinu from Meta account settings can trigger Meta's signed deletion flow after the production app is configured. See the Data Deletion Instructions for the available paths and limitations.
A user who no longer owns a workspace can also delete the global Jinu account using the authenticated account-deletion control. Both controls require the current password and an exact confirmation phrase.
11. Children
Jinu is a business service and is not directed to children. The minimum customer age and any additional treatment of audience data involving minors are [COUNSEL TO CONFIRM FOR LAUNCH MARKETS]. Customers must not use Jinu in a way that violates applicable child-privacy rules or Meta policies.
12. Changes to this policy
We will post revisions on this page and update the effective date and version. Material changes will be communicated through [OWNER TO SELECT NOTICE CHANNEL] when required.