Skip to content
JJinu
PrivacyTermsData deletion
Pre-publication draft

Draft for owner and legal counsel review. Do not publish or submit to Meta until every bracketed field is resolved.

Jinu legal

Privacy Policy

How Jinu collects, uses, shares, retains, and deletes information when providing Instagram comment-to-message automation.

Version
Draft 0.1
Date
Proposed effective date: [EFFECTIVE DATE — OWNER/COUNSEL TO APPROVE]

On this page

  1. 1. Who we are and how to contact us
  2. 2. Scope and privacy roles
  3. 3. Information we process
  4. 4. Where information comes from
  5. 5. Why we process information
  6. 6. When information is shared
  7. 7. Retention and deletion
  8. 8. Security
  9. 9. International transfers
  10. 10. Privacy choices and rights
  11. 11. Children
  12. 12. Changes to this policy

1. Who we are and how to contact us

Jinu is operated by [LEGAL ENTITY NAME], with an address at [LEGAL ADDRESS] ("Jinu," "we," "us"). Questions and privacy requests may be sent to [PRIVACY CONTACT EMAIL].

This draft describes the current MVP. The operator identity, contact channel, governing privacy laws, age threshold, and effective date require owner and legal counsel approval before publication.

Owner action: provide a monitored privacy email, legal entity name, and postal address.

2. Scope and privacy roles

This policy covers the Jinu website, dashboard, API, and support for the service. It does not replace the privacy terms of Instagram or Meta products.

For a customer's Instagram audience data, the customer generally decides why an automation runs and what it says. Jinu processes that data to provide the customer's configured service. Jinu separately determines how it uses account, billing, support, security, and service analytics data. These role descriptions must be confirmed against the launch jurisdictions and customer agreement.

3. Information we process

  • Jinu account and workspace data: name, email address, password hash, session metadata, workspace membership, role, and audit records.
  • Instagram connection data received through official Meta APIs: professional account ID, username, account type, granted permissions, token status and expiry, and encrypted access credentials.
  • Automation configuration: selected posts or Reels, trigger keywords, reply text, optional links, rule status, and public-reply settings.
  • Interaction data needed to run automations: comment and message identifiers, Instagram-scoped recipient identifiers, comment or message content, timestamps, conversation-window state, and attachment type.
  • Delivery and reliability data: webhook events, automation runs, delivery status, retry state, Meta trace or message identifiers, bounded error details, and queue state.
  • Technical and support data: IP-derived request and security information, device/browser data normally present in HTTP requests, structured application logs, aggregate metrics, and information a customer chooses to provide to support.
Jinu does not use unofficial scraping, browser cookies, or cold-audience lists to provide the MVP.

4. Where information comes from

We receive information directly from customers, from workspace members, automatically when the service is used, and from Meta through OAuth, Instagram APIs, and signed webhooks. Customers are responsible for giving required notices and having authority to configure messages sent from their professional account.

5. Why we process information

  • Authenticate users, administer workspaces, and enforce tenant access controls.
  • Connect an authorized Instagram professional account and maintain its token state.
  • Match comments to enabled rules, send permitted replies, continue eligible conversations, and prevent duplicate sends.
  • Provide event, delivery, conversation, and aggregate performance records to the relevant workspace.
  • Secure, debug, monitor, and improve service reliability; prevent abuse; and respond to support requests.
  • Comply with binding law, protect rights and safety, and enforce the Terms of Service.
Legal bases, consent language, and any jurisdiction-specific disclosures: [COUNSEL TO CONFIRM BEFORE LAUNCH].

6. When information is shared

Jinu exchanges platform data with Meta only as needed to connect accounts and perform customer-configured Instagram actions. Meta independently operates its products under its own terms and privacy policy.

We may use infrastructure, database, queue, object-storage, monitoring, email, and support providers acting under contract; the production subprocessor list and hosting regions are [OWNER TO SELECT AND DISCLOSE]. Information may also be disclosed when required by law, to protect the service or people, or as part of a properly documented corporate transaction.

The MVP does not sell personal information or use Instagram audience data for cross-context behavioral advertising. [COUNSEL TO CONFIRM THE APPLICABLE STATUTORY DISCLOSURE AND OPT-OUT LANGUAGE].

7. Retention and deletion

  • Raw webhook payloads are scheduled for redaction after 30 days; the minimum event and delivery metadata needed for reliability and audit may remain while the workspace is active.
  • Expired or revoked authentication sessions are removed by the retention job.
  • Deleting a workspace removes its active-database tenant records through a cascading deletion. A valid signed Meta deletion request removes the associated Instagram connection data.
  • After deleting every workspace they own, a Jinu user can delete the global account. That operation removes the user record, email, authentication sessions, and remaining workspace memberships from the active database.
  • Production backup, infrastructure-log, support-ticket, legal-record, and aggregate-metric retention periods are [OWNER TO SELECT; COUNSEL TO APPROVE]. Backup copies may persist until their documented rotation expires.
No production retention promise should be published until backup, logging, support, and legal-hold schedules are documented and technically enforced.

8. Security

The current design uses tenant-scoped backend authorization, PostgreSQL row-level security, hashed session tokens, encrypted OAuth credentials, signed-webhook verification, restricted logs, rate limiting, and bounded retention. No system is completely secure, and production hosting, key management, access review, backup security, and incident contacts must be verified before launch.

9. International transfers

Jinu and its providers may process information outside a person's country. Hosting locations, transfer mechanisms, and regional supplements are [OWNER/COUNSEL TO CONFIRM AFTER PROVIDER AND MARKET SELECTION]. We do not claim participation in any certification framework in this draft.

10. Privacy choices and rights

Depending on location and Jinu's role, a person may have rights to access, correct, delete, restrict, object to, or receive a copy of personal information, and to appeal or complain to a regulator. Send requests to [PRIVACY CONTACT EMAIL]. We may need to verify identity and authority and may direct an Instagram recipient to the customer that controls the relevant professional account.

Workspace owners can permanently delete a workspace using Jinu's authenticated deletion operation. Removing Jinu from Meta account settings can trigger Meta's signed deletion flow after the production app is configured. See the Data Deletion Instructions for the available paths and limitations.

A user who no longer owns a workspace can also delete the global Jinu account using the authenticated account-deletion control. Both controls require the current password and an exact confirmation phrase.

11. Children

Jinu is a business service and is not directed to children. The minimum customer age and any additional treatment of audience data involving minors are [COUNSEL TO CONFIRM FOR LAUNCH MARKETS]. Customers must not use Jinu in a way that violates applicable child-privacy rules or Meta policies.

12. Changes to this policy

We will post revisions on this page and update the effective date and version. Material changes will be communicated through [OWNER TO SELECT NOTICE CHANNEL] when required.

Jinu · official Meta API workflows only
PrivacyTermsData deletion