Privacy Policy

Last updated: July 2026

DMlite ("we", "our", "us") operates the website and service at dmlite.app. This Privacy Policy explains how we collect, use, store, and protect your information when you use our service.

1. Information We Collect

We collect information you provide directly and information generated through your use of the service:

  • Account Information: Email address, name, and password when you create an account.
  • Instagram Account Data: When you connect your Instagram Business or Creator account, we receive your Instagram username, profile information, and an access token via the official Meta OAuth flow.
  • Usage Data: Automation configurations, DM counts, comment interactions, and activity logs generated by your use of the service.
  • Payment Information: Billing details processed securely by our payment provider (Razorpay). We do not store your full card or UPI details on our servers.
  • Device & Log Data: IP address, browser type, operating system, and access timestamps collected automatically for security and analytics purposes.

2. How We Use Your Data

We use the information we collect to:

  • Provide, operate, and maintain the DMlite service, including sending automated DMs and comment replies on your behalf via the Instagram API.
  • Process payments and manage your subscription or one-time purchases.
  • Send service-related communications such as account verification, billing notifications, and support responses.
  • Improve and optimise the service, including analytics and performance monitoring.
  • Detect and prevent fraud, abuse, or violations of our Terms of Service.

3. Data Storage & Security

Your data is stored securely on Supabase (PostgreSQL) with row-level security policies enforced at the database level. Instagram access tokens are encrypted at rest. We implement industry-standard security measures including HTTPS encryption, secure authentication flows, and regular security audits to protect your data against unauthorised access, alteration, or destruction.

4. Third-Party Services

We integrate with the following third-party services to operate DMlite:

  • Meta / Instagram API: To send and receive messages and interact with your Instagram account.
  • Supabase: Database hosting and authentication.
  • Razorpay: Payment processing (subject to Razorpay's Privacy Policy).
  • Upstash: Rate limiting and caching.

We do not sell, rent, or trade your personal information to any third party.

5. Cookies & Tracking

DMlite uses essential cookies to maintain your authenticated session and remember your preferences. We may also use analytics cookies to understand how the service is used and to improve user experience. You can disable cookies in your browser settings, but some features of the service may not function properly without them.

6. Data Retention

We retain your personal data for as long as your account is active or as needed to provide you with the service. If you close your account, we will delete your personal data within 30 days, except where we are required to retain it for legal, regulatory, or legitimate business purposes (e.g., fraud prevention, resolving disputes).

7. Data Deletion

You can request complete deletion of your data at any time by emailing us at support@dmlite.app or by using the data deletion option within your account settings. We will process your request within 30 days and confirm once your data has been permanently removed.

8. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

  • Access: Request a copy of the personal data we hold about you.
  • Correction: Request correction of inaccurate or incomplete data.
  • Deletion: Request deletion of your personal data.
  • Portability: Request your data in a machine-readable format.
  • Objection: Object to certain types of data processing.

To exercise any of these rights, please contact us at support@dmlite.app.

9. Children's Privacy

DMlite is not intended for use by anyone under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child under 18, we will take steps to delete that information promptly.

10. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by updating the "Last updated" date at the top of this page and, where appropriate, through in-app notifications or email. Your continued use of the service after any changes constitutes acceptance of the updated policy.

11. Contact Us

If you have any questions or concerns about this Privacy Policy or our data practices, please contact us: