Privacy Policy

How PostToDM handles your data, in plain words.

Last updated: 29 September 2026. This policy covers the PostToDM website (posttodm.com) and the PostToDM app (app.posttodm.com).

PostToDM helps businesses and creators reply to comments and messages on their own Instagram professional accounts, and plan and publish their posts. PostToDM is operated by Dynamic Minds Group, Delhi, India ("we", "us"). This policy explains what data we process, why, and your choices.

Data we process

  • Connected business accounts: Instagram account ID, username, profile details and posts, and an access token issued by Instagram. We never see or store your Instagram password.
  • People who interact with a connected account: Instagram-scoped user ID, username, name, the text of comments and messages, whether they follow the business account, button taps, and timestamps.
  • Details people choose to share in a chat: for example an email address or phone number typed in reply to a question from the business.
  • Link clicks: time of click, browser type and a one-way hash of the IP address.
  • Content for scheduled posts: photos, videos and captions the business uploads to publish on its own account.
  • PostToDM users: login name, password (stored only as a secure hash) and settings.
  • Website visitors: information you submit in our forms, and basic analytics about pages visited.

How we use it

  • To reply to comments and send the messages a person asked for, for example a requested link or file.
  • To publish posts, Reels, carousels and Stories at the time the business chooses.
  • To show the business owner their comments, messages, leads and statistics, and to export leads to the owner's own Google Sheet when they turn this on.
  • To prevent duplicate or unwanted messages, abuse and errors, and to keep the service secure.

We do not sell personal data and do not use it to advertise to the people who message a business. Businesses that use PostToDM decide what they do with their own leads and are responsible for having a lawful basis to contact them.

Who we share it with

Only with service providers needed to run PostToDM: our hosting provider (secure servers), Meta Platforms (to send and receive Instagram data through its official API), and Google (only when a business turns on Google Sheets export). We may disclose data if required by law, after checking that the request is valid.

Automated messages

Replies sent through PostToDM are automated on behalf of the business. A person can stop them at any time by not replying, or by blocking or restricting the business account on Instagram.

Storage and security

Data is stored on secured servers with encrypted connections. Instagram access tokens are encrypted at rest. Access is limited to authorised Dynamic Minds Group staff, and backups are kept for up to 14 days.

Retention

Data is kept while the business account stays connected. It is deleted within 30 days after the account is disconnected or after a valid deletion request, except where the law requires us to keep it longer.

Cookies

The PostToDM app uses one essential cookie to keep you logged in. The website may use analytics cookies to understand visits; you can block them in your browser.

Your rights

You can ask to access, correct or delete your data, and to withdraw consent. See Data Deletion or email us. We handle requests in line with applicable law, including India's Digital Personal Data Protection Act, 2023.

Grievance officer

Sudhir Singhal, Dynamic Minds Group, Delhi, India. Email: sudhir.dmg@gmail.com. We acknowledge complaints within 48 hours and resolve them within 30 days.

Changes

We may update this policy. The date at the top shows the latest version; important changes are announced in the app.