TaraDM AI
Security & Compliance Verification

Privacy Policy & Data Deletion

Learn how TaraDM AI manages, uses, and secures your credentials, campaign configurations, and Instagram data.

1. Introduction

Welcome to TaraDM AI ("we", "us", "our", or the "App"), owned and operated by Finds By Tara ("Developer"). We are dedicated to respecting and protecting the privacy of creators, influencers, and digital businesses who leverage our automation toolkit to improve engagement and direct communication workflows on Instagram.

This Privacy Policy describes the policies and procedures regarding our collection, storage, usage, and transfer of information that is obtained via the mobile application, Cloud Functions servers, and related services (collectively, the "Service").

Effective Date: June 4, 2026
Last Updated: June 4, 2026

Compliance Standard: This Privacy Policy is structured to comply with the Instagram Graph API Developer Policy, General Data Protection Regulation (GDPR), and California Consumer Privacy Act (CCPA).

2. Information We Collect

To enable Instagram DM and comment automation, TaraDM AI collects specific, essential information from creators who authenticate their accounts:

  • Account Authentication Details: When registering via Firebase Authentication (e.g. Google Sign-In or email login), we collect your unique Creator ID (UID), full name, email address, and profile picture.
  • Meta/Instagram Integration Tokens: When connecting your Instagram Business profile via our Meta OAuth authorization flow, we securely request:
    • Temporary and long-lived access tokens.
    • Your Instagram Business Account ID and username.
  • Instagram Media Records: To configure specific response triggers for specific posts, our system fetches your recent media posts (including media IDs, captions, media URLs, and permalinks). We cache this data to display and map campaign settings on your dashboard.
  • Creator-Configured Product Details: Products you publish inside the app including titles, descriptions, image reference URLs, keyword triggers, and destination affiliate/product URLs.
  • Campaign Analytics Logs: To calculate conversion rates and provide analytics dashboards, we track and store metadata about interactions triggered by commenter activity, including:
    • The commenter's Instagram public username.
    • The triggered comment text containing target keywords.
    • Timestamps of comment triggers, direct messages successfully initiated, and link clicks.

No Password Storage: TaraDM AI will NEVER ask for, access, or store your Instagram password. Authentication is completed securely via the official Meta Graph API OAuth 2.0 flow.

3. How We Use Collected Data

All data collected is used strictly to power core functions of the automation service. Specifically, we use your data to:

  1. Execute Automated Workflows: Automatically scan incoming webhook events from Meta (comments on your posts) and send the user-configured product DM matching those comments instantly.
  2. Maintain App Accounts: Manage your creator profile, link product directories, and secure Firebase access.
  3. Provide Conversions Analytics: Process metrics (e.g., total comments, DMs delivered, click-through rates) and present summaries on your application statistics panels.
  4. Optimize URL Metadatas: Allow client-side and server-side scraper requests to retrieve title and thumbnail image metadata for product link setups.

We do not sell, rent, license, or share your raw credentials or audience data with advertisers, third-party marketing companies, or data brokers.

4. Data Security and Storage Location

Your privacy and safety are paramount. We use enterprise-grade cloud systems to secure credentials and configuration logs:

  • Cloud Infrastructure: Your app databases, authentication profiles, and logs are hosted on Google Firebase (Firestore & Firebase Auth) servers in secure data centers.
  • Encrypted Tokens: Access tokens and OAuth configurations are transmitted over secure HTTPS (TLS 1.3) protocols and stored securely under strict Firebase Security Rules, accessible only by the creator owning the account.
  • Data Retention Limit: Analytics log history is kept for a limited duration (e.g., 90 days) to display performance graphs and is periodically pruned automatically.

5. Meta API & Platform Compliance

TaraDM AI integrates with the Meta Graph API (Instagram Business Graph APIs) to receive and process interaction webhooks and dispatch direct messages on your behalf. In using our app, you acknowledge and agree that:

  • The system requires active permissions: instagram_business_basic, instagram_business_manage_messages, and instagram_business_manage_comments.
  • We comply fully with the Meta Platform Terms and Developer Policies.
  • No automated DMs are dispatched to users who have not voluntarily initiated an interaction by commenting with targeted trigger keywords on your designated media posts.

6. Meta Data Deletion Instructions

To request deletion of your account, connection tokens, or any analytics logs, or to revoke the app's authorization over your Instagram profile, choose one of the following methods:

Method A: Revoke Authorization in Facebook Settings (Recommended)

You can revoke the application's access to your Instagram profile at any time directly through your Facebook Account settings:

  1. Log in to your Facebook profile associated with your Instagram Business account.
  2. Go to Settings & Privacy > Settings.
  3. On the sidebar, find and select Business Integrations (or Apps and Websites).
  4. Locate TaraDM AI in the active list.
  5. Click Remove and confirm the removal. This instantly voids the access tokens held in our databases and halts all integrations.

Method B: Disconnect Instagram Profile Inside the App

Disconnecting from the settings panel immediately purges integration configurations:

  1. Open the TaraDM AI application on your mobile device.
  2. Navigate to the Admin Settings or Instagram management panel.
  3. Tap the Disconnect Profile or Remove Meta Connection button.
  4. Our system will immediately delete your active Meta OAuth tokens and campaign linkages from Google Firestore.

Method C: Request Full Data Deletion via Email

If you wish for all your details, authentication records, campaign metadata, and analytics logs to be permanently expunged, please send us a deletion request using the interactive generator below:

Interactive Deletion Request Generator

Complete the form below to auto-generate a valid email request to our support desk. We process manual deletion requests within 48 hours.

7. Privacy & Security FAQ

Common security and data compliance inquiries regarding TaraDM AI:

Does the app collect my password?
No. TaraDM AI uses the official Meta Graph OAuth system. You log in and authorize the connection via Meta's secure servers, which return a secure API token. We never see or store your credentials.
Who owns the product links and details that I upload?
You do. All affiliate links, pricing details, and keywords belong to you. Our platform acts strictly as a secure courier delivering your product listings to commenters who express intent.
Are there any automated actions not initiated by comments?
No. TaraDM AI never performs spontaneous outreach or triggers cold DMs. Messages are sent only in response to a user interacting first (such as commenting with target keywords).

8. Contact Information

If you have any questions about this Privacy Policy, compliance validations, or how we manage your information, please reach out to us at:

Support & Privacy Inquiry:
Email: friendsrewards@gmail.com
Developer Organization: Finds By Tara

Success message