Skip to content
PopDMBack to PopDM

Last updated 10 October 2026

Privacy policy

This notice covers PopDM at popdm.app and its connected Instagram automation service. It explains the information used to run your workspace, deliver the replies you configure and handle support or privacy requests. Operator and contact details are listed on Contact.

Information we process

  • Your PopDM account: the account identifier, verified email, name and sign-in information supplied by Clerk. If you choose Google sign-in, Google and Clerk process that authentication.
  • Your Instagram connection: Instagram account identifiers, handle, profile picture, permission and connection status, and the access token needed to use the permissions you grant. PopDM does not ask for your Instagram password.
  • Conversation and automation information: supported comments and messages, sender identifiers and handles, relevant attachments, post and story information, keywords, templates, links, labels and the flows you configure. Delivery records include timestamps, provider references, attempts and outcomes.
  • Details recipients choose to provide: email addresses or phone numbers supplied in a configured lead-collection conversation, together with the associated handle, source flow and recorded response time. A reply is not consent for unrelated marketing.
  • Operation and support information: a Free-tier usage ledger keyed to each account’s stable Instagram ID, other usage counts, verified account-ownership records, security and administrative activity, request diagnostics, and correspondence you send us. Hosting and authentication providers may receive IP addresses, browser information, requested URLs and request times.
  • Billing, when enabled: subscription identifiers, plan, payment-provider references, status and expiry. PopDM’s subscription checkout is not currently enabled. Payment credentials are entered with the payment provider, not in a PopDM message or support email.

Why the information is used

We use information to authenticate you, connect the Instagram account you authorise, match supported events to your rules, send approved replies, provide Inbox and Reply Desk, collect volunteered lead details, show delivery outcomes and enforce each Instagram account’s plan and lifetime Free allowance. Each connected Instagram account has its own workspace and, when enabled, its own paid subscription. Pro-tier DMs do not consume its Free allowance. We also use necessary information to protect the service, investigate failures or abuse, respond to requests and meet applicable legal duties.

The workspace owner determines the purpose of their audience conversations and lead collection. They must give recipients appropriate information, obtain any required permission and use exported contacts only for an authorised purpose. PopDM processes that workspace content to provide the selected service. Account administration and service-security records are handled for PopDM’s own operational purposes.

Optional marketing and materially new purposes require separate notice and permission where applicable. PopDM does not sell audience contact records or use your workspace messages for third-party advertising.

Providers and information shared

  • Clerk: sign-in, account verification, session and account-management information. See Clerk’s privacy policy.
  • Meta / Instagram: the account connection, permitted Instagram content, outgoing replies and platform delivery information. Meta also processes information under its own privacy policy.
  • Cloudflare: website and API hosting, database, queued work, image storage and security/diagnostic services. See Cloudflare’s privacy policy.
  • Support and email providers: the correspondence you send and information necessary to answer or verify a request.
  • Payment providers, when enabled: the information necessary to create and verify a subscription. Razorpay integration is prepared, but live checkout is disabled. Native app subscriptions are not launched.

These providers may process information outside India. PopDM does not promise that all information is stored only in India; applicable transfer restrictions and provider safeguards still apply. We may disclose relevant information where required by law or a lawful order, or to investigate abuse, protect rights or address a security incident.

Opening a link in a message sends you to the linked website, whose own collection and terms apply. Uploaded message images are available through a shareable URL so that Instagram and recipients can load them. Do not upload private documents or sensitive records as message images.

AI and integrations

AI drafting is currently disabled. Workspace messages are not sent to an AI drafting provider through this feature while it is disabled. If we enable it, the relevant input, purpose and provider will be disclosed before use; generating a draft will not activate or send an automation by itself.

Optional external connectors require a separate authorised connection. They are unavailable until their authorisation is configured. You can review connector permissions and disable allowed actions in Settings when the feature is available.

Browser storage

Essential sign-in cookies and session information support authentication and account security. The website stores your light/dark preference locally until you change it or clear site data. Unsaved-work warnings protect the editor while you are working. Clearing browser data can sign you out; it does not delete server-side workspace records.

The current PopDM website does not add advertising trackers or optional marketing analytics cookies. Essential hosting and security diagnostics are separate from optional visitor tracking.

Retention and deletion

Workspace conversations, lead records, automation settings and uploaded images remain available until deleted through the service or a verified request. There is currently no fixed inactivity period that automatically deletes an entire workspace.

Disconnecting Instagram stops future use of the saved connection; it does not erase existing workspace content. The separate workspace-data deletion control removes its Instagram message history, captured leads, automation content and uploaded images. It clears saved Instagram tokens and cancels queued activity; an already submitted platform request cannot be recalled.

Workspace deletion retains the Clerk sign-in identity, workspace-owner/account identifiers, the stable Instagram ID allowance ledger, limited delivery identifiers and necessary financial, security and audit records. The ledger records lifetime Free-tier usage so that disconnecting, deleting a workspace, changing a handle or signing up through a different PopDM login does not issue another 1,000-DM allowance. Reconnection and requested ownership changes require verified control of the Instagram account. Retained identifiers are not anonymous; workspace-content deletion is not a complete identity deletion. Contact us for full account closure, removal of retained personal details, and the reason and retention period applicable to any exception.

Deleted content may remain temporarily in restricted provider backups or previously cached images until those copies expire. It must not be restored to ordinary service use simply because a backup exists. Instagram, independent providers and a workspace owner’s downloaded exports have separate records that PopDM cannot erase directly. See Delete your data for the available methods and scope.

Your choices and privacy requests

You can ask for access to information about you, correction, deletion, withdrawal of consent, or help with an authorised representative or nomination where applicable. Workspace owners can pause automations, disconnect Instagram, export lead records and delete workspace content in the dashboard. An Instagram recipient can contact the account they messaged or contact PopDM with the account handle and relevant interaction.

We may need a proportionate identity check to prevent another person accessing or deleting your information. Do not send identity documents unless a necessary verification method has been agreed. Withdrawing permission can stop features that need it; it does not undo lawful earlier processing.

India’s Digital Personal Data Protection Act, 2023 and Rules, 2025 have phased commencement. Statutory duties and remedies apply as the relevant provisions take effect. We accept privacy requests now and do not limit rights available under applicable law. You may approach a competent authority after following the applicable grievance process.

Security and children

Safeguards include encrypted transport, server-side credentials, encryption of saved Instagram access tokens and controls that scope workspace access. No system is completely secure. Report a suspected incident promptly; notifications will follow applicable requirements.

PopDM accounts are intended for adults aged 18 or older. Do not deliberately collect children’s personal information or sensitive records through automation. If you believe a child’s information was processed, contact us so we can investigate and remove it where appropriate.

Contact, complaints and changes

Contact hey@mihirjadhav.com for support, privacy requests or complaints. PopDM is operated by Mihir Jadhav. See Contact for operator and grievance details.

Include your workspace ID or Instagram handle, the relevant date and a brief description. Send only the information needed to handle your request. Do not send passwords, account tokens, card numbers, CVVs or payment OTPs.

We aim to acknowledge a privacy complaint within 48 hours and resolve it within 30 days, following any shorter period required by applicable law. We will explain a necessary verification step or retention exception. Material policy changes will be notified through the relevant service where required; a new processing purpose needs its own notice and permission where applicable.