Privacy Policy
Last updated: January 15, 2025
1. Introduction
Welcome to SocialOra ("we," "our," or "us"). We are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Instagram DM automation platform.
By using SocialOra, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies and practices, please do not use our service.
2. Information We Collect
2.1 Account Information
When you create an account, we collect:
- Email address
- Name (if provided)
- Password (encrypted and hashed)
- Authentication tokens from Supabase
2.2 Instagram Account Data
To provide our services, we collect and store:
- Instagram session cookies (encrypted) - Required for authenticating with Instagram's API
- Instagram user ID and username
- Profile information (name, profile picture URL)
- Direct messages and conversations (stored securely)
2.2.1 Chrome Extension Data Collection
Our Chrome extension ("Socialora – Smart DM Automation") facilitates easy account connection by:
- Reading Instagram Cookies: The extension accesses cookies from instagram.com when you click "Grab Instagram Session" while logged into Instagram in your browser
- Extracting Session Data: It extracts only the necessary authentication cookies (sessionid, csrftoken, ds_user_id, mid, ig_did, rur) required to authenticate with Instagram's API
- Transferring to Application: Cookies are securely transferred to the SocialOra web application via browser localStorage and are never transmitted to any third-party servers
- No Browsing History: The extension does not access, read, or store your browsing history, bookmarks, or any other personal data beyond Instagram authentication cookies
- Local Storage Only: Cookies are stored locally in your browser and in our encrypted database - they are never shared with external parties
Important: The extension only accesses cookies when you explicitly click the "Grab Instagram Session" button. It does not run automatically or in the background. You must be logged into Instagram in your browser for the extension to work.
2.3 Usage Data
We automatically collect information about how you use our service:
- Campaign performance metrics
- Message sending statistics
- Feature usage analytics (via PostHog)
- Error logs and debugging information
3. How We Use Your Information
We use the collected information for:
- Providing and maintaining our service
- Processing and managing Instagram DM campaigns
- Authenticating and authorizing access to your account
- Improving our service and user experience
- Analyzing usage patterns and performance
- Sending important service notifications
- Detecting and preventing fraud or abuse
- Complying with legal obligations
4. Data Storage and Security
We implement industry-standard security measures to protect your data:
- Encryption: All sensitive data, including Instagram cookies, are encrypted at rest and in transit
- Database Security: Row-level security (RLS) policies ensure data isolation between users
- Authentication: Secure authentication via Supabase with email verification
- Access Control: Workspace-based access control ensures users can only access their own data
- Regular Backups: Data is regularly backed up to prevent loss
5. Data Sharing and Disclosure
We do not sell, trade, or rent your personal information. We may share your information only in the following circumstances:
- Service Providers: With trusted third-party services (Supabase, PostHog) that help us operate our platform
- Legal Requirements: When required by law or to protect our rights and safety
- Business Transfers: In connection with a merger, acquisition, or sale of assets
- With Your Consent: When you explicitly authorize us to share your information
6. Your Rights
You have the right to:
- Access: Request a copy of your personal data
- Correction: Update or correct inaccurate information
- Deletion: Request deletion of your account and data
- Portability: Export your data in a machine-readable format
- Opt-out: Unsubscribe from marketing communications
- Withdraw Consent: Revoke consent for data processing
To exercise these rights, please contact us at the email address provided in the Contact section.
7. Cookies and Tracking
We use cookies and similar technologies to:
- Maintain your session and authentication state
- Store your preferences and settings
- Analyze service usage and performance
- Provide personalized experiences
You can control cookies through your browser settings, but this may affect the functionality of our service.
8. Third-Party Services
Our service integrates with:
- Supabase: Authentication and database hosting
- PostHog: Analytics and product insights
- Instagram: Direct message platform (via official API and cookies)
These services have their own privacy policies. We encourage you to review them.
9. Data Retention
We retain your personal information for as long as necessary to provide our services and comply with legal obligations. When you delete your account, we will:
- Delete your account information within 30 days
- Remove all Instagram session data
- Delete all messages and conversations
- Retain anonymized analytics data for service improvement
10. Children's Privacy
Our service is not intended for users under the age of 13. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately.
11. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. We ensure appropriate safeguards are in place to protect your data in accordance with this Privacy Policy.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new policy on this page and updating the "Last updated" date. You are advised to review this policy periodically.
13. Contact Us
If you have any questions about this Privacy Policy or wish to exercise your rights, please contact us:
Email: digital@socialora.app
Support: Visit Support Page
