Skip to content
aghost
Back to home

Privacy Policy

Last updated:

Your Instagram conversations and account information deserve clear answers. This policy describes what aghost processes, why it is needed, which providers are involved, and the choices you have.

1. Who this policy covers

This policy explains how the team providing aghost handles personal information when you visit the website, create an account, connect Instagram, or use automations, contacts, the inbox, MCP, or the REST API. The team is reachable at abhishek@thinkingsoundlab.com.

It also covers information about people interacting with an Instagram account connected to aghost. Workspace owners decide which automations to run and what messages to send. They are responsible for their own communications, notices, and lawful use of their audience’s information.

2. Information we process

  • Account information: Google sign-in identifiers, email address, and basic profile details made available during sign-in, along with your workspace name and identifiers.
  • Instagram connection: account identifiers, username, display name, profile image, connection status, granted permissions, and provider references. Credentials needed for the integration are handled through the connection provider.
  • Automations and interactions: selected post identifiers and details, keywords, message text, buttons and URLs, public replies, follower rules, and activity and delivery records.
  • Contacts and inbox: participant identifiers, usernames or profile details, conversations, message content and attachments, and timestamps made available by Instagram and Zernio.
  • Statistics: comment, DM, and link-click counts and delivery status made available for your automations.
  • Billing: payment-provider customer and subscription identifiers, plan, currency, subscription status, billing periods, and payment status. Payment details are entered in Dodo’s hosted checkout; aghost does not collect your full card number.
  • Access and support: API-key names, prefixes, hashes, permissions, creation and usage timestamps, support correspondence, and technical records needed to operate and secure the service.
  • Product usage: pages viewed, clicks and other interactions, device and browser details, approximate location derived from your IP address, performance and error records, recordings of how pages are used, and actions taken in your workspace through the dashboard, API, or MCP. Recordings mask typed input and leave out Instagram users’ messages, names, and contacts.

We do not receive your Google or Instagram password. Some information is stored in aghost; other information, including inbox messages and contacts, is fetched from connected providers when you use the relevant feature.

3. How information is used

We process information to sign you in, maintain your workspace, connect Instagram, deliver the automations and replies you request, display contacts and statistics, manage subscriptions, answer support requests, and investigate errors or misuse.

We use information only as needed for these purposes and applicable legal obligations. We do not sell your personal information or use Instagram message content for advertising.

Where data-protection law requires a legal basis, processing may rely on providing the service under our agreement, your consent for optional connections, legitimate interests in operating and securing the service, or legal obligations. You may withdraw a permission or consent by disconnecting the relevant service or contacting us; this does not undo processing already carried out lawfully.

4. Providers and information sharing

We share information needed to operate the service with the following types of providers:

  • Google: account authentication when you choose Google sign-in.
  • Meta / Instagram and Zernio: account authorization, connected-account data, comments, contacts, conversations, message delivery, and automation reporting.
  • Supabase: authentication and storage of workspace, account, automation, API-key, and billing records.
  • Dodo Payments: hosted checkout, subscriptions, payment processing, and the billing portal.
  • PostHog: product analytics, session recordings, and error tracking, stored in the United States.
  • Hosting and infrastructure providers, including Vercel and Amazon Web Services: serving the website and API and maintaining operational records.

These providers process information under their own applicable terms and privacy policies. We may also disclose information where required by law, to address fraud or security threats, or as part of a business transfer with appropriate protections.

Links and messages you configure may lead to other websites. Their owners are responsible for their own privacy practices.

5. Information available to your AI agent

Connecting an agent through MCP or the REST API gives that agent access using your workspace API key. New keys allow the agent to read connected accounts and posts, automations and their activity, contacts, and inbox messages, and to manage automations and send replies.

Your agent provider may receive and process the data returned by those tools under its own privacy terms, including its retention and model-training settings. Review those settings before connecting an agent. aghost does not control what a third-party agent does with data after receiving it.

You control which agent receives a key and can revoke it in Settings → API. Revocation prevents subsequent access through that key; it does not remove information an agent has already received.

6. Cookies and technical records

The service uses authentication cookies to keep you signed in. These are handled by the backend and are not readable by browser JavaScript. Third-party sign-in and checkout pages may use their own cookies under their own policies.

We use PostHog to understand how the website and dashboard are used. It keeps an identifier in a cookie and in your browser’s local storage so that visits before and after you sign in are counted as yours.

Hosting and API infrastructure may process IP addresses, request details, browser information, timestamps, and error records to deliver and secure the service. Blocking essential cookies may prevent sign-in from working.

7. Retention and deletion

Workspace and configuration records are kept while needed to provide your account and connected features. We may retain limited records as needed for billing, legal obligations, fraud prevention, security, or resolving disputes. Retention also depends on the policies of connected providers.

Disconnecting Instagram stops the connection and removes the associated aghost automations, but does not itself delete your Google sign-in, workspace, or billing records. Cancelling a subscription stops renewal as shown in the billing portal and does not itself delete data.

To request deletion of your aghost account or workspace data, follow our Data deletion instructions. We may need to verify the request and explain any information we must retain. Copies in backups may remain until those backups are replaced or expire.

8. Security and international processing

Access to workspace data is checked by the backend. API keys are stored as hashes, and you can revoke them. We use reasonable technical and organizational measures to protect information, but no system can guarantee absolute security.

Our providers may process information in countries other than your own. Where applicable law requires safeguards for international transfers, appropriate safeguards must apply. Contact us for information about processing relevant to your account.

9. Your choices and privacy rights

You can edit your workspace details, pause or delete automations, revoke API keys, and disconnect accounts in the dashboard. For requests to access, correct, export, or delete personal information, or to object to or restrict processing, contact us. Available rights depend on the law that applies to you.

If you interacted with an Instagram account using aghost, include that account’s username and your own username so the request can be located. The workspace owner may need to help resolve requests about their communications. Do not send passwords, API keys, payment-card details, or unrelated private messages.

Where applicable, you can withdraw consent and complain to your local data-protection authority. We may need to verify your identity before acting on a request.

10. Children

aghost accounts are intended for adults who can enter into an agreement. We do not knowingly collect personal information from children to create aghost accounts. If you believe a child has provided such information, contact us so we can investigate and take appropriate action.

11. Updates and contact

We may update this policy as features or providers change. The current version and update date appear on this page. We will provide notice and request additional consent where applicable law requires it.

For privacy questions, complaints, or requests, email abhishek@thinkingsoundlab.com or use our Contact page. Our Terms of Service explain the conditions for using aghost.