Privacy Policy
Effective date: 2026-09-29
This Privacy Policy explains how Feal Fruits Inbox ("the App", "we", "us"), operated by Feal Fruits, collects, uses, stores, shares and deletes information when businesses use the App to manage their Instagram Direct Messages through the Meta Platform (Instagram Graph API / Messenger Platform), and when their customers exchange messages with those businesses.
1. Who this policy applies to
- Account holders – businesses or creators who register in the App and connect an Instagram Professional account.
- Customers – Instagram users who send Direct Messages to a connected Instagram Professional account.
2. Information we collect
| Data | Source | Purpose |
|---|---|---|
| Username and password (stored only as a salted bcrypt hash) | Account holder | Sign-in to the App |
| Facebook app-scoped user ID, Facebook Page ID, Instagram Professional account ID and username | Meta, after the account holder authorizes the App via Facebook Login | Linking the Instagram account to the correct App user; processing deauthorization and data deletion requests |
| Page access token | Meta | Receiving and sending Instagram Direct Messages on the account holder's behalf. Stored encrypted (AES-256-GCM). |
| Instagram-scoped IDs (IGSID), username, name and profile picture URL of customers | Meta webhooks and the Instagram User Profile API | Displaying the conversation list in the inbox |
| Message content (text and attachment links), direction and timestamp | Meta webhooks and messages sent through the App | Displaying conversation history to the account holder |
We do not collect payment data, precise location, contacts, or any data beyond what is listed above.
3. Permissions we request from Meta
instagram_basic– read the connected Instagram Professional account's ID and username.instagram_manage_messages– receive and send Instagram Direct Messages for that account.pages_manage_metadata– subscribe the linked Facebook Page to webhooks so new messages are delivered.pages_read_engagementandpages_show_list– list the Pages the account holder manages and find the linked Instagram account.
4. How we use information
Information is used exclusively to provide the inbox functionality requested by the account holder: showing incoming messages, sending replies, and keeping conversation history. We do not sell data, use it for advertising, build profiles, train AI models on it, or transfer it to data brokers. We comply with the Meta Platform Terms and Developer Policies.
5. Sharing
Data is shared only with: (a) Meta Platforms, Inc., to deliver messages through the Instagram API; (b) our hosting and database providers acting as processors under confidentiality obligations; (c) authorities when required by law. Message data of a connected account is visible only to the App user who connected that account.
6. Security
- All traffic is served over HTTPS.
- Passwords are hashed with bcrypt; access tokens are encrypted at rest with AES-256-GCM.
- Every webhook request is verified with an HMAC-SHA256 signature (
X-Hub-Signature-256) using our App Secret. - Graph API calls include
appsecret_proof; the App Secret never leaves our server. - API access requires a signed, expiring session token (JWT); login endpoints are rate-limited.
7. Retention
We keep messages and contact data while the Instagram account remains connected. When the account holder disconnects the App, removes it from Facebook/Instagram settings, or requests deletion, access tokens are revoked immediately and Meta-derived data is deleted as described below.
8. Your rights and data deletion
You can request access, correction or deletion of your data at any time:
- From Facebook: Settings & privacy → Settings → Apps and websites → select Feal Fruits Inbox → Remove → and tick the option to delete data.
Meta then sends us an automated deletion request; we delete all messages, contacts, tokens and IDs linked to your account and give you
a confirmation code and a status page at
https://app.fealfruits.com/auth/data-deletion/status?code=<code>. - From Instagram: Settings → Website permissions / Apps and websites → remove Feal Fruits Inbox.
- By email: write to feal.shpk00@gmail.com with your username; we complete the request within 30 days.
Customers who messaged a business may ask that business, or us at the address above, to delete their messages.
9. Children
The App is intended for businesses and is not directed to children under 13 (or the minimum age in your country).
10. International transfers
Data may be processed in countries other than yours. Where required (e.g. under the GDPR), we rely on appropriate safeguards such as Standard Contractual Clauses.
11. Changes
We will post any changes on this page and update the effective date above.
12. Contact
Feal Fruits – feal.shpk00@gmail.com – https://app.fealfruits.com