Privacy Policy

Last updated: 14 September 2026

Fideson is a shared inbox that lets a business read and answer the Instagram Direct Messages its customers send. Fideson is operated by Platestory Innovations LLP, India, which is the data controller for the information described here. This policy explains what we obtain from Meta when you connect an Instagram account, how we use it, where it is stored, who processes it, how long we keep it, and how to delete it.

How the connection works

You connect an Instagram professional (Business or Creator) account with Instagram Login (Instagram API with Instagram Login). Fideson does not use Facebook Login, and no Facebook account or Facebook Page is involved. Instagram shows you exactly what you are granting. We request only these permissions:

  • instagram_business_basic
  • instagram_business_manage_messages

You can remove Fideson at any time in Instagram (Settings → Apps and websites) or with Settings → Disconnect inside Fideson.

Exactly what we access, and why

  • Your account (instagram_business_basic): your Instagram account's ID and username. Used to identify the connected account in your workspace.
  • Direct messages (instagram_business_manage_messages): the text, photos and other attachments, sender, recipient, time and message ID of the Direct Messages people send to your account, and the replies your team sends through Fideson. Used only to show those conversations in your inbox and to deliver the replies you write. Fideson only replies to a person who messaged your business first. It never starts a conversation and never sends promotional, marketing or bulk messages.
  • The people who message you: their Instagram-scoped ID, username, name and profile picture, so your team can see who wrote.
  • Access token: the credential Meta issues when you connect, which lets Fideson read and send messages on your behalf. It is treated as a secret: kept only in our production database, never sent to the browser or written to logs, and accessible only to the Fideson service.

We do not request, access or store any other Meta Platform data, such as ads data, insights, payment information, or data about accounts you have not connected. We do not use Meta Platform data for advertising or to build advertising profiles, and we do not sell it.

Optional AI reply assistant

Fideson includes an AI assistant that is off by default. Only if a workspace owner turns it on, the text of incoming messages in that workspace is sent to Google's Gemini API to draft or send a reply, and to nothing else. Replies written by the AI assistant or by automated flows always stay within Instagram's standard 24-hour messaging window.

Where data is stored and who processes it

We share Meta Platform data only with the service providers that run Fideson for us, strictly to operate the service:

  • Railway (United States): application hosting, database and queue.
  • Cloudflare R2: storage for photos and attachments received in messages, so they keep displaying in your inbox.
  • Resend (United States): account emails such as password resets, team invitations and connection alerts, which can include your email address, workspace name and Instagram username.
  • Google (Gemini API): message text, only for workspaces that have turned on the AI assistant.

All data is encrypted in transit (TLS). We may disclose data if required by law, after reviewing the legality of the request and disclosing only the minimum necessary.

Data retention

  • While an Instagram account is connected, we keep its conversations so your team has the history it needs to answer customers.
  • When you disconnect, or remove Fideson in Instagram, the access token is deleted immediately and no new data is received. Existing conversation history stays in your workspace until you ask us to delete it.
  • When deletion is requested (see below), the data is deleted within 30 days. Residual copies in backups are purged within a further 30 days.

Deleting your data

  • From Instagram: remove Fideson under Settings → Apps and websites and request deletion. Meta notifies us through our data-deletion callback and we delete the data automatically. You receive a confirmation code and a status page.
  • By email: write to vamsi.bhogi@gmail.com with the Instagram username involved. We confirm within 48 hours and delete within 30 days.

Full steps are on our Data Deletion page.

Meta Platform compliance

Fideson's access to and use of information obtained through Meta comply with the Meta Platform Terms and Developer Policies. We use Meta Platform data only to provide the features you use in Fideson, and never to sell it, to advertise, to build advertising profiles, or to pass it to a data broker, ad network or monetization service. If we stop using a permission, we delete the data obtained through it.

Children

Fideson is a business tool for people aged 18 and over. We do not knowingly collect data from children.

Changes to this policy

If we change the permissions we request or how we use this data, we will update this policy and, where required, ask for your consent again.

Contact

Platestory Innovations LLP, India. Questions about this policy or your data: vamsi.bhogi@gmail.com