Legal
Privacy
Policy.
What we collect, why, and how you stay in control of it.
Last updated: July 24, 2026
- Who we are
- What we collect
- Instagram & customer data
- How we use it
- AI processing
- Legal basis for processing
- Who we share it with
- Data retention
- International data transfers
- Security
- Your rights
- California privacy rights
- Cookies & local storage
- Children's privacy
- Changes to this policy
- Contact
Who we are
dmly ("dmly", "we", "us") builds an AI-powered Instagram employee for businesses — it replies to DMs and comments, tracks orders, and runs broadcasts on your behalf. This policy covers dmlyai.app, the dmly dashboard, and the automation service running behind them. We're based in Cairo, Egypt.
This policy applies to two kinds of people: you, the business owner who signs up for a dmly account, and your customers — the people who message your Instagram account, whose messages dmly processes on your behalf as part of the service. Where it matters, we call these out separately below.
dmly is currently operated as an unincorporated business based in Cairo, Egypt, not a registered company. We'll update this page if that changes.
What we collect from you
When you create a dmly account, we collect:
- Your name, email address, and password (handled by our authentication provider, Supabase — we never see or store your password in plain text).
- Your brand/business name and the business details you enter during setup — industry, tone of voice, working hours, shipping and returns policy, FAQs.
- Billing and contact details you give us to arrange payment. Today, billing is handled manually — when you check out, we collect your name, email, and optionally a WhatsApp number, and reach out directly to arrange payment. Once automated billing is available, card and payment details will be handled by a third-party payment processor and never stored on our servers; we'll name that processor here when it launches.
- Basic usage data: what pages you visit in the dashboard, which features you use, and error/diagnostic logs, so we can keep the product working and fix bugs.
Instagram & customer data
When you connect an Instagram Business account, dmly receives (via Meta's official Graph API, with your authorization) a long-lived access token and, from that point on, the DMs and comments your account receives. Specifically, we process:
- Instagram usernames, display names, and message/comment content from people who contact your connected account.
- Conversation history, so the AI can hold a coherent thread instead of treating every message as the first.
- Order and customer data pulled from any commerce platform you connect (currently Shopify), so the AI can answer "where's my order" questions accurately.
- Shipping/delivery status from any logistics provider you connect (currently Bosta).
We only request the Instagram permissions the product actually needs to send and receive messages on your behalf — we don't use your connection to post, follow, or act as you outside of the automations you configure.
Data we receive through Meta's Graph API ("Platform Data") is handled according to Meta's Platform Terms and Developer Policies: we use it only to run the automations you've configured, we don't use it to serve ads, for retargeting, or for any other advertising purpose, and we don't sell or license it to third parties. See our data deletion page for how Instagram Platform Data is removed when you disconnect or delete your account.
How we use it
- To run the automations you build — matching incoming messages to your flows and sending the replies you've configured.
- To generate AI replies that sound like your brand, using the business details, tone, and knowledge base you provide.
- To show you analytics about your own account — conversation volume, response times, conversion rates, and similar aggregate metrics.
- To detect and prevent abuse, fraud, or violations of our Terms of Service.
- To improve dmly itself — for example, understanding which features are used and which error patterns come up most, so we can prioritize fixes.
We do not sell your data, or your customers' data, to anyone.
AI processing
To generate replies, dmly sends the relevant conversation context (the incoming message, your business's knowledge base, and recent conversation history) to a third-party AI model provider. We use a small set of providers selected for cost and quality, and this may change as models improve. These providers process the data solely to generate a response and, per their standard commercial terms, do not use it to train their general-purpose models. We don't send more than the automation actually needs to answer the message in front of it.
Legal basis for processing
Where data protection law requires a legal basis for processing — for example, under the EU/UK GDPR — we rely on: performance of our contract with you to provide the service, your consent where you've given it (for example, connecting Instagram or an optional integration), our legitimate interests in operating and improving dmly securely, and compliance with legal obligations where applicable.
Data retention
Conversation history and customer memory (order history, preferences, past complaints) are kept for as long as your account is active, up to a retention window you control from your dashboard's memory settings (180 days by default). If you delete your account, we delete your business data and disconnect your Instagram account within 30 days, except where we're required to retain records for legal or accounting purposes. See our data deletion page for how to request this and exactly what's removed.
International data transfers
dmly is based in Cairo, Egypt, and our infrastructure and service providers — including Supabase and our AI model providers — may process data outside your country, including outside the EU/UK. Where we transfer personal data internationally, we rely on the transfer mechanisms available under applicable law (such as standard contractual clauses) and take reasonable steps to keep your data secure in transit and at rest.
Security
Access tokens and credentials are stored encrypted and are never exposed to the browser or to anyone outside the systems that need them to operate. Access to production data is restricted to the people who need it to run the service. No system is perfectly secure, but we take reasonable, industry-standard measures to protect your data and will tell you if something goes wrong that affects you.
Your rights
Depending on where you're located — including under the EU/UK GDPR — you may have the right to:
- Access the personal data we hold about you.
- Correct inaccurate data, most of which you can edit directly in your dashboard.
- Request deletion of your account and associated data — see our data deletion page for how.
- Restrict or object to certain processing, including processing based on our legitimate interests.
- Export your data in a portable, machine-readable format.
- Withdraw consent at any time where we rely on it — this won't affect processing that already happened.
- Lodge a complaint with your local data protection supervisory authority if you believe we haven't handled your data properly.
To exercise any of these, email us at the address below — we'll respond within 30 days.
California privacy rights
If you're a California resident, the CCPA/CPRA gives you additional rights over the personal information we collect: the right to know what we've collected, the right to delete it, the right to correct it, and the right to opt out of the "sale" or "sharing" of personal information.
We don't sell or share personal information for cross-context behavioral advertising, and we don't use sensitive personal information for anything beyond what's needed to run dmly. We won't discriminate against you for exercising any of these rights. To make a request, use the contact details below — we may need to verify your identity first.
Children's privacy
dmly is a business tool and isn't directed at children. We don't knowingly collect personal data from anyone under 16. If you believe a child has provided us data, contact us and we'll remove it.
Changes to this policy
If we make material changes, we'll update the date at the top of this page and, for significant changes, notify account owners by email. Continued use of dmly after a change means you accept the updated policy.
Contact
Questions about this policy or your data — [email protected]. For everything else, reach out here.