Official Privacy Policy

Privacy Policy

Last updated: 10/10/2026

Welcome to Sygil (“Platform”, “we”, “us”, “our”). This Privacy Policy explains how we collect, use, disclose, and protect your information when you access or use the Sygil website, applications, APIs, and connected services (including our creator tools and Instagram Auto-DM automation services).

By using Sygil or connecting third-party platforms such as Instagram to your Sygil account, you agree to the practices described in this Privacy Policy.

1. Information We Collect

We collect information only to the extent necessary to operate, maintain, and provide the Platform's creator monetization and automation services.

1.1 Information You Provide Directly

When you create an account or use Sygil, we may collect:

  • Name or display name
  • Email address
  • Username and bio/profile details
  • Links and social handles you choose to display
  • Communications sent to our support channels

1.2 Payment Information

Financial transactions and creator payouts on Sygil are processed by certified third-party payment gateways (such as Razorpay).

  • Sygil does not collect or store credit card, debit card, CVV, UPI PINs, or sensitive banking passwords.
  • All payment data is handled directly by payment processors in compliance with applicable standards (PCI-DSS) and their respective privacy policies.

1.3 Automatically Collected Technical Information

When navigating Sygil, we may collect technical log details:

  • Device type, browser version, and operating system
  • IP address and approximate geographic region
  • Access timestamps and platform navigation paths
  • Essential functional cookies required for session security

2. Instagram & Meta API Data Processing

Sygil offers creators an official Auto-DM & Comment Automation tool powered by Meta's official Instagram Graph API (Instagram API with Instagram Login). This section explains what Meta and Instagram data we process, why we process it, how it is secured, and how you retain complete control over your data.

2.1 What Instagram Data We Process

When a creator connects their Instagram Professional (Business or Creator) account via Instagram Login:

  • Connected Creator Identity: We receive and store the Instagram Account ID (user ID), Instagram username (@handle), and account type (BUSINESS or CREATOR).
  • Instagram User Access Tokens: We obtain OAuth access tokens necessary to perform authorized API calls on the creator's behalf. All tokens are encrypted using AES-256-GCM before storage.
  • Comment Interactions (Webhooks): When public comments are left on a connected creator's posts or Reels, Meta delivers real-time webhook events containing the comment ID, comment text, media ID, timestamp, and commenter identification (Instagram User ID and public username).
  • Direct Messages (Webhooks): For direct message automations, we process incoming message events containing the message ID, sender ID, timestamp, and message text strictly to match creator-configured automation keywords.
What We Never Collect: We do not collect or store your Instagram passwords, personal friends/follower lists, private drafts, unshared media files, or private browsing history outside of authorized automation events.

2.2 Purpose & Use of Instagram Data

Sygil processes Instagram data exclusively to fulfill the creator's explicitly configured services:

  • Keyword Detection & Auto-Replies: To examine incoming comment or message text and trigger automated private replies (e.g., automatically sending a resource link, guide, coupon code, or greeting) when a keyword specified by the creator is detected.
  • Idempotency & Abuse Prevention: To prevent duplicate replies from being sent to the same user or comment.
  • Automation Delivery Logs: To record delivery logs (AutoDMLog) so the creator can audit triggered automations, delivery success, and failure statuses within their private Sygil dashboard.

We strictly enforce:

  • We do not sell, rent, license, or monetize Instagram user data to third parties, data brokers, or advertising networks.
  • We do not use Instagram message content or comment text to train artificial intelligence or machine learning models.
  • We do not use Instagram data for behavioral surveillance or advertising profiling.

2.3 Protection & Encryption of Instagram Data

Sygil implements robust, defense-in-depth security controls to safeguard Instagram credentials and interactions:

  • AES-256-GCM Encryption at Rest: All long-lived Instagram access tokens are encrypted with military-grade AES-256-GCM authenticated encryption before being saved into MongoDB. Unique initialization vectors (IVs) and authentication tags are stored per token to prevent cryptographic tampering.
  • Ephemeral In-Memory Decryption: Tokens are decrypted strictly in memory at the moment an outgoing Meta Graph API call is made and are immediately discarded. Tokens are never written to log files, cached on disk, or exposed to frontend clients.
  • HMAC-SHA256 Signature Verification: All incoming webhook requests from Meta are validated using timing-safe HMAC-SHA256 signature verification (x-hub-signature-256) against our application secrets to prevent spoofing.
  • Transport Layer Security: All API communication between Sygil servers and Meta Graph API endpoints takes place over TLS 1.3 / HTTPS.

2.4 How Users Can Request Deletion or Disconnect

Users and creators retain complete authority over their Instagram connection and may disconnect or purge data at any time:

  1. Disconnect inside Sygil: Creators can visit Dashboard > Manage Auto DMs and click “Disconnect Account”. This action immediately revokes and permanently deletes all stored access tokens and automation links from Sygil.
  2. Revoke via Instagram Settings: In the Instagram app, navigate to Settings & privacy > Website permissions > Apps and websites > Active, locate Sygil, and click Remove. Meta will immediately revoke the token and notify Sygil.
  3. Dedicated Data Deletion Request: Visit our public User Data Deletion Page or email contact@sygil.app to request complete erasure of all associated data. All requests are processed within 48 to 72 hours.

3. How We Use General Platform Information

We use collected general account information to:

  • Create, authenticate, and maintain your Sygil account
  • Operate platform features such as custom creator pages, link hubs, and digital vaults
  • Facilitate creator support settlements and send service notifications
  • Prevent abuse, fraud, spam, and security breaches
  • Comply with applicable legal, financial, and regulatory obligations

We do not sell personal data or license it to third-party marketing brokers.

4. Information Sharing & Third Parties

We do not sell your personal data. We disclose information only to trusted service partners under strict confidentiality:

4.1 Infrastructure & Technical Providers

  • Cloud hosting infrastructure (e.g., Microsoft Azure App Service)
  • Database hosting (MongoDB Atlas with network access controls and encryption at rest)
  • Payment gateway providers (Razorpay) for transaction settlement
  • Meta Platforms, Inc. for authorized Instagram Graph API communications

4.2 Legal Obligations

We may disclose information if required to do so by applicable law, court order, or governmental authority, or where necessary to protect the rights, property, or safety of Sygil, its users, or the public.

5. Data Retention & Disposal

We retain personal data only for as long as your account remains active or as needed to provide our services.

  • Instagram Access Tokens: Retained only while the creator maintains an active connection. Deleted immediately upon disconnection.
  • Automation Logs: Retained for a limited duration to enable creator delivery verification, after which records are purged.
  • Account Deletion: When an account is terminated, personal data is permanently deleted from production databases within 30 days, except where financial retention laws require recordkeeping.

6. Your Rights & Choices

Depending on your jurisdiction, you have the following rights:

  • Right of Access: Request a summary of the personal information we hold about you.
  • Right to Rectification: Update or correct inaccurate profile information through your dashboard.
  • Right to Erasure (Deletion): Request permanent deletion of your account and personal data.
  • Right to Revoke Consent: Disconnect third-party services (such as Instagram) at any time.

To exercise any of these rights, visit our Data Deletion Instructions or contact us at contact@sygil.app.

7. Children's Privacy

Sygil is not directed to individuals under 18 years of age. We do not knowingly collect personal data from minors. If you believe a child has provided us with personal information, please contact us immediately so we can remove the data.

8. Changes to This Policy

We may periodically update this Privacy Policy to reflect enhancements in our platform, new integrations, or changes in legal regulations. Updates will be published on this page with an updated “Last updated” timestamp.

9. Contact Us

If you have questions, inquiries, or data requests regarding this Privacy Policy or our Instagram integration, contact us at:

Platform: Sygil (sygil.app)
Privacy Inquiries: contact@sygil.app
Data Deletion Requests: sygil.app/data-deletion

Key Summary

Sygil collects only the data needed to power creator pages and authorized automations. Instagram access tokens are encrypted with AES-256-GCM at rest, never sold or shared with advertisers, and can be disconnected or deleted at any time with complete transparency.