Privacy Policy
Last updated: September 22, 2026
This policy explains how Serenidesk LLC ("Serenidesk", "we") handles information when you use serenidesk-ai.com and connect your Instagram account. Contact: halomari@serenidesk-ai.com.
What we access
When you connect an Instagram Business or Creator account through Instagram's authorization screen, we request the instagram_business_basic and instagram_business_manage_comments permissions. With them we read:
- Your account's username, account type and media count.
- Your reels and posts: captions, timestamps, links and comment counts.
- Comments and replies on your reels, including the commenter's username, text, timestamp and like count.
We never receive your Instagram password. We do not post, comment, like, follow or send messages on your behalf.
Why we use it
Solely to show you your reels and their comments and to analyze what your audience is asking for, so you can plan educational products and content. We do not sell this data, use it for advertising, or share it with third parties, except service providers that host our application (Vercel) acting on our instructions.
How long we keep it
Your access token is stored in an encrypted, http-only cookie in your own browser for up to 30 days, or until you disconnect. Comment data is fetched live from Instagram when you open the dashboard and is not stored on our servers. If we later store data to produce reports you request, we will keep it only as long as needed to provide that service and delete it within 30 days of your request or of the end of our engagement.
Your choices and deletion
- Disconnect at any time from the dashboard, which deletes the session cookie.
- Revoke access in Instagram: Settings → Website permissions / Apps and websites → remove Serenidesk.
- Request deletion of any data we hold by emailing halomari@serenidesk-ai.com or following our data deletion instructions. We complete requests within 30 days.
Security
Tokens are encrypted with AES-256-GCM and transmitted only over HTTPS. The app secret is stored as a server-side environment variable and never exposed to the browser.
Children
Serenidesk is not directed to anyone under 18.
Changes
We will update this page if our practices change and revise the date above.