Draft

Draft — to be reviewed before going Live. Values in [brackets] are still to be filled in.

Privacy policy

Last updated 29 September 2026 · Draft

SutraDhar is read-only. Today it connects your Instagram account and reads no messages. Once reading is switched on, it keeps brand offers only. Personal messages are never saved.

Who we are

SutraDhar AI (“SutraDhar”, “we”) is a deal manager for creators. It is in private testing: only invited testers can use it, and nothing is open to the public yet. It is run by [OPERATOR: legal entity or founder name]. For anything about your data, write to [CONTACT EMAIL].

What SutraDhar does today

In this version SutraDhar only connects your Instagram professional account (Creator or Business), using Meta’s official Instagram Login. It does not read your messages yet.

SutraDhar is read-only. It never sends messages, posts, comments or likes as you.

What we collect when you connect

  • From Instagram: your Instagram account IDs (Instagram gives each app more than one), username, name, profile picture link and account type.
  • The permissions you gave (instagram_business_basic and instagram_business_manage_messages) and the access token Instagram issues for them. The token lasts about 60 days.
  • When you connected, and when the token runs out.
  • A sign-in record for each device you use, so you stay logged in. We keep only a scrambled (hashed) copy of the sign-in cookie, never the cookie itself.

We never see or store your Instagram password. You type it only on Instagram’s own page.

When message reading is switched on

This is not switched on yet. We will update this page, and tell connected testers, before it is. When it is:

  • SutraDhar reads new incoming DMs only. Older conversations are not read.
  • Each message is checked in memory by a filter that uses fixed rules, not an AI model, to decide whether it is a brand offer. Who follows whom is never used to skip or keep a message.
  • Brand offers are saved, encrypted: the sender’s handle, the message text, the time, and which rules matched.
  • Messages that are not brand offers are never saved and never written to any log. Only a count goes up, such as “12 checked today”.
  • If the filter is unsure, the text is not saved. We keep only the message ID, the sender’s handle and the time, and ask you: “Possible brand offer from @handle. Keep it?” If you keep it, SutraDhar fetches that one message from Instagram again and saves it. If you drop it, or don’t answer within 7 days, the ID is deleted.
  • Your own sent messages, reactions, read receipts and story mentions are ignored.
  • If a sender unsends or edits a message we saved, our copy is deleted or updated to match.

What we never do

  • Sell your data, or share it for advertising.
  • Send messages or post anything as you.
  • Use analytics, tracking pixels or third-party scripts.
  • Put message text, tokens or passwords in our logs.
  • Send your messages to an AI provider. If AI is ever added, it would only see messages already identified as brand offers, and this policy would change first.

Cookies

We use two cookies, both needed for sign-in. Neither is used for tracking.

  • sd_session keeps you signed in for up to 30 days, or until you log out.
  • A sign-in check cookie that lasts 10 minutes and protects the Instagram connection step from forgery.

How your data is protected

  • Everything travels over HTTPS, and the app’s connection to its database is encrypted too.
  • Instagram access tokens are encrypted at rest (AES-256-GCM).
  • Saved brand offers will be encrypted at rest too.
  • The app and database are hosted by [HOSTING PROVIDER AND REGION].

How long we keep it

  • Your connection details and access token: while you stay connected. Disconnecting deletes them from our database straight away. If Instagram tells us the access token no longer works, we delete the token at once.
  • Sign-in records: deleted when you log out or disconnect. Otherwise a sign-in stops working after 30 days, and its record is deleted the next time anyone signs in to SutraDhar.
  • If Meta sends us a deletion request for you: only its confirmation code and its dates, so the status page can answer. Nothing that identifies you is kept with it.
  • Unsure message IDs (once reading is on): 7 days at most.
  • Saved brand offers (once reading is on): until you delete them or disconnect.
  • Backups kept by our hosting provider: deleted data can stay in them, still encrypted where it was encrypted, for [BACKUP RETENTION, IF ANY] before they expire.

Deleting your data and your rights

You can delete everything at any time by disconnecting Instagram in SutraDhar, or by writing to us. Removing SutraDhar in Instagram’s settings also deletes your data once Instagram notifies us; we haven’t yet confirmed during testing that these notifications arrive, so disconnect in SutraDhar to be sure. See how to delete your data.

You can also ask us what data we hold about you, or ask us to correct it, by writing to [CONTACT EMAIL]. We aim to meet India’s Digital Personal Data Protection Act, 2023. SutraDhar is meant for creators aged 18 and over.

Changes to this policy

If we change what we collect or read, we will update this page and its date, and tell connected testers before the change takes effect.