Skip to content

Privacy Policy

Last updated: 11 August 2026

GrowDM.ai (“GrowDM”, “we”, “our”, or “us”) is an Instagram automation platform operated by SolarioTech from India. This policy explains what we collect, why, who we share it with, and what you can ask us to do with it. It covers our website, web app, desktop app, and mobile apps.

1. Information You Give Us

When you create and use an account, we store:

  • Your name, email address, and profile picture.
  • Your password, stored only as a salted hash — we cannot read it or recover it for you.
  • Phone number, country code, and timezone, if you provide them.
  • Billing details you enter for invoicing: address, city, state, country, PIN code, and GST number where applicable.
  • If you sign in with Google: your Google account email, name, and the token Google issues for that sign-in.
  • For brand accounts: brand name, logo and cover image, description, industry, location, website, social links, and the point-of-contact name and mobile number submitted for approval.
  • Anything you send us through a support or contact form.

2. Information From Instagram When You Connect an Account

Connecting an Instagram Business or Creator account authorises us to receive:

  • Your Instagram account ID, username, display name, account type, profile picture, biography, and website.
  • Your follower, following, and media counts.
  • An access token, which we store encrypted and use only to act on your account as you have configured.

You can disconnect the account in GrowDM, or revoke our access from Instagram’s settings, at any time.

3. Information About People Who Message You

To run your automations, we necessarily process information about the people who interact with your Instagram account. When a message, comment, or story mention triggers one of your automations, we store:

  • The sender’s username and the identifier Instagram issues for them — an identifier scoped to your account, not a general Instagram ID.
  • The content of the message, comment, or mention that triggered the automation, and the event details Instagram sends us with it.
  • Which automation matched, what was sent in reply, whether it succeeded, and where the conversation reached in a multi-step flow.
  • A record of comments already acted on, so the same person is never messaged twice for the same comment.

We process this data to deliver the automations you configured. We do not sell it, use it to build advertising profiles, or use it to market to your audience on our own behalf.

4. Information We Collect Automatically

  • Device and connection data: IP address, browser and device type, pages viewed, and session activity.
  • Crash and error reports, so we can diagnose failures in the app.
  • App download events, recorded as platform, region, and a device identifier.

5. Cookies

We use a small number of cookies:

  • auth_token and refresh_token — required to keep you signed in. Without these you cannot use the product.
  • growdm-theme — remembers your light or dark theme choice.
  • Analytics cookies set by Google Tag Manager and Google Analytics, used to understand traffic and feature usage.

You can block cookies in your browser, but sign-in will not work without the session cookies above.

6. The Mobile App

  • Sign-in tokens are stored in your device’s own secure storage, provided by iOS and Android.
  • If your device has Face ID, a fingerprint reader, or a passcode, the app can lock behind it. This exists purely to stop someone who picks up your unlocked phone from opening your account. The check is performed entirely by your device’s operating system — your biometric data never leaves the device, is never sent to us, and is never stored by us. All we receive is whether the unlock succeeded.
  • The app downloads over-the-air updates through Expo, which receives the technical request data needed to serve them.

7. How We Use Information

  • To create and secure your account and keep you signed in.
  • To connect your Instagram account and run your automations.
  • To show you analytics about your own account and automation performance.
  • To process subscriptions, issue invoices, and apply referral credits.
  • To send transactional email: verification, password reset, billing, and service notices.
  • To provide support when you contact us.
  • To detect abuse and fraud, enforce our Terms, and meet legal obligations.
  • To fix bugs and improve the product.

8. Who We Share It With

We do not sell personal information. We share it only with the providers that make GrowDM work:

  • Meta Platforms — to read and send Instagram messages and comments on your behalf.
  • Amazon Web Services — hosting and media storage.
  • Razorpay — payment processing. Razorpay handles card and UPI details directly; we receive only the payment, order, and invoice identifiers, the amount, the method type such as UPI or card, and the result.
  • Google — sign-in, and website analytics through Google Analytics and Tag Manager.
  • Resend — delivery of transactional email.
  • Sentry — crash and error reporting.
  • Expo — mobile app delivery and over-the-air updates.

We may also disclose information where required by law, or to protect our rights, users, or platform security.

9. Where It Is Stored and How It Is Protected

GrowDM runs on Amazon Web Services infrastructure located in India. Passwords are stored only as salted hashes, Instagram access tokens are encrypted at rest, sessions use signed HTTP-only cookies, and repeated failed logins lock an account temporarily.

These measures reduce risk but cannot eliminate it — no internet-based system is completely secure.

10. How Long We Keep It

We keep your account data, automations, and the message and comment records described in section 3 for as long as your account is active, because automations rely on them to run correctly and to avoid replying twice to the same person.

When you delete your account or ask us to delete your data, we remove it, except where we are required to retain records — for example invoices and payment records kept for Indian tax and accounting rules. Disconnecting an Instagram account removes its stored access token.

11. Your Rights

Under India’s Digital Personal Data Protection Act, 2023 — and comparable laws elsewhere — you can ask us to:

  • Give you a copy of the personal information we hold about you.
  • Correct information that is inaccurate or incomplete.
  • Delete your account and associated data.
  • Withdraw consent for a specific integration or processing.

Email privacy@growdm.ai from the address on your account, or follow our Data Deletion Instructions. We respond to valid requests within the timeframes the applicable law requires.

12. Children

GrowDM is not intended for children under the age of 13, and we do not knowingly collect personal information from them. If you believe a child under 13 has given us personal information, contact us and we will delete it.

13. International Transfers

Our primary infrastructure is in India. Some providers listed in section 8 operate outside India, so your information may be processed in other countries where data protection laws differ. Where we transfer data internationally, we do so on the basis permitted by applicable law.

14. Changes to This Policy

We may update this policy. When we make material changes we will update the date at the top of this page and, where the change significantly affects you, notify you in the app or by email.

15. Contact Us

Privacy: privacy@growdm.ai
Support: support@growdm.ai
Website: https://growdm.ai