Privacy, Data & Security
What DMpro stores, how it keeps your Instagram and TikTok account safe, and your rights under GDPR and CCPA.
DMpro stores specific data about you so the service can function. Here is exactly what and why.
- Account data. Your email address (your primary account identifier), name (for personalization), country (for pricing display and invoice defaults), sign-up date and source, and an auto-generated referral code.
- Onboarding data. Your persona (Brand, Creator, Business), platform preference (Instagram, TikTok, or both), use case, goal and experience level, and persona-specific answers.
- Connected social accounts. Your Instagram/TikTok handles, when you connected them, and when they were last used. DMpro never stores your Instagram or TikTok password.
- Prompts and templates. Every prompt you’ve created (title, content, default status) plus its usage count and last-used date.
- Generated messages. Recent generated messages (last 30-90 days) for your Activity Log. Older messages may be aggregated or deleted per DMpro’s retention policy.
- Campaigns. Every campaign you’ve created (name, platform, usernames, settings, statuses) plus per-username status and message.
- Payment data. Payment history from Stripe (amount, date, plan) and your card’s last 4 digits for your reference in billing history. Never the full card number, CVV, or expiration date.
- Usage and analytics. Daily generation counts for your Usage view, aggregated stats for reports, and campaign progress metrics.
- Session data. Active JWT tokens (30-day expiry), plus login timestamps and device info for security.
- Fingerprint data. Which Instagram/TikTok handles are associated with your DMpro account, and how that association was made (onboarding self-report, extension detection, or admin), used for anti-abuse.
How long DMpro keeps it
| Data type | Retention |
|---|---|
| Account data | As long as your account exists |
| Generated messages | Recent history (30-90 days), then aggregated or deleted |
| Payment records | Retained for tax and legal compliance, typically 7 years |
| Deleted account data | Removed within 7 business days of your deletion request |
DMpro is designed to protect your Instagram and TikTok account safety. Here is how.
Rate limits protect your account. Safety Mode caps sending at 20 DMs a day, adds 3-6 minute delays between sends, and auto-pauses on Instagram block signals. This helps prevent your account from being flagged by Instagram or TikTok’s anti-spam systems.
About Instagram and TikTok’s Terms of Service
DMpro operates within Instagram and TikTok’s normal use patterns, but automated DMs at scale are technically against their Terms of Service. Instagram can block or flag accounts they suspect of automation, and Safety Mode reduces that risk but doesn’t eliminate it. See “How DMpro handles Instagram and TikTok’s Terms of Service” below for the full picture.
Best practices to stay safe
- Keep Safety Mode on.
- Send genuine, personalized outreach, not spammy blasts.
- Don’t scale too fast (jumping from 10 to 100 DMs a day in a week is risky).
- Use an established account. Older accounts carry less risk.
- Keep real content on your profile (posts, followers).
Multi-account protection. DMpro’s fingerprint system tracks which Instagram/TikTok accounts are linked to which DMpro accounts. This prevents users from creating fake DMpro accounts tied to the same social account (abuse), and avoids confusion about which social account is “yours.”
Privacy from other DMpro users. Your prompts, campaigns, and Instagram/TikTok connection are private to your account. No other DMpro user can see them.
Enterprise safety features. Enterprise plans add Account Safety Guardrails: dynamic rate limits, multi-account rotation, and post-send verification, for accounts that need higher volume with lower risk.
DMpro complies with GDPR, CCPA, and similar data protection laws. Here are your rights and how to use them.
- Right to access. Request a full copy of your data.
- Right to rectification. Correct inaccurate data.
- Right to erasure (“right to be forgotten”). Request deletion.
- Right to portability. Export your data in a machine-readable format.
- Right to object to processing of your data.
- Right to withdraw consent for marketing.
These rights apply to EU residents (GDPR), California residents (CCPA), and UK residents (UK GDPR).
How to request your data
Email [email protected] from your DMpro account email with:
- Subject: “GDPR Data Request” or “CCPA Data Request.”
- The type of request (access, rectification, erasure, or portability).
- Any specific data or accounts you’re referring to.
Requesting deletion
If you want your account permanently deleted:
- Email [email protected] from your DMpro account email.
- Use the subject “Delete My Account.”
- Confirm you understand deletion is irreversible.
Deletion is processed within 7 business days.
What gets deleted
- Your user record: removed.
- Prompts: deleted.
- Campaigns: deleted.
- Sessions: invalidated.
- Fingerprint associations: removed after the retention period.
- Payment records: retained for tax and legal reasons, but anonymized.
Requesting an export (data portability)
Email support with the subject “Export My Data.” DMpro provides your prompts, campaigns, and usage data in JSON or CSV format, delivered within 30 days.
Opting out of marketing
Turn off marketing in your Notification Preferences, or click unsubscribe in any marketing email. The effect is immediate.
Who DMpro shares data with
DMpro does not sell your data. Data is shared only with Stripe (payment processing), Postal (email delivery), and other brandID products if you explicitly connected them. There are no data brokers and no advertising networks involved.
DMpro uses cookies for essential functionality and minimal analytics. Here is what and why.
Cookies DMpro uses
- JWT session cookie. Your login token. Required.
- Preferences cookie. UI preferences, such as side panel state.
- Analytics cookies. Aggregated and anonymized.
Cookies DMpro does NOT use
- Advertising cookies. DMpro is ad-free.
- Third-party marketing cookies. No Google Ads, no Facebook Pixel.
- Cross-site tracking. DMpro doesn’t follow you around the web.
Analytics. DMpro uses Google Analytics (or similar) for aggregated usage stats, with anonymized IPs and no personal identifiers sent to analytics.
Third-party cookies. Stripe sets cookies for payment processing when you’re on Stripe Checkout, and Chatgram sets cookies for the support widget. Each has its own privacy policy.
Cookie consent for EU/UK users
Per GDPR, EU/UK users see a cookie consent banner on first visit, with the choice to accept all cookies, keep only essential cookies (JWT and preferences), or customize per category.
DMpro also respects Do Not Track headers if your browser sends them. When it does, non-essential cookies (analytics) are disabled.
Cookies vs. session storage
DMpro uses localStorage for the JWT token on the dashboard, Chrome extension storage for extension-specific data, and cookies for cross-page state on the dashboard. localStorage and extension storage are same-origin scoped, so other sites can’t access them.
Managing cookies in Chrome, Brave, or Edge: go to Settings → Privacy → Cookies to clear or block cookies for specific sites. DMpro’s full cookie policy lives at dmpro.brandid.app/privacy#cookies.
Instagram and TikTok have Terms of Service that govern how you use their platforms. Here is where DMpro stands.
Instagram and TikTok generally prohibit automated posting or DMing, fake accounts, buying or selling likes and follows, scraping data at scale, and unauthorized API access.
Where DMpro stands
DMpro uses your real, logged-in browser session (not a fake account), sends from your real account (not spoofed), personalizes each message with AI (not identical spam blasts), and enforces conservative rate limits through Safety Mode to stay under anti-spam thresholds. Even so, Instagram and TikTok can still consider this technically against their Terms of Service, since it is automation.
Why this isn’t as big a deal as it sounds
- Instagram doesn’t actively hunt individual users at Safety Mode volumes. They target obvious spammers.
- Personalized DMs are treated more leniently than repetitive spam blasts.
- Millions of small users use similar tools, so DMpro isn’t uniquely at risk.
- DMpro doesn’t stand out from a manual user as much as some automation tools do.
What could trigger a block: sending 100+ DMs a day (well above Safety Mode’s 20), sending identical messages to many recipients, sending from a very new account, or sending to profiles that report you. Following Safety Mode dramatically reduces this risk.
Legal vs. Terms violation. DMpro’s usage isn’t illegal in most jurisdictions. It is, technically, a Terms of Service matter, and enforcement is at Instagram or TikTok’s discretion. The tradeoff is better efficiency against a slight TOS risk, and most DMpro users decide the tradeoff is worth it.
If Instagram blocks you, your DMpro subscription is unaffected. You simply can’t send until the block clears. If Instagram or TikTok change their platform in ways that break DMpro’s automation, we update the extension, and we monitor industry developments closely. TikTok is generally more lenient than Instagram for legitimate outreach, though the same principles apply.
If you’d rather avoid automation risk entirely
- Use DMpro to generate messages you copy and paste manually.
- Send at lower volume (5-10 a day), below the anti-spam radar.
- Try a different channel, such as LinkedIn Sales Navigator or cold email.
DMpro’s full Terms of Service live at dmpro.brandid.app/terms. Here is a summary of the acceptable use rules that most affect day-to-day use.
Acceptable uses
DMpro is designed for legitimate outreach: sales prospecting, creator collab pitches, brand influencer marketing, recruiting, partnership outreach, and community engagement.
Prohibited uses
- Spam: sending irrelevant, unsolicited mass messages to random recipients.
- Harassment: messages designed to intimidate, threaten, or harm.
- Sexual content or minors: DMs involving inappropriate content.
- Impersonation: pretending to be someone you’re not.
- Illegal activity of any kind.
- Circumventing Instagram or TikTok blocks or bans.
- Multi-account abuse: creating fake DMpro accounts to farm free credits.
DMpro’s AI monitors for prohibited content categories. Flagged messages may pause your generation, trigger a review, or result in a temporary account suspension. If Instagram or TikTok users complain about your outreach, we investigate: legitimate complaints result in warnings or suspension, while frivolous complaints don’t affect you.
Consequences for violations
- First violation: a warning email.
- Second violation: temporary suspension (7-30 days).
- Severe or repeated violations: permanent account termination.
- Illegal content: immediate termination, with potential legal action.
Other key terms
- Age restrictions. You must be 16+ (or 18+ in some jurisdictions). Under-18 accounts are suspended when detected, and business accounts must be created by authorized representatives.
- Account sharing. One person per account, except on Enterprise team plans, which support up to 10 team members. Sharing credentials violates the terms.
- Data you send. You are responsible for the legality and accuracy of what you send. DMpro facilitates delivery but is not the sender of record, and you must comply with the laws in your jurisdiction and your recipients’.
- Refund rights. A 30-day money-back guarantee applies to unused one-time credit packages, and a 7-day money-back guarantee applies to annual plans. Monthly subscriptions have no refund past the initial period.
- Changes to terms. Terms may be updated periodically. Material changes come with 30 days’ email notice, and continued use counts as acceptance.
- Governing law. DMpro operates from Toronto, Canada, and disputes are governed by Ontario law. Enterprise contracts may specify a different governing law.
dmpro.brandid.app/terms, consult a lawyer for specific interpretation, or contact support for clarification.DMpro is intentional about what data it does and doesn’t collect. Here is an explicit list of things DMpro never stores.
- Your Instagram or TikTok password. DMpro has no login flow that asks for it. Never asked, never stored.
- Full credit card details. Card number and CVV never touch DMpro’s servers, and the full expiration date is only stored by Stripe. DMpro keeps just the last 4 digits, for your reference.
- Your bank account information. Bank routing/account numbers and debit card PINs are never asked for. Payment goes through Stripe, and DMpro only sees payment confirmations.
- Your Instagram/TikTok DM history. Past DMs you’ve sent, DMs from other people, and group chat content are not read. DMpro’s extension only sends messages you generate through DMpro; it doesn’t peek at your existing conversations.
- Your post content. Post captions, comment history, and story views are not read or tracked. Only profile bio and header data is used, for AI prompt context.
- Your followers/following list. Who you follow and who follows you are not read. Only aggregate counts are used.
- Your precise location. GPS coordinates and precise location are never tracked. IP geolocation is used only to approximate your country, for pricing and tax purposes.
- Your contacts list. Phone contacts and your email address book are never asked for or synced.
- Your browsing history. Other websites you visit, your search history, and your Google searches are not tracked. DMpro only knows about profile pages you deliberately visit while the extension is active.
- Your other social media. Facebook, Twitter (X), LinkedIn, Snapchat, and similar platforms are not accessed. DMpro only touches Instagram and TikTok.
- Data from third parties. DMpro doesn’t buy data from brokers and doesn’t scrape public data at scale for its own use. What you provide is what we have.
- Sensitive personal info. SSN or national ID, health information, financial account balances, and political affiliations are never asked for or tracked.
- Voice or video data. DMpro doesn’t have audio or video features, so nothing is recorded.
- Cookies from other sites. DMpro’s cookies are same-origin scoped; it doesn’t read cookies from other sites.
- Bulk metadata. Screen time on Instagram and detailed clickstream data are not tracked.
Still stuck? We’re happy to help.
Create your DMpro account, see pricing, or reach out to support directly.




