Privacy & Security

Privacy, Data & Security

What DMpro stores, how it keeps your Instagram and TikTok account safe, and your rights under GDPR and CCPA.

DMpro stores specific data about you so the service can function. Here is exactly what and why.

  • Account data. Your email address (your primary account identifier), name (for personalization), country (for pricing display and invoice defaults), sign-up date and source, and an auto-generated referral code.
  • Onboarding data. Your persona (Brand, Creator, Business), platform preference (Instagram, TikTok, or both), use case, goal and experience level, and persona-specific answers.
  • Connected social accounts. Your Instagram/TikTok handles, when you connected them, and when they were last used. DMpro never stores your Instagram or TikTok password.
  • Prompts and templates. Every prompt you’ve created (title, content, default status) plus its usage count and last-used date.
  • Generated messages. Recent generated messages (last 30-90 days) for your Activity Log. Older messages may be aggregated or deleted per DMpro’s retention policy.
  • Campaigns. Every campaign you’ve created (name, platform, usernames, settings, statuses) plus per-username status and message.
  • Payment data. Payment history from Stripe (amount, date, plan) and your card’s last 4 digits for your reference in billing history. Never the full card number, CVV, or expiration date.
  • Usage and analytics. Daily generation counts for your Usage view, aggregated stats for reports, and campaign progress metrics.
  • Session data. Active JWT tokens (30-day expiry), plus login timestamps and device info for security.
  • Fingerprint data. Which Instagram/TikTok handles are associated with your DMpro account, and how that association was made (onboarding self-report, extension detection, or admin), used for anti-abuse.

How long DMpro keeps it

Data typeRetention
Account dataAs long as your account exists
Generated messagesRecent history (30-90 days), then aggregated or deleted
Payment recordsRetained for tax and legal compliance, typically 7 years
Deleted account dataRemoved within 7 business days of your deletion request
Everything above exists to make DMpro work for you (personalization, billing history, anti-abuse). Nothing on this list is sold or shared with advertisers.

DMpro is designed to protect your Instagram and TikTok account safety. Here is how.

🔒
DMpro never stores your credentialsDMpro never asks for your Instagram or TikTok password and never stores your login. The extension works by reading whichever session you’re already logged into in your browser. Your login cookies stay in your browser, and no credentials ever leave your machine.

Rate limits protect your account. Safety Mode caps sending at 20 DMs a day, adds 3-6 minute delays between sends, and auto-pauses on Instagram block signals. This helps prevent your account from being flagged by Instagram or TikTok’s anti-spam systems.

About Instagram and TikTok’s Terms of Service

DMpro operates within Instagram and TikTok’s normal use patterns, but automated DMs at scale are technically against their Terms of Service. Instagram can block or flag accounts they suspect of automation, and Safety Mode reduces that risk but doesn’t eliminate it. See “How DMpro handles Instagram and TikTok’s Terms of Service” below for the full picture.

Best practices to stay safe

  • Keep Safety Mode on.
  • Send genuine, personalized outreach, not spammy blasts.
  • Don’t scale too fast (jumping from 10 to 100 DMs a day in a week is risky).
  • Use an established account. Older accounts carry less risk.
  • Keep real content on your profile (posts, followers).

Multi-account protection. DMpro’s fingerprint system tracks which Instagram/TikTok accounts are linked to which DMpro accounts. This prevents users from creating fake DMpro accounts tied to the same social account (abuse), and avoids confusion about which social account is “yours.”

Privacy from other DMpro users. Your prompts, campaigns, and Instagram/TikTok connection are private to your account. No other DMpro user can see them.

Enterprise safety features. Enterprise plans add Account Safety Guardrails: dynamic rate limits, multi-account rotation, and post-send verification, for accounts that need higher volume with lower risk.

If you have concerns about DMpro’s impact on your account safety, contact [email protected]. We can advise on best practices for your specific situation.

DMpro complies with GDPR, CCPA, and similar data protection laws. Here are your rights and how to use them.

  • Right to access. Request a full copy of your data.
  • Right to rectification. Correct inaccurate data.
  • Right to erasure (“right to be forgotten”). Request deletion.
  • Right to portability. Export your data in a machine-readable format.
  • Right to object to processing of your data.
  • Right to withdraw consent for marketing.

These rights apply to EU residents (GDPR), California residents (CCPA), and UK residents (UK GDPR).

How to request your data

Email [email protected] from your DMpro account email with:

  • Subject: “GDPR Data Request” or “CCPA Data Request.”
  • The type of request (access, rectification, erasure, or portability).
  • Any specific data or accounts you’re referring to.
DMpro responds within 30 days, as required under GDPR.

Requesting deletion

If you want your account permanently deleted:

  1. Email [email protected] from your DMpro account email.
  2. Use the subject “Delete My Account.”
  3. Confirm you understand deletion is irreversible.

Deletion is processed within 7 business days.

What gets deleted

  • Your user record: removed.
  • Prompts: deleted.
  • Campaigns: deleted.
  • Sessions: invalidated.
  • Fingerprint associations: removed after the retention period.
  • Payment records: retained for tax and legal reasons, but anonymized.
Nothing that identifies you personally is retained after deletion, apart from anonymized transaction records kept for legal compliance (typically 7 years). Aggregated analytics and system logs are also retained, but already anonymized.

Requesting an export (data portability)

Email support with the subject “Export My Data.” DMpro provides your prompts, campaigns, and usage data in JSON or CSV format, delivered within 30 days.

Opting out of marketing

Turn off marketing in your Notification Preferences, or click unsubscribe in any marketing email. The effect is immediate.

Who DMpro shares data with

DMpro does not sell your data. Data is shared only with Stripe (payment processing), Postal (email delivery), and other brandID products if you explicitly connected them. There are no data brokers and no advertising networks involved.

DMpro uses cookies for essential functionality and minimal analytics. Here is what and why.

Cookies DMpro uses

  • JWT session cookie. Your login token. Required.
  • Preferences cookie. UI preferences, such as side panel state.
  • Analytics cookies. Aggregated and anonymized.

Cookies DMpro does NOT use

  • Advertising cookies. DMpro is ad-free.
  • Third-party marketing cookies. No Google Ads, no Facebook Pixel.
  • Cross-site tracking. DMpro doesn’t follow you around the web.

Analytics. DMpro uses Google Analytics (or similar) for aggregated usage stats, with anonymized IPs and no personal identifiers sent to analytics.

Third-party cookies. Stripe sets cookies for payment processing when you’re on Stripe Checkout, and Chatgram sets cookies for the support widget. Each has its own privacy policy.

Cookie consent for EU/UK users

Per GDPR, EU/UK users see a cookie consent banner on first visit, with the choice to accept all cookies, keep only essential cookies (JWT and preferences), or customize per category.

DMpro also respects Do Not Track headers if your browser sends them. When it does, non-essential cookies (analytics) are disabled.

Cookies vs. session storage

DMpro uses localStorage for the JWT token on the dashboard, Chrome extension storage for extension-specific data, and cookies for cross-page state on the dashboard. localStorage and extension storage are same-origin scoped, so other sites can’t access them.

Deleting DMpro’s cookies clears your session. You’ll need to sign in again with the magic code flow.

Managing cookies in Chrome, Brave, or Edge: go to Settings → Privacy → Cookies to clear or block cookies for specific sites. DMpro’s full cookie policy lives at dmpro.brandid.app/privacy#cookies.

Instagram and TikTok have Terms of Service that govern how you use their platforms. Here is where DMpro stands.

Instagram and TikTok generally prohibit automated posting or DMing, fake accounts, buying or selling likes and follows, scraping data at scale, and unauthorized API access.

Where DMpro stands

DMpro uses your real, logged-in browser session (not a fake account), sends from your real account (not spoofed), personalizes each message with AI (not identical spam blasts), and enforces conservative rate limits through Safety Mode to stay under anti-spam thresholds. Even so, Instagram and TikTok can still consider this technically against their Terms of Service, since it is automation.

Why this isn’t as big a deal as it sounds

  • Instagram doesn’t actively hunt individual users at Safety Mode volumes. They target obvious spammers.
  • Personalized DMs are treated more leniently than repetitive spam blasts.
  • Millions of small users use similar tools, so DMpro isn’t uniquely at risk.
  • DMpro doesn’t stand out from a manual user as much as some automation tools do.

What could trigger a block: sending 100+ DMs a day (well above Safety Mode’s 20), sending identical messages to many recipients, sending from a very new account, or sending to profiles that report you. Following Safety Mode dramatically reduces this risk.

Legal vs. Terms violation. DMpro’s usage isn’t illegal in most jurisdictions. It is, technically, a Terms of Service matter, and enforcement is at Instagram or TikTok’s discretion. The tradeoff is better efficiency against a slight TOS risk, and most DMpro users decide the tradeoff is worth it.

If Instagram blocks you, your DMpro subscription is unaffected. You simply can’t send until the block clears. If Instagram or TikTok change their platform in ways that break DMpro’s automation, we update the extension, and we monitor industry developments closely. TikTok is generally more lenient than Instagram for legitimate outreach, though the same principles apply.

If you’d rather avoid automation risk entirely

  • Use DMpro to generate messages you copy and paste manually.
  • Send at lower volume (5-10 a day), below the anti-spam radar.
  • Try a different channel, such as LinkedIn Sales Navigator or cold email.
Your own outreach may also carry legal considerations: CAN-SPAM (US) generally exempts personal outreach from its opt-in requirement, GDPR (EU) often exempts personal outreach to businesses under legitimate interest, and CASL (Canada) works similarly to CAN-SPAM. Consult a lawyer for specifics that apply to you.

DMpro’s full Terms of Service live at dmpro.brandid.app/terms. Here is a summary of the acceptable use rules that most affect day-to-day use.

Acceptable uses

DMpro is designed for legitimate outreach: sales prospecting, creator collab pitches, brand influencer marketing, recruiting, partnership outreach, and community engagement.

Prohibited uses

  • Spam: sending irrelevant, unsolicited mass messages to random recipients.
  • Harassment: messages designed to intimidate, threaten, or harm.
  • Sexual content or minors: DMs involving inappropriate content.
  • Impersonation: pretending to be someone you’re not.
  • Illegal activity of any kind.
  • Circumventing Instagram or TikTok blocks or bans.
  • Multi-account abuse: creating fake DMpro accounts to farm free credits.

DMpro’s AI monitors for prohibited content categories. Flagged messages may pause your generation, trigger a review, or result in a temporary account suspension. If Instagram or TikTok users complain about your outreach, we investigate: legitimate complaints result in warnings or suspension, while frivolous complaints don’t affect you.

Consequences for violations

  • First violation: a warning email.
  • Second violation: temporary suspension (7-30 days).
  • Severe or repeated violations: permanent account termination.
  • Illegal content: immediate termination, with potential legal action.

Other key terms

  • Age restrictions. You must be 16+ (or 18+ in some jurisdictions). Under-18 accounts are suspended when detected, and business accounts must be created by authorized representatives.
  • Account sharing. One person per account, except on Enterprise team plans, which support up to 10 team members. Sharing credentials violates the terms.
  • Data you send. You are responsible for the legality and accuracy of what you send. DMpro facilitates delivery but is not the sender of record, and you must comply with the laws in your jurisdiction and your recipients’.
  • Refund rights. A 30-day money-back guarantee applies to unused one-time credit packages, and a 7-day money-back guarantee applies to annual plans. Monthly subscriptions have no refund past the initial period.
  • Changes to terms. Terms may be updated periodically. Material changes come with 30 days’ email notice, and continued use counts as acceptance.
  • Governing law. DMpro operates from Toronto, Canada, and disputes are governed by Ontario law. Enterprise contracts may specify a different governing law.
This summary isn’t comprehensive. For complete details, read dmpro.brandid.app/terms, consult a lawyer for specific interpretation, or contact support for clarification.

DMpro is intentional about what data it does and doesn’t collect. Here is an explicit list of things DMpro never stores.

  • Your Instagram or TikTok password. DMpro has no login flow that asks for it. Never asked, never stored.
  • Full credit card details. Card number and CVV never touch DMpro’s servers, and the full expiration date is only stored by Stripe. DMpro keeps just the last 4 digits, for your reference.
  • Your bank account information. Bank routing/account numbers and debit card PINs are never asked for. Payment goes through Stripe, and DMpro only sees payment confirmations.
  • Your Instagram/TikTok DM history. Past DMs you’ve sent, DMs from other people, and group chat content are not read. DMpro’s extension only sends messages you generate through DMpro; it doesn’t peek at your existing conversations.
  • Your post content. Post captions, comment history, and story views are not read or tracked. Only profile bio and header data is used, for AI prompt context.
  • Your followers/following list. Who you follow and who follows you are not read. Only aggregate counts are used.
  • Your precise location. GPS coordinates and precise location are never tracked. IP geolocation is used only to approximate your country, for pricing and tax purposes.
  • Your contacts list. Phone contacts and your email address book are never asked for or synced.
  • Your browsing history. Other websites you visit, your search history, and your Google searches are not tracked. DMpro only knows about profile pages you deliberately visit while the extension is active.
  • Your other social media. Facebook, Twitter (X), LinkedIn, Snapchat, and similar platforms are not accessed. DMpro only touches Instagram and TikTok.
  • Data from third parties. DMpro doesn’t buy data from brokers and doesn’t scrape public data at scale for its own use. What you provide is what we have.
  • Sensitive personal info. SSN or national ID, health information, financial account balances, and political affiliations are never asked for or tracked.
  • Voice or video data. DMpro doesn’t have audio or video features, so nothing is recorded.
  • Cookies from other sites. DMpro’s cookies are same-origin scoped; it doesn’t read cookies from other sites.
  • Bulk metadata. Screen time on Instagram and detailed clickstream data are not tracked.
If it isn’t on this page’s “what DMpro stores” list, DMpro doesn’t have it. That’s by design, not by accident.

Still stuck? We’re happy to help.

Create your DMpro account, see pricing, or reach out to support directly.

Back to Help Center