Privacy Policy
Last updated: 2026-10-04
This Privacy Policy explains what information AiHopper (“AiHopper”, “we”, “us”) collects when you use the AiHopper application, why we collect it, and the choices you have. This page describes the current AiHopper product as implemented; it is written by the engineering team to be technically accurate and is not a substitute for legal advice. See the configuration note at the end of this document.
1. Who AiHopper is and what AiHopper does
AiHopper is a software product for creators, coaches and small businesses that helps you create and schedule Instagram Reels, and — if you choose to connect a professional Instagram account — automate replies to comments and direct messages, qualify leads from those conversations, and use AI to help write captions, hashtags, replies and Reel covers. AiHopper is not affiliated with, endorsed by, or a representative of Meta Platforms, Inc. or Instagram.
2. Information we collect
Account information
Your name and email address (used for login, verification, and account communications), and your password (stored as a hash by our authentication system, never in plain text).
Workspace information
The workspace/business name and any brand-profile details you enter (e.g. what your business does), used to ground AI-generated content in your actual business.
Instagram account information
If you connect a professional Instagram account: the account’s Instagram-assigned identifier, username, display name, profile picture URL, account type, and an encrypted access token issued by Meta. See Section 3 for the full Meta/Instagram-specific disclosure.
Comments, messages and events required for automations
When automations are enabled, comment and direct-message content and metadata (sender identifier/username, message text, timestamps) that Meta’s APIs deliver to us for the connected account, so automations and the shared inbox can work.
Contact details people choose to share
If you add a “collect email/phone” step to an automation, the email address or phone number a person types (or taps) in reply is saved on their lead record. It is only asked for in a DM and only saved when they send it.
Link clicks
If you turn on link tracking for an automation, links in its DMs are replaced by short AiHopper links. We record how many times each person’s link was opened and when (first and last click), so you can see which messages work. We do not store the clicker’s IP address or device with these counts.
Integrations and API keys
If a workspace admin connects a lead webhook (for example Zapier, Make or Google Sheets), new and updated lead details are sent to the URL they configure. API keys for MCP clients and scripts are stored only as a one-way hash.
Referrals
If you arrive through a referral link, we remember the referral code in a cookie for up to 30 days and, when you create your first workspace, record which workspace referred you so both sides can receive credits.
AI-generated content
Captions, hashtags, content ideas, Reel covers, analysis results and automated reply drafts that AiHopper’s AI features generate on your behalf.
Uploaded media
Videos and images you upload for Reels, plus derived files (normalized video, extracted frames, generated covers).
Usage and product analytics
Product usage events (e.g. which features are used), without message content, used to understand and improve the product.
Device/browser information
Standard web request metadata such as IP address (used for rate limiting and security) and user-agent, where applicable.
Logs and error information
Application logs and error reports. Error reports are scrubbed of request bodies, cookies, and values that look like credentials before being sent to our error-monitoring provider.
Cookies and similar technologies
AiHopper only stores what the service needs to work. We do not use advertising, tracking or cross-site cookies, so there is nothing to opt in or out of:
- Sign-in cookie (essential): keeps you signed in and protects your account. It ends when you sign out or the session expires.
- Referral cookie (only if you open someone's referral link): remembers the referral code for up to 30 days so both of you can get credits.
- Settings in your browser (local and session storage, never sent to anyone else): things like the workspace you last opened, list or board view, which tips you've closed, and a one-time key that stops a double-click from paying twice. Clearing your browser data removes them.
- Product analytics (PostHog) runs without cookies: it keeps an anonymous id in memory for the current page visit only and stores nothing on your device. It never records what you type, your messages or your screen.
When you pay, Razorpay's checkout and, on sign-up, Cloudflare Turnstile's bot check may set their own strictly necessary cookies for fraud prevention and security, under their own policies.
3. Instagram / Meta data — dedicated disclosure
Connecting Instagram is entirely optional and requires you to explicitly authorize AiHopper through Meta’s own OAuth consent screen for a professional (business or creator) Instagram account. AiHopper requests only the Meta permissions necessary for the features described in this product, currently:
- instagram_business_basic — read basic profile information for the connected account.
- instagram_business_manage_messages — read and send direct messages, for the inbox and DM automations.
- instagram_business_manage_comments — read comments and post replies, for comment automations.
- instagram_business_content_publish — publish Reels, photo posts, carousels and Stories you create and schedule in AiHopper.
- instagram_business_manage_insights — read the connected account’s own statistics for the Analytics page.
With the Insights permission, AiHopper periodically reads the connected account’s own statistics (follower count, reach, views and interactions for the account and for its recent posts and Stories) and stores them as snapshots to show trends, best times to post and top posts. These are aggregate numbers about your account, not information about the individual people who viewed it. Accounts connected before this permission existed keep working without it and show no statistics until reconnected.
Public media kit: off by default. If you turn it on, anyone with its link can see your username, follower count, 30-day reach, views and engagement rate, averages per format and the covers of your top posts. You can turn it off or replace the link at any time, which stops the old link working immediately.
Through these permissions, and depending on which features you use, AiHopper may receive and store:
- Your connected account’s identifier, username, display name, profile picture URL and account type.
- Comments on your posts/Reels and their authors’ identifiers/usernames, where a comment automation is configured.
- Direct messages you send and receive through the connected account, where messaging features or the shared inbox are used.
- Webhook-delivered events describing the above (comment created, message received, and similar), used to trigger automations.
- The Reel media you explicitly upload through AiHopper and ask AiHopper to publish to your connected account.
How this data is used: to display your connected account in AiHopper, to run the automations you configure, to populate the shared inbox and leads views, to publish Reels you schedule, and — only where you explicitly enable AI replies for an account or conversation — to let an AI feature draft a reply. Instagram access tokens are stored encrypted and are never returned by any AiHopper API response.
Disconnecting your Instagram account: you can disconnect at any time from AiHopper’s account settings. Disconnecting immediately deletes the stored access token, marks the connection as disconnected, and pauses any automations attached to that account. It does not, by itself, delete comment/message history already recorded in AiHopper; use data export/erasure (Section 5) for that, or see /data-deletion for the Meta-specific data deletion request process.
You can also revoke AiHopper’s access directly from Instagram/Meta’s own account settings at any time, independent of AiHopper. Meta will typically notify AiHopper of this through a callback; see /data-deletion for what AiHopper does in response.
4. AI processing
Certain AiHopper features send relevant user-provided or Instagram-derived content to our AI service provider to perform the functionality you requested. Depending on the feature, this can include: Reel audio for transcription, transcripts and captions for content analysis and hashtag suggestions, comment/message text for AI-drafted replies and lead/message analysis, and prompts for AI-generated Reel covers.
Data may be processed by our AI service provider to provide the requested functionality, subject to their applicable terms and policies. AI replies are opt-in per account/conversation and off by default. We do not claim that our AI provider uses your data to train their models; if you want their current data-use terms, consult their published policies directly, as we do not control and cannot guarantee their terms.
AI output is generated content, not verified fact, and is never used to automatically authorize a payment, financial action, or an irreversible account change. See the AI-generated content section of our Terms of Service for the responsibilities this places on you as the person configuring automations.
5. How we use information
- Providing and operating AiHopper, including the Instagram automation functionality described above.
- Reel processing: transcoding, thumbnail/frame extraction, transcription and publishing.
- AI features you enable (captions, hashtags, replies, covers, analysis).
- Account and infrastructure security (rate limiting, abuse detection, webhook signature verification).
- Analytics and product improvement, using non-content usage events.
- Customer support, to respond to requests you send us.
- Fraud and abuse prevention.
- Complying with legal obligations we are subject to.
6. Third-party service providers
AiHopper uses the following providers to operate the service. We only list providers actually integrated into the current product — this list is kept accurate as the product changes, and information is shared with each provider only where necessary to provide the corresponding functionality:
| Provider | Purpose |
|---|---|
| Meta / Instagram | Instagram account connection, comments, messages, Reel publishing (Section 3) |
| OpenAI | AI text/caption/reply generation, transcription, image (cover) generation |
| MongoDB | Primary application database (hosted database infrastructure) |
| Cloudflare R2 | Storage for uploaded/generated media (videos, images, covers) |
| Resend | Transactional email (verification, password reset and password-change notices, team invitations) |
| Razorpay | Payment processing for paid plans (see also the Terms of Service billing section) |
| PostHog | Product analytics (non-content usage events, cookieless) |
| Sentry | Error monitoring (scrubbed of request bodies, cookies and credential-shaped values) |
Information may be processed by these providers where necessary to provide the requested functionality, subject to each provider’s own terms and policies.
7. Data retention
We retain information for as long as reasonably necessary to provide the service, comply with legal obligations, resolve disputes, enforce agreements, and maintain security, unless a different retention period is required by applicable law. Where a specific automatic retention window is implemented in the product today, it is:
- Raw webhook event records (the data Meta delivers describing a comment/message event): automatically deleted after 30 days.
- Comment records shown in the app: automatically deleted after 90 days.
- Videos and photos you upload: deleted from our storage about an hour after they are published to Instagram (the cover image and post details stay until you delete the post). Unfinished uploads are deleted within a few hours.
- Messages, conversations and leads: kept until you delete them or erase your workspace.
- Internal audit-trail entries (action names and record ids only, no message content): kept for up to 1 year.
Deleting a workspace removes its database records and stored media objects we control, and deletes the stored Instagram access token, immediately. Deleting your account is scheduled 14 days ahead so a mistake (or someone else using your session) can be undone: straight away your plan stops renewing, your automations pause, your scheduled posts are held and you are signed out everywhere; you can sign in and keep the account until the date we email you, after which it is erased as described above. Financial/payment records are kept for accounting purposes as described in Section 5 of the workspace erasure behavior. After erasure we keep only a record that the deletion happened (dates and counts, with your email address stored as a one-way hash), and one-way hashes of your email address and Instagram account id that stop the one-time welcome credits from being claimed again. Backups are not individually edited when you delete data; daily backup snapshots are kept for 14 days and then deleted, so deleted data may persist in a backup for up to 14 days after deletion. Any background jobs queued for your data (e.g. a scheduled publish or a media-processing job) are cancelled or fail safely once the underlying record is deleted.
8. Your rights
Depending on your location and applicable law, you may have rights regarding your personal information, including to:
- Access the information we hold about you.
- Correct inaccurate information.
- Request deletion of your information (see /data-deletion).
- Withdraw consent, where processing is based on consent (for example, disconnecting Instagram or turning off AI replies).
- Object to or request restriction of certain processing, where applicable.
- Request a portable copy of your data, where applicable.
AiHopper already provides self-service data export and workspace/account deletion from within the product; to exercise any right not covered by those tools, contact us using the details in Section 11.
9. Security
Measures actually implemented in the current product include:
- Session-based authentication with mandatory email verification; resetting or changing a password signs out other devices and sends a notice to the account email.
- Server-side workspace membership checks on every workspace-scoped request (no client-supplied workspace id is trusted).
- Instagram access tokens encrypted at rest and never returned by any API response.
- HTTPS in production, with secure cookies and a strict Content-Security-Policy.
- Role-based access control within a workspace (Owner/Admin/Member/Viewer).
- Signature verification on incoming Meta and Razorpay webhooks before any event is trusted.
- Centralized secret management via environment configuration, with checks against known placeholder/default values in production.
- Structured logging and error monitoring, with rate limiting on sensitive endpoints.
No system is perfectly secure, and we do not claim certification against any specific security standard.
10. Children
AiHopper is not directed to, and is not intended for use by, children. If you believe a child has provided us with personal information, contact us using the details below so we can address it.
11. Contact
For privacy questions or requests, contact: privacy@www.aihopper.in.
docs/LEGAL-LAUNCH-CHECKLIST.md.