At Noolu LLC (“Noolu,” “we,” “us,” or “our”), we build Instagram DM and comment automation infrastructure designed around privacy, security, and absolute transparency. This Privacy Policy explains how we collect, process, store, and protect your information when you use our platform at noolu.pro.
Noolu operates as both a Data Controller (for information related to registered creators and their accounts) and a Data Processor / Service Provider (when processing comments, direct messages, and interactions sent by Instagram users to our creators' accounts).
Key Principles:
When Instagram users interact with a creator's posts, Reels, or DMs managed by Noolu, we process the minimum technical data necessary to trigger configured flows:
Noolu requests only the specific API permissions required to deliver the automation features you explicitly configure:
instagram_business_basic
Reads your Instagram account ID, username, and profile picture to link your account to your Noolu dashboard.
instagram_business_manage_messages
Enables Noolu to receive incoming DMs via webhooks and dispatch automated direct message flows in response.
instagram_business_manage_comments
Monitors public comments on your posts and Reels to identify trigger keywords and send automated replies.
We process collected data exclusively for the following operational purposes:
We store personal data only for as long as necessary to provide the service and fulfill legitimate business purposes:
Account & Flow Configurations
Retained throughout the active lifetime of your Noolu account. Deleted immediately upon user-initiated account deletion.
Conversation Logs & Activity
Retained for up to 90 days for analytics, debugging, and trigger verification, after which records are automatically pruned.
Instagram Access Tokens
Retained only while your Instagram account is actively connected. Revoked and erased immediately upon disconnection or account deletion.
Encrypted System Backups
Maintained on a continuous 30-day rotating backup lifecycle for disaster recovery before permanent overwrite.
If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the CPRA, provides you with specific rights regarding your personal information:
To submit a verifiable consumer request, email info@noolu.pro with the subject “California Privacy Request.”
Noolu is designed exclusively for professional creators, businesses, and adults aged 18 and older. Our platform is not intended for or directed toward children under 13 (or under 16 within the European Union).
We do not knowingly collect or solicit personal information from children. If we discover that personal data from a child has been collected without verifiable parental consent, we will delete that data immediately. Parents or guardians who believe their child has provided personal information to Noolu can contact us at info@noolu.pro.
If you access Noolu from the European Economic Area (EEA), United Kingdom, or Switzerland, we process your personal data under the following legal bases recognized by the GDPR:
Where data is transferred outside the EEA, we ensure adequate protections are in place through Standard Contractual Clauses (SCCs) and robust cryptographic standards. EEA users also have the right to lodge a complaint with their local Data Protection Authority.
We employ enterprise-grade technical and organizational safeguards:
You maintain full ownership of your data. You can delete your account at any time directly from your dashboard — no waiting period, no friction.
Self-serve deletion permanently removes:
• Your profile, email, and authentication credentials
• Connected Instagram tokens and webhooks
• All visual automations and flow definitions
• Conversation logs and performance analytics