Back to Home
Data Transparency & Security

Privacy Policy

At Noolu LLC (“Noolu,” “we,” “us,” or “our”), we build Instagram DM and comment automation infrastructure designed around privacy, security, and absolute transparency. This Privacy Policy explains how we collect, process, store, and protect your information when you use our platform at noolu.pro.

Effective: February 27, 2026
Official Instagram Graph API Integration
01

Overview & Roles

Noolu operates as both a Data Controller (for information related to registered creators and their accounts) and a Data Processor / Service Provider (when processing comments, direct messages, and interactions sent by Instagram users to our creators' accounts).

Key Principles:

  • We never ask for, view, or store your Instagram passwords.
  • We connect exclusively through Meta's Official Instagram Login for Business with cryptographic OAuth tokens.
  • We never sell, rent, or trade personal data to third parties, data brokers, or advertising networks.
  • You maintain total ownership of your data with immediate self-service deletion tools.
02

Information We Collect & Process

A. Information Provided by Creators

  • Account Credentials: Email address, name, and securely hashed passwords (using bcrypt).
  • Connected Instagram Account Data: Instagram account ID, username, and profile picture URL retrieved via official OAuth.
  • API Access Tokens: Long-lived OAuth access tokens used exclusively to perform authorized automation calls.
  • Automation Configurations: Keyword triggers, visual flow nodes, message templates, smart delays, and custom response logic.
  • Billing Information: Stripe customer IDs and subscription tier status (payment card details are handled directly by Stripe and are never stored on Noolu servers).

B. Information Processed for Third-Party Instagram Users

When Instagram users interact with a creator's posts, Reels, or DMs managed by Noolu, we process the minimum technical data necessary to trigger configured flows:

  • Comment Text: Public comment strings inspected to match keyword triggers (e.g. “LINK” or “INFO”) and post automated comment replies.
  • Direct Message Content: Incoming DM text required to execute multi-step conversational nodes.
  • Instagram-Scoped IDs (IGSID): Anonymous platform identifiers generated by Meta to route DMs back to the interacting user.
  • Link Clicks: Aggregate click timestamps when users click shortened tracking links (“/l/[slug]”) sent inside DMs.
03

Instagram Graph API Permissions Disclosed

Noolu requests only the specific API permissions required to deliver the automation features you explicitly configure:

instagram_business_basic

Reads your Instagram account ID, username, and profile picture to link your account to your Noolu dashboard.

instagram_business_manage_messages

Enables Noolu to receive incoming DMs via webhooks and dispatch automated direct message flows in response.

instagram_business_manage_comments

Monitors public comments on your posts and Reels to identify trigger keywords and send automated replies.

04

How We Use Your Data

We process collected data exclusively for the following operational purposes:

Executing automated DM and comment replies
Authenticating your account and dashboard sessions
Verifying incoming webhooks from Meta servers
Surfacing real-time dashboard performance metrics
Detecting urgent support keywords (e.g. 'help')
Providing customer support and debugging errors
05

Data Retention Schedules

We store personal data only for as long as necessary to provide the service and fulfill legitimate business purposes:

Account & Flow Configurations

Retained throughout the active lifetime of your Noolu account. Deleted immediately upon user-initiated account deletion.

Conversation Logs & Activity

Retained for up to 90 days for analytics, debugging, and trigger verification, after which records are automatically pruned.

Instagram Access Tokens

Retained only while your Instagram account is actively connected. Revoked and erased immediately upon disconnection or account deletion.

Encrypted System Backups

Maintained on a continuous 30-day rotating backup lifecycle for disaster recovery before permanent overwrite.

06

Cookies & Tracking Technologies

Noolu uses minimal, privacy-first cookies and tracking mechanisms:

Essential Session Cookies: We set an HTTP-only, secure JWT cookie (`access_token`) to maintain your authenticated login state.
First-Party Link Tracking: Shortened links (“/l/[slug]”) measure click counts for creator automations without third-party ad tracking or cross-site profiling.
No Third-Party Ad Cookies: We do not use third-party advertising cookies, data brokers, or retargeting pixels on your dashboard.
07

California Privacy Rights (CCPA / CPRA)

If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the CPRA, provides you with specific rights regarding your personal information:

  • Right to Know & Access: You can request disclosure of the categories and specific pieces of personal data collected about you.
  • Right to Deletion: You have the right to request the permanent erasure of your personal information.
  • Right to Correction: You can update or rectify inaccurate profile information directly in your settings.
  • No Sale or Sharing: Noolu does not sell or share personal information for cross-context behavioral advertising.
  • Non-Discrimination: We will never discriminate against you for exercising your privacy rights.

To submit a verifiable consumer request, email info@noolu.pro with the subject “California Privacy Request.”

08

Children's Privacy (COPPA)

Noolu is designed exclusively for professional creators, businesses, and adults aged 18 and older. Our platform is not intended for or directed toward children under 13 (or under 16 within the European Union).

We do not knowingly collect or solicit personal information from children. If we discover that personal data from a child has been collected without verifiable parental consent, we will delete that data immediately. Parents or guardians who believe their child has provided personal information to Noolu can contact us at info@noolu.pro.

09

International Transfers & European Privacy Rights

If you access Noolu from the European Economic Area (EEA), United Kingdom, or Switzerland, we process your personal data under the following legal bases recognized by the GDPR:

  • Performance of Contract: To deliver the automation services you configure and manage your subscription.
  • Legitimate Interests: To secure our infrastructure, prevent platform abuse, and maintain service reliability.
  • Legal Obligations: To comply with tax, corporate recordkeeping, and lawful authority requests.

Where data is transferred outside the EEA, we ensure adequate protections are in place through Standard Contractual Clauses (SCCs) and robust cryptographic standards. EEA users also have the right to lodge a complaint with their local Data Protection Authority.

10

Data Security Infrastructure

We employ enterprise-grade technical and organizational safeguards:

Bcrypt password hashing with unique salts
TLS 1.3 encryption for all data in transit
Redis JWT token blacklisting on logout
Automated IP rate limiting & brute-force protection

Self-Serve Data Deletion

You maintain full ownership of your data. You can delete your account at any time directly from your dashboard — no waiting period, no friction.

Self-serve deletion permanently removes:

• Your profile, email, and authentication credentials

• Connected Instagram tokens and webhooks

• All visual automations and flow definitions

• Conversation logs and performance analytics