Privacy Policy
Last updated 10 September 2026
Who this covers
Tappy is a comment-to-DM tool operated by Mobile Growth Media, LLC. This policy describes how we handle personal data. We are the data controller, and you can reach us at:
Mobile Growth Media, LLC131 Continental Dr, Suite 305Newark, DE 19713United StatesTwo different groups of people appear in it:
- Operators. People who connect an Instagram account to Tappy and build flows with it.
- Commenters. People who comment on an operator’s Instagram post and receive a message as a result. If you commented a keyword and got a DM, this section is about you.
What we collect from operators
- Your Instagram account details, meaning the account ID, username, display name and profile picture, taken from Instagram when you connect.
- An Instagram access token. This is what lets Tappy read comments and send messages as your account. It is encrypted with AES-256-GCM before it is stored and is never shown in the interface, sent to your browser, or shared with anyone.
- The flows you build, including trigger words and the message text you write.
- An activity log of triggers, sends and failures, so you can see what happened and why.
Tappy does not receive or store your Instagram password. Authorisation happens on Instagram, and we only ever hold a token that you can revoke.
What we collect from commenters
When you comment a keyword on a post that has a flow running, Meta sends us a notification containing:
- your Instagram-scoped user ID and username;
- the text of your comment and the post it was made on.
If the flow asks you a question and you answer, we store your answer. In most flows that means an email address. Only what you actually send in the conversation is stored. We cannot see your other messages, your followers, or anything else on your account.
Providing an email address is optional. If you would rather not, close the conversation and nothing further is recorded.
Why we process it
- To provide the service. Reading comments and sending replies is the entire function of the tool.
- To keep it working and safe. Logs and send limits exist to prevent failures and to avoid overwhelming recipients.
- Consent, for the details you volunteer. An email address is collected because you typed it in response to a question. That consent can be withdrawn at any time.
Where the GDPR applies, the operator who connected the account is the data controller for the leads their flows collect. Mobile Growth Media, LLC acts as processor for that data, and as controller for operator account data.
Who we share it with
We do not sell personal data, and we do not share it for advertising. It reaches only:
- Meta, because sending an Instagram message requires calling Meta’s API. Meta’s own handling of that data is governed by its policies.
- Our hosting and database providers, who store the data on our behalf and may not use it for anything else.
- The operator whose post you commented on. They can see, and export, the leads their flows collected.
How long we keep it
- Webhook records used to avoid duplicate messages are deleted after 30 days.
- Conversations that go unanswered are closed after about 8 days.
- Leads are kept until the operator deletes them or disconnects and deletes the workspace.
- Access tokens are deleted as soon as an account is disconnected.
Your rights and how to delete your data
You can ask for a copy of what we hold about you, ask for it to be corrected, or ask for it to be deleted. Write to team@gotap.it with the Instagram handle you used, and we will act on it within 30 days.
Deletion is a single operation for us: it removes every conversation and every stored answer tied to that handle, across all connected accounts. Nothing is retained afterwards except aggregate counts that identify no one.
There is a dedicated page with step by step instructions at Delete your data, including the automatic route through Instagram’s own settings.
Operators can disconnect Instagram from the Account page at any time, which deletes the stored token immediately and pauses every flow. You can also remove Tappy’s access from Instagram directly, under Settings, then Apps and websites.
If you are in the UK or EU and are unhappy with our response, you can complain to your local data protection authority.
Security
Access tokens are encrypted at rest. Every webhook from Meta is verified with a cryptographic signature before it is acted on, so forged requests are rejected. The dashboard is password protected and served over HTTPS.
No system is perfect. If you believe you have found a security problem, please write to team@gotap.it rather than posting it publicly, and we will respond quickly.
Children
Tappy is not intended for anyone under 13, and Instagram itself requires users to be at least 13. We do not knowingly collect data from children. If you believe we have, contact us and we will delete it.
Changes
If this policy changes in a way that affects you, we will update the date at the top and, where the change is significant, tell operators in the dashboard.
Questions go to team@gotap.it. The Terms of Use cover the rest of the relationship.