Privacy policy
Last updated 16 September 2026
YallaDM answers comments and messages on Instagram for the businesses that use it. This policy explains what YallaDM receives, what it keeps, who else handles it, how long it is kept, and how to have it deleted.
Who is responsible
YallaDM is operated by Aly Elazab. For any question about your data, or to make a request, email hello@growwithazab.com.
Each business that uses YallaDM decides which of its posts YallaDM answers and what it sends. YallaDM handles the data below only to do that.
Who this policy covers
- Businesses that connect an Instagram professional account to YallaDM.
- People who comment on or message those accounts.
What YallaDM keeps about a business
- The Instagram account id, and the access token Meta issues when the account connects, with the date it expires. The token is what lets YallaDM reply as that account.
- The replies the business sets up: which posts they apply to, the keywords that trigger them, the wording of the private and public replies, and the links they send.
- Records about a business and the people who comment on its posts are tagged with the business they belong to, so one business's records are kept apart from another's.
- The numbers the business exported from the tool it used before YallaDM, for a post YallaDM now answers, so it can compare the two.
What YallaDM keeps when you comment
YallaDM only reads comments on posts where the business has turned it on. Comments on other posts are not kept.
If your comment contains one of the business's keywords, YallaDM keeps:
- Your Instagram scoped id. This is a number Instagram gives YallaDM to tell people apart. It is not your account id, and other apps see a different number for you.
- Your Instagram username.
- The id of your comment, the id of the post, and when you commented.
- Whether YallaDM's reply to you was sent, is waiting to be sent, or failed, and how many times YallaDM tried.
If your comment doesn't contain a keyword, YallaDM keeps only the first 80 characters of it and the comment's id, without your scoped id, so a keyword that should have matched can be spotted and added.
What YallaDM keeps when you reply
If you tap a button in a message from YallaDM, or write back to it, YallaDM keeps:
- When you last wrote, which request is open, when YallaDM sent you what you asked for, and whether you got it by tapping a button, writing back, or commenting again.
- If the business asks people to follow it first, which step of that request you're on. YallaDM checks whether you follow when you tap, write back, or comment again while already talking with it, though a reply that arrives before YallaDM's last message gets no check. It doesn't keep the answer on your record, but the activity log below holds how each check turned out.
- The ids of the messages YallaDM sent you, so it can tell its own messages apart from a person's replies.
- Whether a person from the business replied to you, and when.
YallaDM reads each message to decide whether to answer, and doesn't keep what it says. Messages you send the business outside a conversation YallaDM started are not kept.
The activity log
YallaDM logs each step it takes, such as a reply sent or a reply that failed, so problems can be found and fixed. A log entry holds ids, the time, and Meta's error codes. It never holds the text of a comment or message, apart from the 80 character snippet described above.
Where a business asks people to follow it first, the log records the outcome of each follow check against your scoped id, with the time: that you were following, that you were not following yet and were asked again, that the check could not be made because Instagram returned an error, or that YallaDM sent you what you asked for anyway. So while your follow status is not kept on your record, the log does show what each check found.
What YallaDM never does
- It never stores photos, videos, links to Instagram media, profile pictures, or follower lists.
- It never keeps the text of private messages.
- It never reads anything from your profile before you tap a button or write to it.
- It never sells data, never uses it for advertising, and never builds advertising profiles.
Who else handles the data
- Cloudflare runs YallaDM and this website, stores YallaDM's database, forwards email sent to the contact address, and keeps short-lived technical logs.
- Meta Platforms operates Instagram and delivers the comments and messages. Meta handles them under its own privacy policy.
- Google hosts the inbox that email to the contact address is forwarded to.
How long it is kept
- Records about a person are deleted 12 months after their last comment or message.
- Comment snippets that matched no keyword are deleted after 30 days.
- A business's access token, replies and records are deleted within 30 days after it disconnects its account.
- Emails are kept for as long as it takes to handle them.
Your choices
- To stop automated messages, block the business's account on Instagram.
- To reach a person, write back in the conversation. The business reads these messages.
- To see or delete what YallaDM keeps about you, follow the steps on the data deletion page.
- A business can disconnect YallaDM at any time in its Instagram settings.
This website
This website sets no cookies, runs no analytics, and loads no scripts.
Children
YallaDM is not directed at children under 16. If you believe it holds a child's data, email hello@growwithazab.com and it will be deleted.
Changes
If this policy changes, the date at the top changes too. Businesses using YallaDM are told about important changes by email.