Legal
Privacy Policy
This policy explains what data the MriiaBot service processes, why, who it is shared with, and how to have it deleted.
1. Who processes your data
The service is operated by Oleh Ruslanovych Kuziv, a sole proprietor (ФОП) registered in Ukraine. The service is available at https://mriiatech.duckdns.org.
For any question about personal data, and for access, correction or deletion requests, contact olkuziv@gmail.com.
2. Two groups of people
- Shop owners — businesses that sign up and connect their Instagram account. For their data we act as the data controller.
- Shop customers — people who send a Direct message to a connected Instagram account. We process those messages on behalf of the shop, as a data processor; the shop remains the controller.
3. Data we hold about shop owners
- Facebook user ID and public profile — sign-in uses Facebook
Login with the
public_profilepermission only. We do not request access to your feed, friends, Facebook email address or ad accounts. - Business name and Instagram business account ID.
- Instagram Graph API access token — stored encrypted at rest and used solely to receive and send messages on behalf of your account.
- Bot configuration — system prompt, shop profile (delivery, payment and returns terms, tone of voice) and the product catalogue with photos that you upload yourself.
- Usage records — one row per processed message: timestamp, selected model tier and token counts. These are the basis for billing.
- Telegram chat ID — if you connected Telegram for escalating conversations to a human manager.
4. Data we process about shop customers
When a customer messages a connected account, we receive from Meta and store:
- the customer's Instagram sender ID (a numeric identifier issued by Meta);
- the message text and its timestamp;
- the conversation history, so the bot can answer in context;
- the bot's replies and whether they were delivered successfully;
- conversation state — whether the bot is currently answering or a human manager has taken over.
We do not request or separately store customers' names, phone numbers, addresses or payment details. If a customer types such information into a message, it is retained as part of the conversation text — which is why we advise shops never to ask for card details over Direct.
Comments. Where a shop has enabled comment handling, we also receive and store the text of public comments left on that shop's own posts, the commenter's Instagram ID and the comment ID, so the bot can answer the question the comment asks. Comment handling is disabled by default and must be switched on by the shop owner. Depending on that shop's settings, an answer may be posted as a public reply under the comment, sent to the commenter as a Direct message, or withheld entirely.
Photos and shared posts sent in a message. A customer may send a photo, share one of the shop's posts, or reply to one of its stories. We fetch that image only to produce a short text description of it, and store the description rather than the image itself.
4a. Actions we take on your Instagram account
Besides reading data, the service acts on the connected account on the shop owner's behalf. It never acts on any account other than the one the shop owner connected.
- Replying to Direct messages — the bot's answers, and messages a human manager types, are sent to the customer in the same conversation.
- Replying to comments — where enabled, a public reply may be posted under a comment on the shop's own post, and a private reply sent to the commenter.
- Publishing catalogue items — where the shop uses the publishing feature, we create posts on the connected account containing catalogue photos and caption text supplied by the shop owner. Posts are created only when the owner selects the items and confirms; nothing is published automatically or on a schedule. We never delete or modify existing posts.
5. Why we process it
- to let the bot reply meaningfully and in context;
- to find products in the shop's catalogue relevant to a customer's question;
- to hand difficult conversations over to a human manager;
- to calculate the cost of using the service;
- to detect failures and abuse.
The legal basis is performance of our contract with the shop owner and, for customer data, the shop's instructions as controller. We do not sell data and do not use it for advertising or profiling.
6. Who we share data with
Message text is sent to external providers so the service can function. Which ones depends on the model tier the shop selects:
- Meta Platforms (Instagram Graph API) — source of inbound messages and the channel for replies;
- Google (Gemini API) — the "Balanced" tier;
- Microsoft (Azure OpenAI) — the "Premium" tier, where configured;
- Telegram Messenger — if the shop connected Telegram, the text of an escalated conversation is delivered to the designated chat;
- our hosting provider — the servers running the application and the database.
Because these providers operate outside Ukraine, data may be processed abroad. We do not share data with anyone else except where required by law.
7. How long we keep it
- conversation history — kept while the shop's account is active, because it provides context for later messages;
- comment text and commenter IDs — kept on the same terms as conversation history, and removed with it;
- catalogue and settings — until you change or delete them;
- usage records — retained for billing and accounting purposes;
- Instagram access token — deleted as soon as the account is disconnected.
There is currently no scheduled automatic deletion. Instead, a shop owner can delete their account and all data themselves from the panel at any time — see the section below.
8. Your rights and how to delete your data
Under Ukraine's Law on Personal Data Protection you may ask what data we hold about you, and request its correction, deletion or restriction of processing, and withdraw consent.
Shop owners can delete their account themselves, from the "Delete account and data" page in the panel. Deletion is immediate and permanent, and covers the account, the Instagram connection and stored access token, bot settings, the catalogue and its photos, customer conversation history, the Telegram link, and usage records.
If you are a shop's customer, or you have lost access to the panel, email olkuziv@gmail.com with the subject "Data deletion". Shop owners should state the connected Instagram account; customers should name the shop they were messaging. We action such requests within 30 days and confirm completion by reply.
A shop owner can also disconnect their Instagram account at any time from the panel. The bot then stops receiving new messages and the stored access token is deleted.
Complaints about the processing of personal data may be submitted to the Ukrainian Parliament Commissioner for Human Rights.
9. Security
Access tokens are encrypted before storage. Traffic to Instagram, Telegram and the model providers uses HTTPS. Inbound requests from Meta are verified by an HMAC-SHA256 signature and those from Telegram by a secret header, so third parties cannot inject forged messages. Database access is limited to authorised personnel.
No system is perfectly secure, so we cannot guarantee absolute security of transmitted information.
10. Cookies
The service uses strictly necessary cookies only: to keep your session after signing in with Facebook, and to protect forms against request forgery. There are no analytics or advertising cookies.
11. Children
The service is intended for businesses and is not directed at anyone under 18. We do not knowingly collect data from children.
12. Changes to this policy
We may update this policy. The current version is always available at this address and the revision date appears at the top. Shop owners will be notified of material changes in the panel.