Back to DMSet AI

Privacy Policy

Last updated: August 24, 2026

This Privacy Policy explains how HRK Media Khan ("DMSet AI", "we", "us") collects, uses, and protects information when you use our Instagram DM automation platform (the "Service"). By using the Service you agree to this policy.

This policy is provided as-is for general information and is not legal advice. Depending on your business and location, you should seek your own legal advice about your obligations.

Information we collect

  • Account information you provide: name, email, login credentials (handled by our authentication provider), and billing details (handled by our payment processor).
  • Configuration data you enter to build your bot: business details, offer, qualifying questions, and connected-account credentials (your ManyChat, Calendly and AI provider keys). Credentials are held server-side only, protected by our hosting providers' encryption at rest, and are never returned to the browser.
  • End-user message data processed on your behalf: when your connected Instagram account receives a direct message, we process the message content and the sender's provided details (such as name, email, phone number, Instagram handle, profile photo, and their answers to your qualifying questions), together with a qualification score our AI derives from the conversation, in order to generate replies, qualify the lead, and book calls. You are the controller of this data; we process it as your service provider.
  • Conversation records: we keep a copy of each turn your bot takes. That record includes the message received, the reply sent, the unedited AI output before our formatting rules are applied, the instructions and settings that produced it, and the model and token cost. We keep it to operate the Service, investigate faults, review quality and bill usage, and authorized staff may read it for those purposes. This applies to live Instagram conversations, in-app test chats, shared demo links, and automated follow-ups.
  • Content you import or upload: training material and files you provide, screenshots and attachments you send with a support request, historical Instagram message archives you choose to import, and product information collected from a public storefront you ask us to read.
  • Usage and billing data: message counts, scan counts, and subscription status used to operate caps, metering, and billing.
  • Technical data: your IP address and browser user agent, recorded when you accept our policies and used for security, fraud prevention, and to evidence that acceptance.

How we use information

  • To provide, operate, and improve the Service.
  • To generate AI replies, qualify leads, and schedule calls on your behalf.
  • To enforce usage limits and process subscription payments.
  • To communicate with you about your account, security, and service changes.

Service providers we share data with

We use trusted third parties to run the Service, and share only what each needs. These include, for example, payment processing (Stripe), AI model providers (such as Anthropic, OpenAI, and OpenRouter), Instagram messaging delivery (ManyChat), scheduling (Calendly), profile lookups (Apify), workflow automation (n8n), our application and database hosting (Base44 and Supabase), edge hosting and delivery of our demo and developer endpoints (Cloudflare), email delivery to you (Resend), and internal team notification and alerting (Discord). Where you configure your own alert webhook, we also send notifications to the destination you choose, which may be Discord or Slack. This list is representative rather than exhaustive and may change as the Service evolves. Each provider processes data under its own terms and security commitments. We do not sell personal information.

Email we send you

We email the address on your account for two reasons, and you control them separately.

  • To run the Service. Receipts and invoices, failed payments, renewal reminders, security and account notices, support replies, usage warnings, and alerts when your bot stops replying. Our lawful basis is performance of our contract with you and our legitimate interest in keeping you informed about your own account. Account and billing emails cannot be switched off while you hold an account; the rest can.
  • Marketing. Product news, guides and offers about DMSet AI. Our lawful basis is your consent, given when you accept our Terms, and for existing customers our legitimate interest in telling you about our own similar products. It is off by default, every marketing email carries a one-click unsubscribe, and you can withdraw consent at any time without giving a reason and without affecting your subscription.

You can change all of this at Settings, then Notifications, or from the "manage which emails you get" link in the footer of any email we send, which works without signing in.

We record which emails we sent you, when, and whether they were delivered, opened, bounced or reported as spam. We keep that for deliverability and support (working out whether an invoice or a ticket reply actually reached you), not to build a profile of you, and we do not use it for advertising. We do not sell or rent your email address and we do not send third-party advertising to it.

Data retention

We retain account and configuration data while your account is active. Message and lead data is retained to provide your dashboard and bot memory, and is deleted on request or within a reasonable period after account closure, subject to legal and operational requirements.

Your rights

Depending on your location, you may have rights to access, correct, export, or delete your personal information, and to object to or restrict certain processing. To exercise these rights, contact us at dmsetai1@gmail.com. If you connect end-user data through your bot, you are responsible for having a lawful basis to do so and for honoring those individuals' rights.

California privacy rights (CCPA/CPRA)

If you are a California resident, the categories of personal information we collect include identifiers (such as name and email), commercial information (such as subscription and billing details), internet and other electronic network activity (such as usage and metering data), and inferences drawn to qualify leads on your behalf. We do not sell personal information, and we do not "share" it for cross-context behavioral advertising. You have the right to know and access the personal information we hold about you, to delete it, to correct it, and to opt out of any sale or sharing (which we do not do). To exercise these rights, contact us at dmsetai1@gmail.com. We verify requests before acting on them, and we will not discriminate against you for exercising these rights.

European rights (GDPR)

HRK Media Khan is established in Norway, which is part of the European Economic Area, so the GDPR applies to our processing. We process personal data on the following lawful bases: performance of a contract with you, our legitimate interests in operating, securing and improving the Service, and your consent where required. You have the rights to access, rectification, erasure, restriction of processing, data portability, and objection, as well as the right to withdraw consent at any time. To exercise these rights, contact us at dmsetai1@gmail.com. You also have the right to lodge a complaint with a supervisory authority. Ours is the Norwegian Data Protection Authority (Datatilsynet), and if you are elsewhere in the EEA or in the United Kingdom you may complain to your own local authority instead. For end-user and lead data processed through your bot, you (the customer) are the controller and DMSet AI acts as the processor, handling that data only on your documented instructions.

International data transfers

We are established in Norway. Several of our sub-processors are based in the United States and elsewhere, so your data may be transferred outside the European Economic Area. For those transfers we rely on appropriate safeguards, such as the European Commission's standard contractual clauses or, where the provider is certified, the EU-US Data Privacy Framework.

Cookies and similar technologies

We use strictly necessary cookies to keep you logged in, maintain your session, and protect the security of the Service. We do not use cookies to sell your data or for cross-context behavioral advertising.

Security

We use industry-standard measures including encryption in transit, server-side secret storage, row-level access controls, and tenant isolation. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

Children

The Service is not directed to individuals under 18, and we do not knowingly collect their information.

Changes

We may update this policy from time to time. Material changes will be posted here with an updated date.

Contact

Questions about this policy: dmsetai1@gmail.com.