Back to home

Legal

Privacy Policy

Effective date:
May 7, 2026
Last updated:
September 15, 2026

This Privacy Policy explains how everythread collects, uses, stores and protects information when you interact with an Instagram account that is operated, in whole or in part, by an AI agent powered by everythread.

If you message, comment on, or otherwise interact with an Instagram account using the everythread platform, this policy applies to you.

§ 1

Who We Are and What This Policy Covers

everythread is an Instagram AI agent platform. Businesses (“Brand Operators”) use everythread to operate AI-powered assistants on their Instagram accounts. The assistants read incoming direct messages and comments and respond on behalf of the Brand Operator.

This policy covers:

  • Data we receive from Meta Platforms, Inc. (“Meta”) through the Instagram Graph API and Messenger Platform.
  • Data we receive from end users (“you”) who message or comment on Instagram accounts operated using everythread.
  • Data we receive from Brand Operators who use the platform.
  • Billing data for Brand Operators who subscribe, which is collected and processed by our payment provider, Stripe.

This policy applies to the everythread platform globally, regardless of where you are located.

§ 2

Information We Collect

We only collect the minimum data needed to operate the AI agent. We do not collect Instagram passwords, payment card data (card payments are handled by Stripe; see Section 2.4), or any data outside the scope described below.

2.1 Information from Meta / Instagram

When you interact with an Instagram account operated using everythread, we receive the following from Meta’s Instagram Graph API and webhooks:

  • Instagram-scoped user ID (IGSID) — a numeric identifier assigned by Meta.
  • Instagram username and display name.
  • Profile picture URL (public).
  • Direct message content — text, attachments, stickers, reactions, voice notes, and any media you send to or receive from the Brand Operator’s account.
  • Comment content — public comments you leave on the Brand Operator’s posts, reels, or stories.
  • Message and comment timestamps.
  • Message metadata — message IDs, conversation thread IDs, and read receipts (where exposed by Meta).

We do not collect: your email, phone number, location, IP address, follower list, posts you have liked, accounts you follow, or any data outside the conversation thread between you and the Brand Operator.

2.2 Information from Brand Operators

Brand Operators provide:

  • Business name, contact information, and Instagram account details.
  • Brand voice, FAQ content, product/service information, and other training material used to configure the AI agent.
  • Account credentials are never collected — Brand Operators authorize everythread through Meta Business Suite partner permissions and Meta’s official OAuth flow.

2.3 Information We Do Not Collect

We do not collect, infer, or derive:

  • Sensitive personal data (race, ethnicity, religion, health status, sexual orientation, political opinions, biometric or genetic data) from your messages.
  • Data from anyone who has not directly interacted with a Brand Operator’s Instagram account.
  • Data via scraping, surveillance, or any source other than Meta’s official APIs.

2.4 Payments and Stripe

Brand Operators who subscribe to everythread pay through Stripe, Inc. (“Stripe”). Card and other payment details are entered into Stripe’s secure payment form (the Payment Element), which is served by Stripe and sends those details directly to Stripe. They never reach our servers. Changing plan, updating a payment method, and cancelling take place in Stripe’s hosted Customer Portal.

To manage a subscription, we share with Stripe and store:

  • The email address of the Brand Operator’s everythread login, sent to Stripe to create their customer record.
  • The Stripe customer ID and subscription ID, the plan subscribed to, the subscription status, and billing period, renewal, and cancellation dates.

Stripe collects information about how you interact with its payment form to provide its services, prevent fraud, and improve its services. This includes using cookies and IP addresses to identify which payment form elements you saw during a single checkout session. Stripe’s use of this information is governed by the Stripe Privacy Policy. For more about how Stripe handles personal data, see the Stripe Privacy Center.

§ 3

How We Use Information

We use the information described in Section 2 only for the following purposes:

  • Operating the AI agent. Reading your message or comment, generating a response in the Brand Operator’s voice, and replying via the Instagram Graph API.
  • Conversation continuity. Maintaining short-term conversation history so the agent can respond coherently within an active thread.
  • Agent quality and safety. Detecting abuse, spam, prohibited content, and routing complex or sensitive messages to a human at the Brand Operator.
  • Service operations. Logging errors, monitoring uptime, and debugging the platform.
  • Billing. Taking subscription payments through Stripe and keeping each Brand Operator’s subscription status current.
  • Compliance. Meeting our obligations under the Meta Platform Terms, Developer Data Use Policy, and applicable law.

We do not use your information for:

  • Selling, licensing, or renting your data to anyone.
  • Advertising, ad targeting, or building advertising profiles.
  • Profiling based on protected characteristics.
  • Re-identifying or de-anonymizing data.
  • Training general-purpose AI models. Your conversation data is not used to train foundation models.
  • Combining data across Brand Operators or with data from other sources, except as needed to operate the platform.
§ 4

Data Retention

We retain data only as long as needed to operate the platform:

  • Active conversation context: retained for up to 90 days of inactivity, then automatically deleted.
  • Brand Operator configuration data: retained for the duration of the Brand Operator’s contract, then deleted within 30 days of contract termination.
  • Aggregate, de-identified statistics (e.g., total messages handled per day): may be retained indefinitely. Cannot be linked back to you.

If you request deletion of your data (Section 5), we delete it within 30 days regardless of the schedule above, except where we are legally required to retain it.

§ 5

Your Rights and How to Exercise Them

You have the following rights regarding your data, regardless of where you live:

  • Right to access — request a copy of the data we hold about you.
  • Right to correction — request that we correct inaccurate data.
  • Right to deletion — request that we delete all data we hold about you.

How to Submit a Request

Email [email protected] with:

  • The Instagram username you used to interact with the Brand Operator’s account.
  • The Brand Operator’s account name (the IG account you messaged or commented on).
  • The type of request (access, correction, deletion, etc.).

We will respond within 30 days. There is no fee for submitting a request, and you do not need to explain or justify the request. Requests are honored regardless of your country of residence.

§ 6

Data Security

We implement industry-standard safeguards:

  • Encryption in transit (TLS 1.2+) for all data exchanged with Meta and sub-processors.
  • Encryption at rest for stored conversation data and configuration.
  • Access controls — least-privilege access, with all administrative access logged.
  • Webhook signature verification — all incoming Meta and Stripe webhooks are validated against their signing secrets to prevent spoofing.
  • No password storage — Brand Operators authorize via Meta’s OAuth flow only.
  • No card data on our servers — payment details are collected by Stripe’s payment form and sent directly to Stripe, a PCI DSS Level 1 certified payment provider.
§ 7

AI Agent Disclosure

When you message a Brand Operator’s Instagram account that is operated using everythread, your message may be read and replied to by an AI agent rather than a human. Brand Operators are required to disclose AI-generated responses where required by law (e.g., California SB 1001, EU AI Act). The agent will hand off to a human at the Brand Operator when your request requires human judgment.

You can opt out of AI interaction at any time by stating “speak to a human” or similar language in the conversation, by ceasing to message the account, or by blocking the account on Instagram.

§ 8

Compliance with Meta Platform Terms

This Privacy Policy is designed to comply with the Meta Platform Terms and the Developer Data Use Policy. Where any conflict arises between this policy and Meta’s policies, Meta’s policies control. We do not use Meta data for any purpose prohibited by Meta, including but not limited to: selling data, profiling on protected characteristics, surveillance, re-identification, unauthorized data combination, or use of data against users’ interests.

§ 9

Changes to This Policy

We may update this Privacy Policy from time to time. The “Last updated” date at the top reflects the most recent change. Material changes will be communicated via the everythread website and, where required by law, by direct notice. Continued interaction with a Brand Operator’s account after a change constitutes acceptance of the updated policy.

everythread

Made with ❤️ in Toronto

© 2026 1001550054 ONTARIO CORPORATION. All rights reserved.

everythread is a product of 1001550054 ONTARIO CORPORATION.