Privacy Policy
Effective 30 May 2025 · Last updated 13 August 2026
1. Read-only scope
Colecta AI Pvt Ltd ("Colecta") reads your Instagram insights to help you understand your own account. Our access is read-only: we never post, message, follow, or change anything on your Instagram.
2. Information we collect
- Account details you give us: name, email, and password (stored only as a secure hash) or a Google sign-in identifier.
- Instagram data via the official Graph API: your profile (username, followers, media count, bio, website, account type), your posts and their metrics (views, reach, likes, comments, shares, saves, watch time), account-level trends including follower vs non-follower reach, and — only at 100+ followers — estimated audience demographics.
- Usage data needed to run the service: your conversations, saved preferences (“memories”), and subscription status.
We only request the Instagram fields listed in our data contract, and nothing outside it.
3. How we use your data
- To analyse your account and answer your questions with figures drawn from your real metrics.
- To generate your first read and weekly briefings.
- To operate billing and provide support.
- To improve Colecta — only if you leave the “Help improve Colecta” setting on. You can turn it off at any time in Settings.
4. What we never do
- We never post or act on your Instagram.
- We do not sell your personal data.
- We do not compare you against other creators without your data forming part of an aggregate you opted into.
5. Sharing & subprocessors
We share data only with the providers needed to run the service — cloud hosting, our AI model provider (to generate answers), and our payment gateway (Razorpay in India). They process data on our behalf under contract and never for their own purposes.
6. Retention & your controls
- You choose how long we keep your data via the retention setting (keep forever, 30 days, or delete immediately after use).
- You can export all your data at any time from Settings.
- You can delete your account and all associated data at any time.
- If you disconnect Instagram, your stored history stays readable and we drop the live access token; you can reconnect in one tap.
7. Security
Instagram access tokens are encrypted at rest, passwords are stored as bcrypt hashes, and sessions use signed tokens over HTTPS. Access to production data is restricted.
8. Your rights
Consistent with India's Digital Personal Data Protection Act and similar laws, you may access, correct, export, or delete your personal data. To exercise these rights, use the in-app controls or email us.
9. Children
Colecta is not intended for anyone under 18, and we do not knowingly collect data from children.
10. Changes
We may update this policy; material changes will be notified in-app or by email. Continued use after an update means you accept the revised policy.
Company & contact
Colecta AI Pvt Ltd
Bengaluru, India
Email: contact@colecta.ai