Privacy Policy
Last updated: 2026-08-23
This policy covers the hosted Chatamatic service at chatamatic.io and app.chatamatic.io. It is written plainly and describes what the software actually does.
Who we are
Chatamatic is operated by MiCCA OÜ, Soola 1a, Tartu, Estonia.
For questions, requests, or anything data-protection related: [email protected].
Two different roles
The distinction matters, because it decides who is responsible for what.
- We are the controller for your account: your name, email, workspace, team members, billing records, and how you use the product.
- We are a processor for the messages your automations handle. When a follower comments "GUIDE" on your Instagram post, we process that comment and that person's identifier on your instructions, to send the reply you configured. You are the controller for that data, and for having a lawful basis to contact those people.
What we collect
From you
- Account: name, email address, password hash (never the password itself), or your Google profile identifiers if you sign in with Google
- Workspace and team: workspace name, members, roles, invitations
- Billing: subscription status, plan, and billing metadata. Card details go directly to Stripe and never reach our servers
- Campaign configuration: keywords, the link or text you want delivered, and which posts a campaign watches
From the platforms you connect (see the permission table below)
- Access tokens for the accounts you connect, encrypted at rest
- Account identifiers: Facebook Page ID, Instagram Business Account ID, Threads user ID, WhatsApp Business Account ID, LinkedIn organization URN
- Your own posts, so you can choose which ones a campaign watches
- Inbound messages and comments that reach your connected accounts: the text, the sender's platform ID and public username, and the post it happened on
Automatically
- IP address, browser and device type, timestamps, and diagnostic logs
- If you accept analytics cookies, aggregate usage data. See our Cookie Policy
What we do with platform data
Platform data is used only to run the automation you configured. We do not sell it, do not use it for advertising, do not use it to train machine-learning models, and do not share it with anyone beyond the subprocessors listed below.
| Permission | What it lets us do for you |
|---|---|
public_profile, business_management |
Identify you during connection and list the assets you administer |
pages_show_list |
Show your Facebook Pages so you can pick which to connect |
pages_read_engagement, pages_read_user_content |
Read comments on your Page posts so a keyword can trigger |
pages_manage_metadata |
Subscribe your Page to webhooks so comments and messages reach us |
pages_messaging |
Send the reply you configured, in Messenger |
instagram_basic |
Read your Instagram professional account and its posts |
instagram_manage_comments |
Read comments on your posts so a keyword can trigger |
instagram_manage_messages |
Send the configured reply as an Instagram DM |
threads_basic |
Read your Threads profile and posts |
threads_read_replies |
Read replies to your Threads posts so a keyword can trigger |
threads_manage_replies |
Publish the configured reply, publicly, on the thread |
threads_manage_mentions |
Detect mentions of you carrying a keyword |
whatsapp_business_management |
Read the WhatsApp Business account you connect |
whatsapp_business_messaging |
Send the configured reply on WhatsApp |
LinkedIn is read-only and covers a company Page you administer, not a personal
profile — reading a member's own posts needs r_member_social, which LinkedIn has
closed. Under r_organization_social and rw_organization_admin we read comments on
that Page's posts and save matches as leads for you to follow up manually. Chatamatic
never sends anything on LinkedIn.
How long we keep it
| Data | Kept for |
|---|---|
| Trigger logs (which keyword fired, when) | 90 days |
| Delivery attempts (what was sent, success or failure) | 90 days |
| Click logs on tracked links | 180 days |
| Processed billing events | 7 days |
| Leads you captured | Until you delete them or close the account |
| Account, workspace, campaign configuration | Until you delete them |
| Invoices and billing records | As long as tax and accounting law requires |
Access tokens are deleted as soon as you disconnect a channel.
Who we share it with
| Subprocessor | Purpose | Region |
|---|---|---|
| Hetzner | Application and database hosting | United States |
| Cloudflare | CDN, DNS, DDoS protection; encrypted backup storage (R2) | Global edge |
| Stripe | Payments and subscriptions | US / EU |
| Resend | Transactional email (verification, password reset) | US |
| Sentry | Error monitoring | European Union |
| Meta | Instagram, Facebook, Messenger, WhatsApp, Threads APIs | Per Meta's terms |
| Community Management API | Per LinkedIn's terms | |
| Analytics, only if you accept cookies; AI caption suggestions, only if enabled | US |
We do not sell personal data. We have never sold personal data.
International transfers
Our application servers are in the United States. When personal data covered by EU or UK law is transferred there, we rely on the European Commission's Standard Contractual Clauses with the providers involved.
How we protect it
Access tokens and channel credentials are encrypted at rest. All traffic uses HTTPS. Sessions are protected with secure, first-party cookies, and two-factor authentication is available on every account. Database backups are encrypted before they leave the server. Access to production is limited to people who need it.
Your rights
If you are in the EU, UK, or another region with similar law, you can request access, correction, deletion, restriction, objection, and portability, and you can complain to your local supervisory authority. In Estonia this is the Data Protection Inspectorate (Andmekaitse Inspektsioon).
You can export your data from your account at any time, and delete your account without contacting us. See Data Deletion for exactly how.
Email [email protected] and we will respond within 30 days.
Deleting your data
Three routes, all of which work:
- In the app — delete your account or workspace from Account settings
- Disconnect a channel — removes that channel's tokens and identifiers
- From the platform side — removing Chatamatic in your Facebook Apps and Websites settings calls our data-deletion endpoint automatically
Full instructions: Data Deletion.
Children
Chatamatic is for businesses and creators, and is not directed at children under 16. We do not knowingly collect their data. If you believe a child has given us personal data, email us and we will delete it.
Changes
If this policy changes materially, we will update the date above and, where the change affects you, tell you in the app or by email.
Last updated: 23 August 2026.