← CloseLoop

Privacy Policy

CloseLoop · Effective July 9, 2026

1. Who we are

CloseLoop ("CloseLoop", "we", "us") is an Instagram DM automation and appointment-setting tool operated by Shaurya Pal as a sole proprietorship. This Policy explains what personal information we collect through the CloseLoop website (closeloopdm.com), the CloseLoop dashboard, and the Instagram automation it powers, why we collect it, and how it's used, shared, retained, and protected. Contact us any time at support@closeloopdm.com.

2. Two roles: controller and processor

CloseLoop is used by coaches and businesses ("Customers") to manage Instagram conversations with their own leads and followers ("Leads"). It's important to understand two different relationships:

  • Customer account & billing data: for this, CloseLoop is the data controller. We decide how it's used, per this Policy.
  • Lead / conversation data (messages, contact details, comments, bookings belonging to a Customer's Instagram audience): for this, the Customer is the data controller and CloseLoop acts only as a data processor, handling it on the Customer's behalf and instructions. If you messaged, commented on, or booked a call with a business that uses CloseLoop, that business (not CloseLoop) is primarily responsible for your data and is your first point of contact for privacy requests. CloseLoop will still assist with any request per Section 8.

3. Information we collect

From Customers (coaches/businesses):

  • Instagram Business account connection details obtained via Meta's OAuth flow ("Login with Instagram"): Instagram-scoped account ID, username, and access token.
  • Dashboard access: CloseLoop uses a single shared deployment password per Customer, not individual user accounts, so we don't collect names/emails for dashboard login itself.
  • Configuration you choose to enter: system prompts/scripts, follow-up message sequences, uploaded voice notes, comment-reply keywords, Calendly and payment integration credentials you connect.
  • Billing contact details handled through our payment/billing process.

On behalf of Customers, about their Leads (processed as their processor, see Section 2):

  • Instagram-scoped ID, username, and profile info of anyone who messages or comments on the Customer's connected Instagram account.
  • Direct message content, both inbound and the Customer's/bot's outbound replies, including transcriptions of voice notes.
  • Contact details a Lead or Customer enters manually: name, email, phone number, timezone.
  • Comment text on the Customer's posts, for comment-triggered auto-replies.
  • Booking and scheduling data (call status, showed-up/no-show, Calendly event details).
  • Free-text notes a Customer adds to a Lead's record, and lead-source/ad-keyword tags.

Automatically:

  • AI usage logs (token counts, timestamps) for billing and reliability, not the message content itself beyond what's needed to generate the reply.
  • Server/application logs for debugging and abuse prevention.
  • A browser push-notification subscription endpoint, if a Customer enables push alerts.
  • An essential session cookie used only to keep a Customer logged into the dashboard. We don't use third-party advertising or cross-site tracking cookies in the dashboard itself. The closeloopdm.com marketing site may use standard, privacy-respecting analytics cookies to understand site traffic.

4. How we use information

  • Operate the core service: send and receive Instagram messages via the Meta Graph API/Instagram API on a Customer's behalf.
  • Generate AI-drafted or AI-sent reply text and voice-note transcriptions, using third-party AI providers (Section 5).
  • Schedule and track appointments via Calendly.
  • Send email alerts and push notifications for events like a Lead needing human handoff.
  • Retarget booked/engaged Leads through a Meta Custom Audience, only when a Customer has explicitly configured this feature.
  • Bill Customers and track platform usage.
  • Provide customer support, and maintain and secure the service.

We do not sell personal information, and we do not use Lead conversation content to train our own AI models.

5. Third-party service providers

We share the minimum data necessary with the following providers to operate CloseLoop. Each processes data under its own terms/privacy policy:

  • Meta / Instagram Graph API: sending/receiving DMs, reading and replying to comments, and (if enabled) Custom Audience retargeting. Use of data obtained through the Instagram API complies with the Meta Platform Terms and Instagram Platform Policy.
  • Anthropic (Claude API): message content is sent to generate AI reply text.
  • Groq: voice note audio is sent for speech-to-text transcription, only if a Customer's deployment has this enabled.
  • Calendly: booking/scheduling data, only if a Customer connects it.
  • Resend: delivers transactional email alerts to Customers.
  • Railway: cloud hosting infrastructure; the database and audio files are stored on Railway's platform.
  • Web push services (browser/OS push relays, e.g. Google/Mozilla/Apple): deliver push notifications, only if a Customer enables them.

6. Data retention

  • Message content and AI usage logs are automatically deleted after 120 days (configurable per deployment) by a nightly cleanup process.
  • Lead profile, booking, and notes records are retained until the Customer deletes them or requests deletion of the underlying Lead.
  • Instagram access tokens are retained, encrypted at rest, only while a Customer's Instagram account stays connected, and are deleted immediately on disconnect.
  • Database backups are retained on a rolling basis and pruned automatically per the Customer's configured retention window.

7. Data security

All traffic to and from CloseLoop is encrypted in transit (HTTPS). Instagram access tokens are encrypted at rest. Every inbound webhook from Meta is verified using HMAC-SHA256 signature validation before it's processed. Dashboard access is protected by a password. No system is perfectly secure, and we can't guarantee absolute security, but we take reasonable technical measures to protect the data we hold.

8. Your rights & data deletion

Depending on where you're located (e.g. under the EU/UK GDPR or the California CCPA/CPRA), you may have the right to access, correct, export, or delete your personal information, and to object to or restrict certain processing. We don't sell personal information, so there is nothing to opt out of in that respect.

If your data relates to a Lead conversation with a specific business, that business is the controller of that data (Section 2) and is the first point of contact. You can also reach us directly at support@closeloopdm.com, or see our Data Deletion Instructions for how to request that your data be deleted.

9. Children's privacy

CloseLoop is a business tool intended for users 18 and older. We do not knowingly collect personal information from anyone under 18.

10. International data transfers

CloseLoop's infrastructure and service providers may process data in the United States, India, and other countries where our providers operate. Where required, we rely on appropriate safeguards for international transfers of personal data.

11. Instagram Platform data

CloseLoop uses the Instagram API to send and receive messages and manage comments on behalf of a Customer's connected Instagram Business account. Any information obtained through the Instagram API is used and shared only as described in this Policy, and in accordance with the Instagram Platform Policy and Meta Platform Terms.

12. Changes to this Policy

We may update this Policy from time to time. Material changes will be reflected by updating the effective date at the top of this page.

13. Contact

Questions about this Policy or how your data is handled: support@closeloopdm.com