Privacy Policy
Duplio is an AI assistant that replies to Instagram DMs on behalf of the businesses that use it. This page describes exactly what data we handle, who we share it with, how long we keep it, and how to have it deleted.
1. Who we are, and which role we play
"Duplio", "we", and "us" refer to the operator of the Duplio service at duplio.app. Duplio is sold to businesses — gyms, coaches, and similar — which we call customers.
There are two different kinds of people whose data passes through Duplio, and our responsibilities differ for each:
- Instagram users who message a customer's account. We process these messages on behalf of that customer, on their instructions. Under GDPR terms, the customer is the controller of that data and Duplio is a processor. If you sent a DM to a business and want your data removed, section 7 explains how — you can come to us directly, and we will also tell that business.
- Our customers themselves — the account owner who signs up, connects their Instagram, and pays. For their own account data we are the controller.
2. What we collect from Instagram users
When someone sends a DM to a customer's Instagram account and Duplio is connected to it, the message is forwarded to us either by ManyChat or by Meta's Instagram Messaging API. We receive and store:
- Message content. The text of DMs in the conversation — both the incoming messages and the replies Duplio sends — stored in our database as part of the conversation history so the assistant has context for later replies.
- Account identifiers. A messaging platform ID (a ManyChat subscriber ID or a Meta Instagram-scoped user ID), and, where the platform provides it, the Instagram handle and display name.
- Images sent in the DM. If a photo or GIF is sent, we download it, send it to OpenAI's vision model to produce a short text description, and store that description in the conversation in place of the image. We do not retain a copy of the image file itself.
- Voice notes. If a voice note is sent, we download it, send it to OpenAI's Whisper API to produce a text transcript, and store that transcript in the conversation in place of the audio. We do not retain a copy of the audio file itself.
- Conversation metadata. Timestamps, conversation stage and status, and counts used for billing and rate limiting.
We do not buy data about you, we do not track you across other websites, and Duplio sets no advertising cookies.
3. What we collect from customers
- Account details — name, email address, and the business details entered during onboarding.
- Billing data — a Stripe customer and subscription identifier. Card numbers go directly to Stripe; Duplio never sees or stores them.
- Connection credentials — ManyChat API and app keys, Meta long-lived access tokens, and Google Calendar service-account credentials where calendar booking is enabled. These are encrypted at rest in our database using authenticated symmetric encryption (Fernet/AES-128-CBC with HMAC), and are decrypted only in memory at the moment they are needed to call the relevant API.
- Usage counters — message and conversation volumes, and model token usage, used for billing and plan limits.
4. Why we process this data
- To generate and send DM replies on the customer's behalf — the core function of the product.
- To keep conversation history, so replies stay coherent across a conversation.
- To book calls into the customer's calendar when a lead is ready.
- To notify the customer by email when a conversation needs a human.
- To meter usage for billing, enforce plan limits, and prevent abuse.
- To operate, debug, and secure the service.
Our legal bases, where GDPR applies, are: performance of a contract (with customers), and the legitimate interests of our customers in responding to people who message their business. Where consent is required for a customer's own marketing use of DM data, it is the customer's responsibility to obtain it.
5. Who we share data with
We do not sell personal data, and we do not share it for advertising. We use the following subprocessors to run the service:
| Provider | Purpose | Data it receives |
|---|---|---|
| OpenAI | AI model that writes the replies, describes images, and transcribes voice notes | Conversation message content, images and voice note audio sent in the DM |
| Supabase | Hosted Postgres database | All stored data described above |
| Railway | Application hosting | Data in transit through the app, plus operational logs |
| ManyChat | Message transport (for customers connected via ManyChat) | Message content and subscriber identifiers |
| Meta | Instagram Messaging API transport | Message content and Instagram-scoped user IDs |
| Stripe | Customer billing | Customer billing details only — no lead or DM data |
| Resend | Transactional email to customers | Customer email address and handover notification content |
| Calendar booking, where the customer enables it | Booking details for the appointment |
We may also disclose data where we are legally required to, or to protect our rights or the safety of others.
A note on AI processing
Duplio's replies are generated by a large language model operated by OpenAI. This means the content of Instagram DMs handled by Duplio leaves our infrastructure and is sent to OpenAI's API in order to produce a reply. OpenAI processes it as our subprocessor under its commercial terms. If that is not acceptable for a given conversation, that conversation should not be routed through Duplio.
6. Where data is stored, and for how long
Data is stored in our hosted Postgres database and processed on servers operated by our hosting and model providers, which may be located in the United States. Where data is transferred out of the UK/EEA, we rely on our providers' standard contractual clauses.
Retention. Conversation history, lead records, and message content are retained for as long as the customer's account is active, because that history is what the assistant uses for context. Duplio does not delete data on a fixed schedule — there is no automatic expiry after a set number of days. Deletion is triggered by a request, and happens when: you send a deletion request through Instagram, which Duplio acts on automatically and immediately (section 7); you email us a deletion request, which we handle manually within 30 days (section 7); or the customer closes their account (within 90 days of closure). Billing records are kept for as long as tax and accounting law requires, and are not removed by any of these routes.
7. How to delete your data
If you are an Instagram user who messaged a business using Duplio, there are two ways to have your data removed. Both delete the same things: your lead record, your conversation history, and all stored message content. Neither costs anything.
Option 1 — through Instagram (automatic, immediate). If you remove Duplio from your Instagram account and request your data be deleted, Instagram sends that request to us directly. We act on it automatically: your records are deleted immediately, with no manual step and no waiting period. Instagram shows you a confirmation code for the request, and this page is the status page that code refers to — if you have a code and want to check on it, email it to us at the address below. This route reaches the records we hold for businesses connected to Instagram through Duplio directly. If you messaged a business that reaches you through ManyChat instead, use option 2, which covers every case.
Option 2 — by email (manual, within 30 days). Email
toby.onabolu@gmail.com
with the subject line Data deletion request and include:
- The Instagram handle you messaged from, and
- The Instagram account of the business you were messaging.
We use those two details to locate your records. We will then permanently delete your lead record, your conversation history, and all stored message content associated with that business, and confirm by email once it is done. We handle these requests manually and will complete them within 30 days of receiving the request.
Either route leaves the business's billing records with us — invoices and usage counts that we are required to keep for tax and accounting purposes. Those are records about the business's account, not about you, and contain no message content.
Note that the business you messaged also holds your conversation inside Instagram itself, and possibly in ManyChat. Deleting your data from Duplio does not delete the thread from Instagram — for that you would need to contact the business or delete the conversation from your own Instagram account.
If you are a Duplio customer and want your account and all associated lead data deleted, email the same address from the address on your account.
8. Your other rights
Depending on where you live, you may have the right to access the personal data we hold about you, correct it, restrict or object to its processing, or receive a copy of it in a portable format. Email toby.onabolu@gmail.com and we will respond within 30 days. Because we act as a processor for DM data, we may need to refer your request to the business you messaged, and we will tell you when we do. If you are in the UK or EEA, you also have the right to complain to your local data protection authority.
9. Security
All traffic to Duplio is served over HTTPS. Third-party credentials are encrypted at rest as described in section 3. Access to the production database is restricted to the people who operate the service. No system is perfectly secure, but if a breach affects your data we will notify affected customers and, where required, the relevant regulator.
10. Children
Duplio is a business tool and is not directed at children. We do not knowingly collect data from anyone under 13. If you believe a child's data has reached us through a DM, contact us using section 7 and we will delete it.
11. Changes to this policy
If we change how we handle data, we will update this page and change the "last updated" date above. Material changes will also be emailed to customers.
12. Contact
Questions about this policy, or about data Duplio holds, go to toby.onabolu@gmail.com.