Privacy Policy
Effective date: September 6, 2026 · Last updated: September 6, 2026
1. Who we are
Engage by Adentra AI ("Engage", "we", "us") is a software product developed and operated by WINBONDS WEB PRIVATE LIMITED (GSTIN: 19AADCW2289D1Z5), an Indian private limited company. "Adentra AI" and "Engage" are product and brand names used by WINBONDS WEB PRIVATE LIMITED — they are not separate legal entities. WINBONDS WEB PRIVATE LIMITED is the entity responsible for the personal data described in this Policy.
2. Scope: three kinds of data
This Policy covers three distinct categories of data, kept clearly separate throughout:
- A. Your account data — information about you as our customer (name, email, billing/plan info).
- B. Instagram/Meta data obtained through your authorization — your Instagram account identifiers and the access token Meta issues when you connect your account.
- C. Data about people who interact with your Instagram account — commenters, Story repliers, and people who DM you, to the extent your automations process them.
3. Information we collect
A. Your account data
- Name, email address, and a securely hashed password (never stored in readable form) when you register.
- Plan/subscription tier, usage counters, and billing records tied to your account or agency workspace.
- If you sign in with Google, the basic profile information Google provides for authentication.
B. Instagram/Meta data (via your authorization)
- When you connect an Instagram professional account through Meta's official OAuth flow, we store your Instagram user ID, username, and an access token issued by Meta, so we can act on your behalf.
- Access tokens are encrypted at rest using authenticated encryption (AES-256-GCM) and are never written to logs or shown in our interface.
C. Data about people who interact with your Instagram account
- Comments — for comments matching the keywords you configure, we store the comment text, the commenter's Instagram-scoped ID and username, and the post/Reel reference.
- Story replies — if someone replies to your Instagram Story, we read that reply to check it against your configured triggers; a matching reply is handled the same way as an incoming Direct Message.
- Direct Messages — if you configure a DM-keyword automation, we read incoming Direct Messages sent to your account to check for a keyword match. We also store the content and delivery status of messages our automations send on your behalf.
- Contact records — a lightweight profile per person who has interacted with your account (Instagram-scoped ID, username, first/last-seen timestamps, interaction count, opt-out status) — this does not include comment or message text.
- Automation & error logs — records of what an automation did (matched, replied, sent a DM, posted a public comment reply, or failed) and why, used for your reporting dashboard and for troubleshooting.
- Usage/analytics records — aggregate daily counts (e.g., messages sent) used for plan limits and reporting.
4. What Engage's automation actually does
So this is unambiguous for you and for anyone reviewing our Meta integration, Engage:
- Matches incoming comments, Story replies, or Direct Messages against keywords/rules you configure.
- Sends a private Direct Message reply you configure.
- Optionally posts a public reply to the triggering comment via Instagram's official API, if you've configured that action.
- Does not post to Instagram Stories on your behalf.
- Does not look up or return product/catalog information — this feature does not exist in Engage today.
- Uses Meta's official Graph API exclusively — no scraping, browser automation, or unofficial endpoints.
5. How we use information
Solely to operate the service you asked for: matching triggers, sending the messages and comment replies you configured, showing you reports, enforcing plan limits, and keeping the service secure and reliable. We do not sell your data or Instagram data obtained through Meta, and we do not use it for advertising.
6. AI features (Ada, our in-app support assistant)
Engage includes an in-app assistant ("Ada") that answers your questions about the product. To generate responses, Ada sends your typed question — together with a small, deliberately limited set of non-identifying account indicators (such as your plan tier or small usage counts) — to third-party AI providers: Groq and, as a fallback, Google Gemini.
Ada never receives and never sends raw Instagram comment text, Direct Message content, access tokens, Instagram-scoped IDs, or usernames to these providers. We do not use Instagram, comment, or message data to train any AI or machine-learning model.
7. Who we share data with
We share data only with:
- Meta Platforms — to make the API calls you authorize.
- Hostinger — our hosting and infrastructure provider, which stores application data and relays application email on our behalf.
- Groq and Google Gemini — process support-chat text as described in Section 6.
- Google — if you choose to sign in with Google, for authentication only.
- Where we are legally required to disclose information.
If you operate an agency workspace, other members of that workspace can see contact metadata (who engaged, how often, opt-out status) and automation outcomes for workspaces they have access to. Raw comment or message content is not exposed through any workspace-facing view in the product today.
8. Data retention
- Account and Instagram-connection data is retained for as long as your account is active.
- Disconnecting an Instagram account (from inside Engage, or by removing the app from your Instagram settings) immediately disables that connection's automations and marks the connection as revoked, so it can no longer be used to access your account or send messages. The associated credential is retained in this inactive, encrypted state as part of your account history until you request full account deletion.
- Deleting your account entirely — including comment/message logs and contact records — is currently a manual process: email us (see Section 12) and we will action full deletion within 30 days and confirm by email.
9. Data deletion
You can request deletion in the following ways:
- Disconnect an Instagram account at any time from within Engage — this stops the integration immediately.
- Remove Engage from your Instagram account settings — Meta notifies us automatically, and we revoke that connection.
- Meta's Data Deletion Request callback — if you use Meta's own account-deletion tools, Meta notifies us via a signed request and we revoke the associated connection automatically.
- Full account deletion — email us at the address in Section 12 with the subject "Delete my account".
See Data Deletion for full details of this process.
10. Your rights
You may request access to, correction of, or deletion of your personal data by contacting us at adentra.ai@gmail.com. Depending on where you live, you may have additional rights under laws such as the GDPR or CCPA. We respond to verified requests on a best-effort basis; we do not claim certification under any specific privacy framework.
11. Security
We use HTTPS for data in transit, authenticated encryption (AES-256-GCM) for stored Instagram credentials, modern password hashing for account passwords, CSRF protection, and access controls that isolate each customer's (and each workspace's) data from others. No system is perfectly secure, but we take these obligations seriously.
12. Contact
- Privacy, data access and deletion requests (Sections 9 and 10): adentra.ai@gmail.com
- Product support: support@adentraai.com
- WINBONDS WEB PRIVATE LIMITED, the company operating this service: winbondsweb@gmail.com
13. Children
Engage is not intended for anyone under 18, and we do not knowingly collect data from anyone under 18.
14. Changes to this Policy
We will update this page and its "Last updated" date if this Policy changes materially.
15. Cookies
Engage sets only the cookies it needs to work: a session cookie that keeps you signed in, and a CSRF token that prevents another site submitting forms as you. Both are strictly necessary, which is why the notice on the site is an acknowledgement rather than a consent choice — there is nothing optional to switch off.
We do not set advertising cookies, and we do not use an analytics or tracking service. Your acknowledgement of the cookie notice is stored in your browser's local storage, not in a cookie. If we ever add anything that is not strictly necessary, this section and the notice will change to ask for consent first.