Privacy Policy
What data Admino collects when you use the product, why we collect it, and who we share it with.
Last updated: July 17, 2026Please read this first
This page describes Admino's actual technical setup and data practices as accurately as we can, in plain language. It is not formal legal advice, and we are not lawyers. Before treating this as a complete compliance document, have it reviewed by qualified legal counsel familiar with the data-protection rules that apply to your business and your users.
Information we collect
Account information: a phone number or email address, and a display name, when you sign up.
- Instagram account information: your connected account's business profile details, plus the messages, comments, and insights data covered by the specific permissions you approve during Instagram's own login screen.
- Message and form content: the DMs, comments, and conversational form answers Admino processes so it can match and send the right automated reply.
- Payment metadata: your plan, amount, currency, and a gateway transaction reference from ZarinPal or Zibal. We do not receive or store your card number — you enter card details directly on the payment gateway's own secure page.
- Files and media: images, videos, and other files you upload for messages or posts, stored in S3-compatible object storage.
- Usage data: counts like messages sent, follow checks performed, and storage used, tracked against your plan's limits.
How we use your information
We use this information to run the automations and features you configure, deliver phone verification codes through Kavenegar, send transactional email through Resend, process payments through ZarinPal or Zibal, show you dashboard/usage data, enforce your plan's limits, and respond to messages you send us through the Contact page.
Your Instagram data specifically
Connecting an Instagram account uses Instagram's own official Business Login and Graph API — you approve access on Instagram's login screen, not inside Admino.
Admino never asks for, receives, or stores your Instagram password. What we can access is limited to the specific scopes you approve (basic profile access, messages, comments, publishing, and insights).
Disconnecting an Instagram account deletes its stored access credentials from Admino and immediately stops all automation for that account.
Where and how we store data
Structured account, message, and configuration data is stored in a PostgreSQL database. Short-lived state — like OTP codes, in-progress form sessions, and cached lookups — is stored in Redis.
Uploaded files and media are stored in S3-compatible object storage, referenced from our database rather than linked from public, permanent URLs by default.
Every new workspace defaults to the Asia/Tehran timezone, and Admino's sign-in sessions are cookie-based, lasting up to 7 days.
Third parties we work with
We share the minimum data each of the following providers needs to do its specific job for us:
- ZarinPal and Zibal — process your subscription payment; we never see your card number.
- Kavenegar — delivers phone verification (OTP) codes and phone-based invitations by SMS.
- Resend — delivers transactional email, such as account and subscription notifications.
- Meta's Instagram Graph API — powers the actual Instagram connection described above.
- Our object storage provider — hosts the files and media you upload.
Cookies and local storage
Admino's product application uses a single authentication cookie to keep you signed in for up to 7 days — this is functional, not advertising, and isn't sold or shared with ad networks.
This marketing site stores your light/dark theme preference directly in your browser (never sent to us), and may load Google Analytics for aggregate, anonymized traffic statistics if it's configured for the environment you're visiting.
Data retention and deletion
We keep your account and workspace data for as long as your account is active. Deleting a file removes it from our object storage before we remove its database record, so a file is never left consuming storage silently after you delete it.
You can request deletion of your account or data by contacting us through the Contact page. We'll act on that request as far as our systems technically support, and let you know if any part of it isn't possible.
Your rights
You can ask us to access, correct, or delete your personal data by reaching out through the Contact page. We'll do our best to respond promptly and explain what we can and can't do.
Children's privacy
Admino isn't directed at children, and we don't knowingly collect personal data from children.
Security
We apply reasonable technical measures to protect your data, including encrypted connections, rate-limited endpoints, and restricting access to sensitive fields like Instagram access tokens within our own systems. No method of storing or transmitting data is completely risk-free, and we haven't claimed any specific third-party security certification here.
Changes to this policy
We may update this policy from time to time. We'll update the "last updated" date above whenever we do.