Privacy Policy
Last updated: October 1, 2026
This policy explains what personal data FastDM collects, why, who it is shared with, how long it is kept, and how you can access or delete it. It covers the website at fastdm.net, the FastDM dashboard, and the automations FastDM runs on Instagram and Facebook.
In short
- We use your data only to run FastDM for you. We don't sell it, use it for advertising, or use it to train AI models.
- We never store the text of the comments people leave on your posts, or who left them.
- FastDM sends replies and DMs for you, but it can't read your DM inbox.
- Access tokens for your Instagram and Facebook accounts are stored encrypted, and our data is hosted in the European Union.
- You can disconnect an account, or ask us to delete everything, at any time. See How to delete your data.
1. Who we are
FastDM is operated by Ahmed Aziz, an individual based in Egypt ("FastDM", "we", "us").
For the data about you as a FastDM user, we are the data controller. For the data of people who comment on your posts, we process it on your behalf, as described in section 4.
You can reach us about anything in this policy at support@fastdm.net.
2. The data we collect
Your FastDM account
- Email address and password. Sign-up, sign-in and password resets are handled by our authentication provider, Supabase. Your password passes through our server on its way to Supabase, but we never store or log it. Supabase keeps only a secure hash of it.
- Profile and plan: a username created from your email address, when you joined, and your plan (trial, Pro, founder).
- What you set up in FastDM: your automations (keywords, reply and DM texts, links and button labels), your saved replies, and which posts you automate.
Accounts you connect
When you connect an Instagram professional account or a Facebook Page through Meta's official login, we receive the data described in section 3.
Security and service data
- Server logs. Our hosting provider records each request to FastDM: IP address, browser type, the page or API called, and the time.
- Sign-in protection. To limit password guessing and fake sign-ups, we count attempts per email address and per network. The counters hold only one-way hashes of the email and IP address, never the address itself.
- Token access log. Each use of a stored access token is logged. For requests from the dashboard, the log includes your IP address. This lets us investigate misuse.
- Trial records. Each Instagram account and Facebook Page gets one free trial. To enforce that, we keep the connected account's ID, the trial dates, the internal ID of the FastDM login that started the trial, and a one-way hash of that login's email.
- Invite codes. If you were invited as a founder, we keep a hash of your code, and when and by whom it was redeemed.
We don't use analytics, advertising or tracking tools, and we don't buy data about you from anyone.
3. Instagram and Facebook data
FastDM uses Meta's official APIs. You choose which account to connect, and you can disconnect it at any time. We ask only for the permissions FastDM needs:
| Permission | Why FastDM needs it |
|---|---|
| instagram_ | To show which account you connected (ID, username, profile picture) and list your posts and reels, so you can choose which ones to automate. |
| instagram_ | To be notified of new comments on the posts you automate, and to post the public reply you set up. |
| instagram_ | To send the commenter one private reply (DM) with your message and link. |
| pages_ | To list the Facebook Pages you manage, including Pages owned through Meta Business Suite, so you can choose one. |
| pages_ | To read the Page's posts and subscribe the Page to comment notifications. |
| pages_ | To post the public reply under a comment on your Page. |
| pages_ | To send the commenter one private reply (DM) from your Page. |
With these permissions we store:
- Instagram: your professional account ID, an app-specific user ID, your username and a link to your profile picture. We also read your name, account type and follower count while connecting, but we don't keep them.
- Facebook: the Page's ID, name and picture, and your Facebook user ID for this app. We use the user ID to process Meta's deauthorization and deletion requests.
- Access tokens: encrypted, so FastDM can act for you. Instagram tokens are renewed automatically while your account can run automations.
- Your posts and reels: each post's ID, caption, link, thumbnail link and publish time, so the dashboard can show them.
FastDM subscribes only to comment notifications. On Instagram these are the "comments" notifications; on Facebook, the Page "feed" notifications, of which FastDM uses only new comments. FastDM sends private replies but never reads your conversations, inbox or the messages people send you.
We use Instagram and Facebook data only to provide FastDM to you, in line with Meta's Platform Terms. We don't sell it, use it for advertising, share it with data brokers, or use it to profile anyone.
4. People who comment on your posts
When someone comments on a post you automate, Meta sends FastDM a notification with:
- the comment's ID and text;
- the commenter's ID;
- their username (Instagram) or name (Facebook).
FastDM uses these in memory, only to:
- check the comment for your keywords;
- skip comments made by your own account;
- fill in personalization tags such as
{first_name}or{username}; - post your public reply and send one private reply, as Meta allows.
We don't store the comment's text, or the commenter's ID, name or username, and they don't appear in our logs. We keep only a processing record: the comment's ID, the post, the time, and whether a reply and a DM were sent. It stops the same comment from being answered twice and feeds your dashboard counts, and it's deleted after 90 days.
For this data you decide what is automated and what the messages say, and FastDM processes it on your behalf (see section 10 of the Terms of Service). If you want to delete a commenter's data, or they ask you to, contact us and we will help.
5. How we use data, and our legal bases
Where the EU or UK General Data Protection Regulation (GDPR), or Egypt's Personal Data Protection Law (Law No. 151 of 2020), applies, we rely on these legal bases:
- To provide FastDM (performance of our contract with you): creating your account, connecting your accounts, running your automations, showing your dashboard, and support.
- To keep FastDM secure and fair (our legitimate interests): rate limits, the token access log, trial records, fraud and abuse prevention, and enforcing our Terms.
- To send service emails (contract): confirming your email, resetting your password, and important notices about your account or these policies. We don't send marketing emails without your consent.
- To answer commenters for you (your legitimate interest in answering people who ask for your link, and theirs in receiving it; we act on your behalf): see section 4.
- To comply with the law and Meta's policies (legal obligation and legitimate interests): responding to lawful requests, keeping required records, and meeting the obligations of the Meta platform.
FastDM doesn't make decisions about you based solely on automated processing that have legal or similarly significant effects. Matching a keyword and sending the reply you set up is an automation you control.
6. Who we share data with
We share personal data only with service providers that help us run FastDM. They process it on our instructions and under contracts that protect it:
| Provider | What for | Where the data is |
|---|---|---|
| Google Cloud | Hosting the app, the queue that processes comments, server logs, secret storage | Belgium (EU) |
| Supabase | Database and sign-in (authentication) | Frankfurt, Germany (EU) |
| Resend | Sending account emails (confirmation, password reset) | EU region |
| Meta Platforms | Carrying out your automations on Instagram and Facebook. Meta's own policies govern what Meta does with data | Meta's infrastructure |
| Google Fonts | Serving the font our pages use. Your browser requests it directly, so Google receives your IP address | Google's infrastructure |
When paid plans launch, payments will be handled by a payment provider (Stripe). We'll update this policy before that starts. FastDM won't see or store your full card details.
We may also disclose data:
- if required by law or a valid legal request;
- to protect the rights, safety or property of our users, the public or FastDM;
- as part of a merger or sale of the service, in which case this policy continues to apply to your data.
We don't sell personal data or share it for advertising.
7. Where data is stored
Our database, sign-in service and hosting are in the European Union. Some of our providers are companies based outside the EU, such as in the United States, and FastDM is operated from Egypt.
Where personal data is transferred outside the European Economic Area or the country you are in, we rely on appropriate safeguards. These include the European Commission's Standard Contractual Clauses, which our providers offer in their data processing terms.
8. How long we keep data
| Data | Kept for |
|---|---|
| Your FastDM account: email, username, plan, saved replies | Until you ask us to delete your account |
| A connected account: IDs, username, picture link, encrypted token, posts list, automations, comment totals | Until you disconnect it or remove FastDM in Instagram or Facebook. The token is deleted earlier if Meta stops accepting it, or 30 days after a free trial ends without a paid plan. |
| Comment processing records (comment ID, post, time, whether a reply and DM were sent) | 90 days |
| Token access log | 90 days, or until the account is disconnected |
| Records of data deletion requests from Meta | 90 days, so you can check the status |
| Sign-in and sign-up attempt counters (hashed) | 1 day |
| Server logs | About 30 days |
| Trial records (connected account ID, trial dates, FastDM login ID, hashed email) | As long as FastDM offers free trials, so each account gets only one |
When the retention period ends, the data is deleted automatically. Copies in our providers' backups, if any, expire on those providers' normal schedules.
9. Security
- All traffic to FastDM is encrypted with HTTPS, and the dashboard uses a secure, HTTP-only sign-in cookie that page scripts can't read.
- Access tokens are encrypted before they're stored, and the encryption keys are kept in a separate secret store.
- The app connects to the database through a restricted role, with only the access it needs. Access to production systems is limited to the operator and monitored.
- We're alerted to unusual activity, such as rejected requests or unexpected access to secrets.
No system is perfectly secure. If a breach affects your personal data, we'll notify you and the relevant authorities as the law requires.
10. Cookies and browser storage
FastDM uses only what's strictly necessary for the service to work, so no consent banner is needed:
- fewchats_session: keeps you signed in. It's HTTP-only and expires with your sign-in session.
- fewchats_signed_in: tells our pages that you're signed in, so they can show the right buttons. It contains no personal data.
- Browser storage: your dashboard preferences (such as the platform you last viewed), a founder invite code while you sign up, and the email you typed, for the sign-in pages in the same tab only. This stays in your browser and isn't sent to us except when you submit a form.
We don't use advertising or analytics cookies.
11. Your rights
Depending on where you live, you have the right to:
- access the personal data we hold about you;
- correct it;
- delete it;
- receive a copy of it in a portable format;
- object to, or restrict, how we use it;
- withdraw consent where we rely on consent.
To use these rights, email support@fastdm.net from the address on your account. We may ask you to confirm your identity. We reply within one month, and we don't charge for reasonable requests.
You can also complain to a data protection authority. In the EU, that's the authority in your country. In Egypt, it's the Personal Data Protection Center. We'd appreciate the chance to resolve your concern first.
12. How to delete your data
Disconnect an account in FastDM
In the dashboard, open the account and choose Disconnect. This immediately deletes:
- its access token;
- its posts list;
- its automations;
- its comment records and totals;
- its token access log.
It also stops FastDM's webhook notifications for that account, unless another FastDM user has connected the same account. For a Facebook Page, it also removes FastDM's access at Meta, unless the same Facebook user has connected another Page to FastDM. Only the trial record (account ID, dates, login ID, hashed email) is kept, as described above.
Remove FastDM from Instagram or Facebook
- Instagram: Settings and activity → Website permissions → Apps and websites → Active → FastDM → Remove.
- Facebook: Settings and privacy → Settings → Business integrations (for Pages) or Apps and websites → FastDM → Remove. Tick the option to delete past activity if it's offered.
When you remove FastDM, Meta notifies us and we delete the connected account's token at once. If you ask Meta to delete your data, we delete the connected account and everything listed above, and Meta shows you a confirmation code. You can check the status of a deletion at https://fastdm.net/webhooks/meta/data-deletion/status?code=YOUR_CODE.
Delete your whole FastDM account
Email support@fastdm.net from your account's address and ask us to delete it. Within 30 days we delete your sign-in, your connected accounts, your automations and your saved replies, and confirm by email. Only the hashed trial records described above are kept.
13. Children
FastDM is a business tool for people aged 18 or over. It isn't directed at children, and we don't knowingly collect data from anyone under 16. If you believe a child has given us personal data, contact us and we'll delete it.
14. Changes to this policy
We'll update this policy when FastDM or the law changes, and the date at the top shows the latest version. If a change is significant, we'll tell you by email or in the dashboard before it takes effect.
15. Contact us
For questions about privacy, data requests or this policy, contact Ahmed Aziz, the operator of FastDM, at support@fastdm.net.