Privacy Policy
Last updated: May 25, 2026
Truffle (“we”, “our”, “us”) helps small-business owners manage customer interactions across the platforms their customers reach them on, including Instagram. This policy explains what data we collect, how we use it, who we share it with, and how to remove it.
Information We Collect
When you sign up for and use Truffle we may collect:
- Your name, business name, business type, and location
- Email address and/or phone number
- Usage data — how you interact with the app and website
When you connect your Instagram account to Truffle via Meta’s Instagram Login API, we receive and store:
- Your Instagram-scoped user id (IGSID) and username
- A long-lived OAuth access token (used to send and receive messages on your behalf)
- The expiration timestamp of that token
As your customers send you Instagram Direct Messages, we receive (via Meta’s webhook) and store:
- The customer’s scoped IGSID, username, display name, and profile picture URL
- The text of each message they send you and each reply you send back
- Timestamps and Meta-issued message identifiers (used for deduplication)
How We Use Your Information
- To deliver the Truffle service — surfacing customer DMs, drafting reply suggestions with AI, and sending your approved replies via Meta’s Instagram Graph Send API
- To create and manage appointments your customers book through DMs
- To improve the service (error monitoring, performance tuning, AI prompt iteration)
- To communicate with you about product updates (you can opt out at any time)
We do not sell your personal information or your customers’ messages to third parties. We do not use customer DMs to train models that serve other businesses.
How We Share Your Information
- Meta — we exchange data with the Instagram Graph API and Webhooks to send and receive messages on your behalf. Your use of Meta APIs is subject to Meta’s terms.
- Service providers — cloud hosting (Google Cloud), AI inference (Google Gemini), and email delivery, only as needed to operate Truffle.
- Legal — when required by law or to protect our users and our rights.
Data Storage and Security
Your data is stored in Google Cloud (US region) using industry-standard encryption in transit and at rest. Access tokens are only readable by our server-side code; they are not exposed to the browser or to other tenants.
Your Rights and Controls
- Disconnect Instagram — Settings → Apps and websites on your Instagram account, find “Truffle”, and tap Remove. We receive Meta’s deauthorize callback and wipe your stored token and IGSID within seconds.
- Delete your account — Contact us at [email protected] or use the Delete Account action in the iOS app’s Settings. All your data (messages, threads, appointments, services, settings) is removed from our systems.
- Request a data export — Email [email protected] and we’ll send you a JSON export within 30 days.
- Meta-initiated deletion — Meta can request
deletion of your data through our callback URL
https://llm-server-biz.truffle.vip/webhooks/instagram/data-deletion. Our endpoint wipes your row and returns a confirmation code you can use to verify completion.
Cookies
The Truffle web app uses cookies for sign-in session management and Google Analytics for understanding how the site is used. You can control cookies through your browser settings.
Children
Truffle is not directed at children under 13. We do not knowingly collect personal information from anyone under 13.
Changes to This Policy
We may update this policy from time to time. Material changes will be reflected by updating the “Last updated” date and, where appropriate, by notifying you in the app or by email.
Contact Us
Questions or requests about your data? Email [email protected].