Skip to content

Last updated 1 September 2026

Privacy

This policy covers customer account data and creator data collected through connected Instagram accounts.

Your data as a customer

We collect the minimum needed to run an account:

  • Your email address, used for sign-in and account communication.
  • Your Instagram connection: the token Meta issues, account identifiers, profile details and token expiry.
  • Service records: jobs, webhook deliveries and API-token use needed to operate and protect the service.

We do not sell personal data, use advertising trackers in the application or add tracking pixels to transactional email.

Creator data

When someone tags or mentions your brand, Signal stores the post details Instagram makes available, including the creator, caption, preview and public engagement. When someone messages your connected account, Signal stores the conversation so your team can reply.

  • We use data available to the connected account. Signal does not scrape profiles, buy third-party creator data or enrich profiles from unrelated sources.
  • Story media expires. By default, Signal removes Story media after its 24-hour window while keeping the mention record.
  • Removed tags are reflected. Scheduled checks mark tagged posts when Instagram no longer returns the tag.
  • Usage-rights decisions keep their terms. Signal stores the terms shown with each approval or decline. The approval link does not independently verify the person opening it.
  • Retention follows workspace policy. Signal applies the retention settings available to your workspace and any required deletion request.
  • A creator can request deletion. Write to [email protected] so we can identify and remove the relevant records.

Where data lives, and who touches it

  • Customer data is stored with managed database and object storage services.
  • Service providers support hosting, storage and transactional email. Meta supplies the connected platform data.
  • Access is limited to people who operate Signal and to service providers acting under our instructions.

Meta data deletion

If you remove Signal through Meta or request deletion there, Meta sends a signed request. Signal processes the request for the relevant connection and provides a status URL. Disconnecting inside Signal removes data imported for that connection.

Your rights

You can export your workspace, ask us to correct personal data or request deletion. UK and EU residents may exercise applicable data-protection rights. Write to [email protected].

Cookies

Signal uses a session cookie for signed-in access. The marketing site stores the selected theme in your browser and does not use advertising analytics. Signal does not use a cookie banner because the public site sets no tracking cookies.

Children

Signal is intended for business users aged 18 or older. We do not knowingly offer accounts to children.

Changes

Material changes are announced by email and dated at the top of this page at least 30 days before they take effect.