Privacy Policy
1. Who is responsible
Jose Rodriguez AI, 482 W. San Ysidro Blvd #2139, San Ysidro, CA 92173 (“we”, “us”), operates DM to Close (the “Service”). For account holders’ own information (for example your login and billing details) we are the controller. For information about an account holder’s leads and customers, the account holder (the business using the Service) is the controller and we process that information on their behalf and on their instructions.
2. Information we process
Account and team information: name, email address, business name, role, hashed password (we never store plain-text passwords), whether two-step verification is on (the secret is stored encrypted), recovery codes (stored only as hashes), sign-in history, active sessions and devices (stored as a hash), and invitations.
Billing information: plan, subscription status, renewal dates and Stripe customer and subscription identifiers. Payment card details are collected and stored by Stripe, not by us.
Instagram information (official connection): when an account holder connects Instagram through Instagram’s official login, we receive from Meta the account’s Instagram ID and username, an access token (stored encrypted), and, through Meta’s webhooks, direct messages and comments sent to or from that account, including the sender’s Instagram-scoped ID, username and display name when Meta provides them, message text, timestamps, and the post or Reel a comment was made on (link, caption and type). We use this information only to provide the Service to that account holder.
Facebook Page information (official connection): when an account holder connects a Facebook Page through Facebook Login, we receive from Meta the Page’s ID and name and a Page access token (stored encrypted), and, through Meta’s webhooks, Messenger messages sent to or from that Page and comments on the Page’s posts, including the sender’s Page-scoped ID and the name and profile picture Facebook provides, message text, timestamps and a link to the post. We do not connect to personal Facebook profiles or personal Messenger accounts.
Lead information supplied by the account holder or their connected AI agents: Instagram username and ID, name and profile-image link when available, message and comment content and timestamps, which post, Reel, ad or keyword a conversation came from (only when actually provided, never guessed), goals, barriers, objections and other notes, lead scores, pipeline stage, follow-ups, sequences, and purchase-link and purchase-confirmation records.
AI agent and browser-agent information: labels and permissions of API keys (keys are stored only as hashes), when they were used, actions they took, and pacing and status reports from browser agents. We never collect Instagram passwords.
Sign-ups started by an AI agent: if an AI agent asks us to start a sign-up for you, we store the business name, email, name and plan it sent, the agent’s name, and the request’s IP address, and we email you a link. If you don’t finish within 48 hours, the request expires and is deleted within 30 days. A key for the agent is created only if you choose to give it access; we hold an encrypted copy only until the agent collects it once.
Technical information: IP address, browser user agent, security and audit logs, and one essential session cookie used to keep you signed in. We do not use advertising or analytics cookies.
3. How we use information
- To provide the CRM: receive and store conversations, show lead profiles, pipelines, follow-ups and reports, and send replies the account holder or their authorized agents choose to send;
- To keep the Service secure: authentication, two-step verification, sign-in alerts, rate limiting, fraud and abuse prevention, and audit logging;
- To enforce safety rules, such as blocking outreach to people who asked not to be contacted, allowing only approved links, and pausing AI when a person takes over;
- To manage accounts, trials and subscriptions, and to send service emails (email confirmation, password resets, invitations, security alerts, billing notices); and
- To comply with legal obligations.
We do not sell or “share” personal information for cross-context behavioral advertising, we do not use it for advertising, and we do not use Customer Data or Instagram data to train AI models.
4. AI processing
Account holders may connect AI agents of their choice (such as Meta’s Muse, ChatGPT, Claude, Gemini, automation tools, or their own software). When they do, those agents read and send information through the Service’s API as the account holder directs, and process it under their providers’ own terms and privacy policies. The Service stores the results so the account holder can review them. AI output can be wrong; account holders review and are responsible for decisions and messages based on it.
5. Who we share information with
- Service providers that help us run the Service, under contract: Cloudflare, Inc. (hosting, database, network security), Stripe, Inc. (payments and subscriptions), and Resend (transactional email);
- Meta (Instagram and Facebook), when an account holder uses an official connection, to receive messages and to send the replies they choose to send;
- AI agents and tools the account holder connects, only as the account holder directs;
- Team members of the same workspace, according to their role. Workspaces are kept separate; one customer cannot see another customer’s data;
- Authorities or others when required by law or to protect rights, safety and security; and a successor in a merger or acquisition, subject to this policy.
6. International transfers
Our providers may process information in countries other than where you live, including the United States. We rely on the safeguards those providers offer and applicable legal mechanisms for such transfers.
7. Retention
We keep account and lead information while the workspace is active. When an account holder deletes a lead, that lead’s messages, notes and history are deleted. When an account holder disconnects Instagram, we delete the stored access token immediately. When a workspace is closed, we delete its information within 30 days, except for billing records, security logs and records we must keep by law, which are kept for up to 12 months or as legally required. Expired sign-in tokens, sessions and pacing records are deleted automatically.
8. Security
We use encryption in transit (HTTPS) and at rest, AES-GCM encryption for Instagram and Facebook Page access tokens and two-step verification secrets, salted password hashing, optional two-step verification with recovery codes, sign-in alerts, HttpOnly secure session cookies, CSRF protection, hashed API keys with per-key permissions, per-workspace isolation, signature verification of Meta and Stripe webhooks, access controls, rate limiting and audit logs. No system is perfectly secure; we will notify affected users of a security incident as required by law.
9. Your rights
Depending on where you live, you may have the right to know, access, correct, delete, or object to the use of your personal information (in California under the CCPA/CPRA; in Mexico, your “ARCO” rights), to limit its use or disclosure, to withdraw consent, and not to be discriminated against for exercising these rights. If you messaged or commented to a business that uses this Service, please contact that business first; they control your information and can update or delete it. You may also contact us at jrodrevolution@gmail.com and we will forward or assist with your request. We respond within the time required by law.
10. Data deletion instructions (Instagram and Facebook)
To remove the Service’s access to your Instagram account or Facebook Page and delete related data: (1) in the Service, open Channels and click Disconnect — the access token is deleted immediately; (2) in Instagram, go to Settings → Apps and websites (or Website permissions) and remove DM to Close; on Facebook, go to Settings & privacy → Settings → Business integrations (or Apps and websites) and remove DM to Close; (3) to delete the conversations and leads stored for your workspace, delete them in the Service or email jrodrevolution@gmail.com from your account email with the subject “Data deletion request”, and we will delete them within 30 days and confirm by email. If you are a person who messaged a business that uses the Service, contact that business or email us and we will help.
11. Do-not-contact requests
If you tell a business using the Service that you don’t want to be messaged, the Service is designed to mark you as “do not contact” and block further messages from that business’s team and AI agents through the Service.
12. Children
The Service is not directed to anyone under 18, and account holders must not knowingly use it to market to minors.
13. Changes
We may update this policy and will post the new version here with a new effective date. Material changes will be communicated to account holders in advance.
14. Contact
Privacy questions or requests: jrodrevolution@gmail.com · 482 W. San Ysidro Blvd #2139, San Ysidro, CA 92173