Privacy Policy

Last Updated: February 5, 2026

1. Introduction

Infllook (“we”, “us”, or “our”) operates the website https://insight.shortchang.com and provides Instagram analytics and DM automation services (the “Service”).

This Privacy Policy explains how we collect, use, and protect your information when you use our Service.

2. Information We Collect

2.1 Instagram Data

When you connect your Instagram Business Account, we collect:

  • Profile Information: Username, profile picture, follower count
  • Media Information: Photos, videos, captions, timestamps
  • Insights Data: Reach, impressions, engagement, saves
  • Comments: Public comments on your posts (for DM automation)

2.2 Facebook Data

When you enable DM automation, we collect:

  • Page Information: Page name, Page ID, Instagram Business Account ID
  • Access Tokens: Long-lived tokens for API access (encrypted with AES-256-GCM)

2.3 Usage Data

We automatically collect:

  • IP address, browser type, device information
  • Login timestamps, feature usage

3. How We Use Your Information

3.1 Service Provision

  • Calculate VIS Score (Instagram analytics)
  • Display media insights and engagement metrics
  • Automate DM responses based on comment keywords

3.2 Service Improvement

  • Analyze usage patterns
  • Fix bugs and improve features

3.3 Communication

  • Send service notifications (e.g., DM sent successfully)
  • Respond to support requests

3.4 Data Visibility and Privacy

Your data is private:

  • Only you can see your Instagram insights and analytics
  • We do NOT share your data with other users
  • We do NOT display your metrics publicly
  • We do NOT create rankings or comparisons with other users

Who can access your data:

  • You (account owner only)
  • Infllook system (for analytics processing)
  • No one else

4. Data Sharing

4.1 Third-Party Services

We use the following third-party services:

  • Vercel: Hosting and deployment
  • Neon Database: Data storage (PostgreSQL)
  • Meta Platforms: Instagram Graph API, Messenger Platform

4.2 Legal Requirements

We may disclose your information if required by law or to:

  • Comply with legal obligations
  • Protect our rights and safety

5. Data Security

We implement industry-standard security measures:

  • Encryption: Access tokens encrypted with AES-256-GCM
  • HTTPS: All data transmitted over secure connections
  • Access Control: Role-based permissions

6. Data Retention

  • Instagram Data: Retained as long as your account is active
  • DM History: Retained for 90 days for analytics
  • Access Tokens: Deleted when you disconnect your account

7. Your Rights

You have the right to:

  • Access: View your data at any time
  • Export: Download your data in JSON format
  • Delete: Request deletion of your data (see Data Deletion Instructions)
  • Disconnect: Revoke access tokens via settings

8. Children's Privacy

Our Service is not intended for users under 13 years old. We do not knowingly collect data from children.

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes via email or in-app notifications.

10. Contact Us

If you have questions about this Privacy Policy:


Effective Date: February 5, 2026