語 Kotoba
PrivacyTermsLog in

Privacy Policy

Last updated 5 August 2026

Kotoba is a workspace for running an Instagram presence — an inbox, comments, publishing and analytics, with translation and drafting help built in. It is operated by DIGITALIS. This policy explains exactly what the product takes from your Instagram account, why, where it lives, and how to make it go away. Questions go to dudleyfire@gmail.com.

What we collect

When you create an account we store your email address, and, if you sign in with Google, the basic profile Google returns. If you use a password instead, we store only a one-way hash of it — never the password itself. We also store the name of your workspace.

When you connect Instagram, and only after Meta has asked your permission for each specific capability, Kotoba retrieves: your Instagram account ID and username; the direct messages in your inbox, including sender, text, timestamps and references to any attached media; comments on your posts along with the commenter's username; your posts' captions, permalinks, media type and publication times; and the insights Instagram exposes for your account and posts, such as follower counts, reach, likes, saves, shares and profile views.

Kotoba then derives further information from that material in order to be useful: the detected language of each message, scores for priority, junk, risk and hostile tone, and — when you ask for them — translations, drafted replies and tone checks. We also keep ordinary server logs, which include IP addresses and request times.

What we do not collect

We do not touch accounts you have not connected. We do not read anything through your Instagram connection beyond the permissions you granted. We do not store payment card numbers — when billing launches, card details go directly to our payment processor and never reach our servers. We do not buy information about you from data brokers, we do not build advertising profiles, and we do not sell your data to anyone, for any purpose.

Why we hold it

Messages and comments are stored so your inbox can be shown to you translated, sorted by what actually needs an answer, and searchable — none of which is possible without keeping the text. Post and insight history is stored because Instagram discards your insights after about 90 days and one of Kotoba's central purposes is remembering them for you. Media you upload for publishing is stored only until it is published, cancelled, or 24 hours have passed.

Artificial intelligence

When you ask Kotoba to translate a message, draft a reply, or check the tone of something you have written, the relevant text is sent to Anthropic's API to produce that result and returned to you. Under our agreement with Anthropic, that content is not used to train models. Nothing is sent to any AI provider unless an action of yours calls for it. If you would rather use your own model and your own API key, Kotoba supports that, in which case your content goes to the provider you have chosen under whatever terms you have with them.

Where it lives, and how it is protected

Your data is stored in a PostgreSQL database operated by Supabase, hosted in the United States. Every row carries the identity of the workspace that owns it, and database-level row security means one workspace physically cannot read another workspace's rows — the isolation is enforced by the database, not by application code that might one day forget.

Your Instagram access token is handled differently from everything else. It lives in a table with row-level security enabled and no read policies whatsoever, which means it cannot be read back through the API by anyone at all. Only sealed server-side functions can use it, and only to make the Instagram calls you have asked for.

Media staged for publishing is briefly readable by anyone who has its unguessable URL. This is not a design choice we are free to make: Instagram publishes by fetching your image or video from a public address. Those files are deleted the moment the post goes live, when you cancel, or automatically within 24 hours — whichever comes first.

Who else sees it

Three service providers process data on our behalf: Vercel, which hosts and serves the application; Supabase, which provides the database and file storage; and Anthropic, which provides the AI described above. Meta receives whatever you explicitly publish or send — replies, comments and posts — because that is the point of the product. Beyond those, we share nothing, except where we are legally required to, or where you ask us to.

Deleting your data

Disconnecting Instagram destroys the stored access token immediately; Kotoba can make no further calls on your behalf from that moment. Removing Kotoba from Instagram's own Apps and websites settings has the same effect, and Meta notifies us so we can act on it without waiting for you to tell us.

To have the data itself removed, use the data deletion request in Instagram's settings or email dudleyfire@gmail.com. Either route deletes the messages, comments, posts, insights, scores, translations and drafts associated with your Instagram account, along with the token. Requests made through Instagram return a reference code and a status page where you can confirm the deletion completed. Ordinary server logs are retained for up to 30 days and then rotate out.

Your rights

You may ask for a copy of your data, ask us to correct it, or ask us to delete it, and we will respond within 30 days. Depending on where you live you may have additional rights under laws such as the GDPR or the CCPA — including the right to object to processing and to complain to your local data protection authority. We honour those requests regardless of where you live, because maintaining two standards would be worse than maintaining one.

Children

Kotoba is not intended for anyone under 13, and not for anyone under 16 in regions where that is the applicable threshold. We do not knowingly collect their data; if we learn we have, we delete it.

Changes

If this policy changes we will update the date at the top of this page, and for any change that materially affects what we collect or who receives it, we will tell account holders by email before it takes effect.

語 Kotoba · © 2026 DIGITALIS
Privacy · Terms · Contact