Privacy policy
Last updated July 11, 2026
Who we are
Nimbus ("we", "us") provides automation for Instagram and WhatsApp messaging. This policy explains what data we collect, why, how long we keep it, and how you can get it or delete it. Questions go to support@nimbus.app.
Data you give us directly
- Account data: your name, email address and password (stored hashed).
- Content you create: automation names, trigger keywords, message templates and any media you upload for use in replies.
Data we receive from Meta
When you connect an Instagram account or WhatsApp Business number, you authorize Nimbus through Meta's official login flows. We then receive, via Meta's APIs and webhooks, only what is needed to run the automations you configure:
- Instagram: your professional account's id, username and profile picture; comments on your posts; messages sent to your account; whether a commenter follows you (when you enable a follow-gated automation).
- WhatsApp: your WhatsApp Business Account id and phone numbers; messages sent to your business number; delivery status of messages we send for you; message template approval status.
- Access tokens that let us act on your behalf. Tokens are encrypted at rest (AES-256-GCM) and never shown to anyone, including you.
We use this data only to run your automations, show you your own contacts and analytics, and meet Meta's platform requirements. We do not sell it, share it with advertisers, or use it to train machine-learning models.
Contacts created by your automations
People who comment on your posts or message your accounts become contacts in your workspace, with their platform id, username or phone number, and any email address they choose to share in a conversation. This data belongs to your workspace and is only used to deliver your automations and analytics.
How long we keep data
Message and analytics history is retained according to your plan (30 to 365 days), then deleted. Account data is kept while your account exists. Encrypted access tokens are deleted when you disconnect the channel or delete your account.
Deleting your data
- In the app: Settings → Delete account removes your account and all stored data, including contacts and message history.
- From Meta's side: removing Nimbus in your Instagram or Facebook settings pauses your automations, and Meta's data deletion callback tells us to purge the connected account's data. We honor both automatically.
- Step-by-step instructions live on our data deletion page.
You can also export everything we hold about your workspace from Settings → Export data.
Where data lives and who sees it
Data is stored on our own servers. We do not use third-party analytics or advertising trackers on this site or in the app. Data is shared with Meta Platforms only as required to operate the integrations you connect, under Meta's Platform Terms.
Changes
If this policy changes materially, we'll email account holders before the change takes effect and update the date at the top of this page.