Last updated: July 27, 2026

Privacy Policy

heyy.to is an Instagram DM automation tool for creators. This page explains every category of data we touch, why we touch it, how long we keep it, and the rights you retain. Questions or requests: hello@heyghe.com.

1. Who we are

heyy.to is operated by Pranav Bhatkar, an independent creator-developer based in Amravati, Maharashtra, India. heyy.to is not (yet) incorporated as a company; it is an early-stage, independent tool. There is no team, no investors, and no external operators. All contact is via hello@heyghe.com.

2. What we collect, and why

The table below lists every category of data heyy.to stores, where it comes from, why we need it, and how long we keep it. If a category isn't here, we don't collect it.

DataSourceWhyRetention
Account info: email, name, role, localeBetter Auth sign-in + invite acceptanceIdentify the creator behind the dashboardUntil account deletion
Instagram access tokenMeta OAuth on Connect IGCall Meta APIs on your behalf to send DMs, reply to comments, fetch media metadataEncrypted in Cloudflare KV (AES-GCM-256); deleted immediately on disconnect
IG account metadata: handle, IG user ID, business account ID, profile picture URL, subscribed webhook fieldsMeta Graph API on connectDisplay your connected account in the dashboard; route webhooks to the right automationRefreshed each connect; deleted on disconnect or account deletion
Comment events: comment text, comment ID, media ID, commenter IG user ID + handle, timestampMeta webhooks for posts/reels you subscribed toMatch your keywords and decide whether to trigger an automation; show you the matched-comments history90 days, then deleted
DM events: recipient IGSID, message payload snapshot, delivery status, response index, error codeheyy.to's send pipelineTrack DM delivery, retry safely, surface failures in your dashboard90 days, then deleted
Contacts: IGSID, display name + profile picture URL (if Meta returns them), counters, first/last triggered timestampsMeta Graph API, lazily enriched on activityPopulate the Contacts page so you know who heyy.to DM'd on your behalf365 days from last activity, or until you delete
Lead submissions: the form fields a viewer fills in response to a Lead Form DMSubmitted by your audience inside Instagram DMHand the leads back to you (CSV export, dashboard view)Until you delete the parent automation, or your account is deleted
Audit log entries: sensitive action, IP, user-agentServer-side, generated by heyy.toInvestigate security incidents (login from new device, IG connect/disconnect, invite use)90 days
Marketing analytics: page views, named events, hashed IP, country, device classGoogle Analytics 4 + PostHog on heyy.toUnderstand which pages bring real creators (no advertising retargeting)GA4: 14 months (default). PostHog: 7 years (provider default; we'll delete on request)
Dashboard product analytics + session recordings: clicks and navigation (autocapture), plus masked session replays where every input and all text is masked before it leaves your browserPostHog on the authenticated dashboard (app.heyy.to)Understand how creators use the dashboard and reproduce bugs (no advertising, no third-party sharing)PostHog: 7 years (provider default; we'll delete on request)
Billing records: plan, subscription status + billing period, Razorpay subscription/payment references, and GST tax invoices (invoice number, amounts, tax split, place-of-supply state). No card, UPI, or bank details.Razorpay checkout + heyy.to's billing pipelineRun your Pro subscription and issue GST-compliant invoicesRetained for tax + accounting records as required by law; otherwise until account deletion

Note: Marketing analytics on heyy.to use anonymized IP collection (GA4 anonymize_ip: true) and run no PostHog session replay. The authenticated dashboard (app.heyy.to) does record masked PostHog session replays, with every input and all text masked - see §8.

3. What we do NOT collect

4. Where your data lives

heyy.to runs entirely on Cloudflare. Your data resides in:

The marketing site (heyy.to), dashboard (app.heyy.to), and API (api.heyy.to) are all served from Cloudflare's edge. Cloudflare's data processing terms apply to the underlying infrastructure.

5. Who we share data with

We do not sell your data. We never share it for advertising or marketing purposes. The only third parties that ever see any of your data are infrastructure processors strictly necessary to run heyy.to:

We do not transfer data to any processor outside this list. We do not engage data brokers, ad networks, or affiliate partners.

6. How we secure your data

heyy.to is not (yet) SOC 2, ISO 27001, or HIPAA certified. We do not make compliance claims we can't back up. The full security model is documented internally and reviewed on every change.

7. Your rights and how to use them

Under India's Digital Personal Data Protection Act, 2023 and (for EU/UK users) the GDPR / UK GDPR, you have the right to access, correct, export, and delete your personal data. heyy.to honors these rights regardless of your jurisdiction.

If you believe heyy.to has mishandled your data, you can lodge a complaint with India's Data Protection Board (once constituted under DPDP-2023) or, for EU users, your local supervisory authority. We'd appreciate you emailing us first so we can fix it.

8. Cookies and analytics

The marketing site (heyy.to) uses two analytics tools and a minimal set of first-party cookies:

Both GA4 and PostHog respect the browser Do Not Track header. If your browser sets navigator.doNotTrack === "1", neither tool fires.

We do not use third-party advertising cookies. We do not load Facebook Pixel, LinkedIn Insight, or any other ad-network tracker.

9. Children

heyy.to is not intended for users under the age of 18, in line with Meta Platform Terms for the Instagram Graph API. We do not knowingly collect data from anyone under 18. If you believe a minor has signed up, email hello@heyghe.com and we will delete the account.

10. International data transfers

heyy.to is operated from India. Your data is processed on Cloudflare's global edge network and stored primarily in their Asia-Pacific D1 region. Cloudflare may route requests through other regions for performance and reliability, covered by their data processing addendum.

For EU/UK users: where processors (Cloudflare, Resend, Google, PostHog, Sentry, Razorpay) are based outside the EEA, they operate under either Standard Contractual Clauses or their own GDPR-compliant transfer mechanisms.

11. Changes to this policy

We will update the "Last updated" date at the top of this page whenever the policy changes. For material changes (new categories of data, new processors, changes to retention) we will email every active beta user at least 14 days before the change takes effect.

12. Contact

Questions, concerns, or data requests: hello@heyghe.com. We aim to respond within 7 days; for urgent security or deletion requests, please write "urgent" in the subject line.