ShadowDM
Legal & Compliance

Privacy Policy

Last Updated: June 26, 2026  ·  Effective immediately upon use of the Service

01

Introduction

Welcome to ShadowDM. ShadowDM is a Google Chrome browser extension that helps business owners reply to their Instagram Direct Messages faster by generating AI-drafted reply suggestions. This Privacy Policy explains what information the extension and its supporting backend collect, why, and how you can delete it (together, the "Service").

The extension runs entirely inside your own logged-in Instagram session in your browser. It does not use the Meta Graph API, does not ask you to log in to Instagram or Facebook through us, and we never have server-side access to your Instagram account. We cannot see your account unless you are using it yourself in your own browser.

02

How the Extension Works

ShadowDM only activates on instagram.com while you are signed in. When you click the "Draft" button (or enable opt-in auto-drafting), the extension reads only the visible text of the DM thread you currently have open and sends that text to our own backend, which uses Google's Gemini AI to generate a suggested reply.

The draft is shown to you inside the extension. You review, edit, and send it yourself. Nothing is ever sent automatically on your behalf — ShadowDM never sends a message for you.

03

Data We Collect

We collect only what is needed to provide the drafting feature:

Account & auth token Open DM thread text Voice / tone settings Business knowledge text

Account & authentication token — a Firebase account identifier and login token that signs you in to the Service.
Open DM thread text — the visible conversation text from the single Instagram DM thread you have open, sent only when you request a draft, so the AI can write a relevant reply.
Voice / tone settings — optional preferences you set for how drafts should sound.
Business knowledge text — optional content you choose to enter (e.g. your menu, FAQ, hours, or procedures) so drafts can answer customer questions accurately.

We do not collect your Instagram password, payment details, browsing history on other sites, or any data from pages other than the Instagram DM thread you are actively drafting a reply to.

04

How We Use Your Data

Your data is used for a single purpose: to provide the AI draft-reply feature (app functionality). The open-thread text and your business-knowledge content are sent to our backend and to the Google Gemini API to generate a draft reply for you to review.

We do not use your data for advertising, we do not build user profiles, and we do not perform cross-site tracking. The only third party that receives conversation text is Google, solely to produce the AI draft.

🔒 WE DO NOT SELL YOUR DATA. EVER.
05

Where Your Data Is Stored

On your device — the extension stores your Firebase auth token and your settings locally in your browser (chrome.storage). This stays on your machine and is removed when you uninstall the extension or clear its storage.

On our servers — your account record, your optional voice settings, and your optional business-knowledge text are stored in Firebase / Firestore so your preferences persist across sessions. DM thread text is processed to generate a draft and is not retained for our own purposes after the draft is returned; it is transmitted over the Google Gemini API subject to Google's terms. All data in transit is encrypted via TLS 1.2+.

06

Your Rights & Data Deletion

You can stop all local data collection at any time by uninstalling the extension, which removes everything stored in your browser. To delete the account, voice settings, and business-knowledge text stored on our servers, follow our Data Deletion Instructions or email us. You also have the right to request access to or correction of your personal data.

07

Contact Us

Questions or concerns about this Privacy Policy? Reach us at: help@shadowdm.cloud