Security

Your account staysyours. Always.

Mtschat is built on Instagram’s official Messaging API. We never ask for your password, never log in as you, and only reply to people who started the conversation.

Instagram access

Compliant by design, not by luck

Unofficial automation tools log in with your password and imitate a person. That is how accounts get restricted. Mtschat works differently.

The official Instagram Messaging API

Every message Mtschat sends goes through Meta’s Instagram API with Instagram or Facebook Login. No browser automation, no scraping, no workarounds that break Instagram’s terms.

No passwords — ever

You connect Instagram through Meta’s own login screen. Mtschat receives an access token with the permissions you approve, never your password, and never logs in as you.

Only people who reached out first

Mtschat replies to comments, story replies and DMs — people who initiated contact with you. It does not cold-message strangers or buy lists.

The 24-hour window, enforced

Instagram lets businesses message someone for 24 hours after their last message. Sequences and broadcasts respect that window automatically, so you can’t accidentally break the rules. How the window works.

Clear permissions, revocable any time

Meta shows exactly which permissions Mtschat requests before you approve them. You can disconnect from Mtschat’s settings or remove access in your Instagram or Meta account settings — the token stops working immediately.

Data protection

How we look after your data

The practices we follow across the product. We describe what we do, not badges we don’t hold.

Encryption in transit and at rest

Traffic between your browser, Mtschat and Meta travels over TLS. Stored data, including access tokens, is encrypted at rest.

Role-based access

In the Team Inbox, role-based permissions decide what each teammate can see and do — so a support agent can answer DMs without touching your automations.

Signed webhooks

Every webhook carries an HMAC-SHA256 signature so your systems can confirm a request came from Mtschat. API keys can be revoked at any time. Developer details.

Data deletion

Delete individual contacts, or close your workspace and have its data removed. Requests can also be sent to privacy@mtschat.com.

Your data, portable

Export contacts as CSV whenever you like. Cancel any time without losing your data.

Least data needed

We collect what an automation needs to run — handles, messages, tags and the fields you choose to capture — and use it only to provide the service. See our privacy policy.

Responsible disclosure

Found a vulnerability?

We welcome reports from security researchers. Email security@mtschat.com with a description of the issue, steps to reproduce and any proof of concept.

  • Give us reasonable time to investigate and fix the issue before disclosing it publicly.
  • Only test against accounts you own; don’t access, change or delete other people’s data.
  • Avoid anything that degrades the service for others, such as denial-of-service testing or spam.
  • We will acknowledge your report, keep you updated and let you know when it is resolved.

Automate your DMs without risking your account

Official API, no passwords, every feature on every plan. Start free with 100 active contacts.