Legal
Privacy Policy
Last updated: August 6, 2026
This Privacy Policy explains how the BotLah operator handles information when you use the BotLah Discord bot or visit this website. BotLah uses information only to connect Instagram accounts, deliver Discord announcements, maintain reliability, protect the service, and respond to support or legal requests.
1. Information BotLah handles
Depending on how your server uses BotLah, the service may process:
- Discord configuration: server, destination channel or thread, administrator user, and BotLah announcement message identifiers.
- Instagram connection information: the connected account identifier, username, authorization token, token expiry, and authorization status. Access tokens are encrypted at rest.
- Instagram media information: media identifiers, usernames, captions, media types, timestamps, post links, preview links, and carousel item details needed to prepare announcements.
- Operational information: delivery status, retry counts, timestamps, and limited error details needed to diagnose failures and avoid duplicate announcements.
- Temporary authorization information: a random, hashed, single-use connection state tied to the Discord server and administrator. It normally expires after 10 minutes.
2. Information BotLah does not need
BotLah requests only Instagram's instagram_business_basic permission. It does not ask for your
Instagram password or store copies of image or video files; it stores the media metadata and links described
above. The bot does not monitor ordinary Discord conversations. After an interrupted send, it may temporarily
inspect up to the latest 100 messages in the configured destination to find an announcement previously sent
by BotLah and prevent a duplicate; it does not store other users' message content from that check.
3. How information is used
Information is used to:
- authenticate the connected Instagram account and refresh its authorization;
- remember each Discord server's account and announcement destination;
- find eligible Instagram updates and format Discord announcements;
- deliver, retry, reconcile, and deduplicate announcements;
- show connection status and useful errors to server administrators; and
- secure, maintain, troubleshoot, and comply with legal obligations affecting the service.
BotLah does not sell personal information or use it for advertising.
4. When information is shared
BotLah sends information to Discord to respond to commands and publish announcements, and to Meta/Instagram to authorize accounts and retrieve connected-account media. The service is hosted using infrastructure providers that may process encrypted data, network metadata, backups, or service logs on the operator's behalf. Information may also be disclosed when required by law, to protect users or the service, or as part of a service transfer subject to appropriate safeguards. BotLah does not give connected Instagram access tokens to other Discord servers or users.
5. Website privacy
This website is static and does not include BotLah-operated analytics, advertising trackers, account registration, forms, or cookies. Cloudflare hosts the website and may process standard request information, such as IP address, browser details, and security events, under its own privacy terms.
6. Retention
- Server configuration and encrypted Instagram authorization remain while the connection is active.
- Expired or used authorization states are cleared automatically.
- Sent and permanently blocked delivery records are normally removed after 30 days.
- Pending or retrying delivery records remain until delivered, blocked, the destination is disabled, or the server disconnects.
- Operational logs and provider backups may remain for a limited period for security, recovery, and troubleshooting.
Information may be retained longer where reasonably required for security, dispute resolution, or legal compliance.
7. Deletion and choices
A server administrator can run /instagram disconnect to delete that server's binding and
delivery records. If no other Discord server uses the same Instagram account, its stored account record and
encrypted token are also removed. Removing BotLah from a Discord server triggers the same server-side
disconnection. Previously posted Discord announcements remain in Discord and can be deleted by a server
administrator using Discord's tools.
For access or deletion questions that cannot be handled with the command, contact the BotLah operator through the Discord community or administrator who provided access. Provide the relevant Discord server ID and do not send passwords or access tokens.
8. Security
BotLah uses measures designed to protect stored information, including encrypted Instagram access tokens, short-lived single-use authorization states, limited Discord permissions, and restricted service storage. No system is completely secure, so absolute security cannot be guaranteed. If you believe a connected account is at risk, revoke the application's Instagram access and disconnect BotLah promptly.
9. International processing
Discord, Meta, Cloudflare, and infrastructure providers may process information in countries other than your own. Their handling of information is governed by their respective policies and safeguards.
10. Children
BotLah is intended for people who are permitted to administer a Discord server and connect a professional Instagram account. It is not directed to children below the minimum age required by Discord or Instagram.
11. Changes and contact
This policy may be updated as BotLah changes. The revision date above shows when it was last updated. Questions or privacy requests can be directed to the BotLah operator through the Discord community or administrator who provided access to the bot.