Privacy Policy
Effective 2026-10-15
1. Who we are
IMMA AI is a social media API and dashboard product operated by PT Majapahit Teknologi Nusantara ("IMMA AI", "we", "us"). Contact for privacy questions: [email protected]. Our full company name and registered address are listed at the bottom of this page.
For your own social account data, we act as a data processor: we process it only on your instructions, as your workspace's owner. For Meta's platforms we are a Tech Provider under the Meta Platform Terms, meaning data is processed solely for the customer that connected the account, never mixed across customers. For account data you give us directly to run IMMA AI itself (email, name, billing), we act as a data controller.
2. Data we collect, by source
We collect data from three sources: what you type into IMMA AI directly, what Meta's APIs return for accounts you connect, and what TikTok's APIs return for accounts you connect.
- Direct input: your email, name, session data, captions and media you upload, and support messages.
- Meta (Facebook, Instagram, Threads), via official API: Page or professional account name, profile picture, IDs, posts and Reels you publish through us, comments on those posts, and performance metrics (reach, views, likes). We only read what is needed to show your own account overview, publish what you compose, and reply to comments in the inbox.
- TikTok, via official API: profile name and picture, videos published through us, and the consent choice, timestamp, IP address and user agent captured when you approve a TikTok Direct Post (kept as compliance evidence).
On our marketing website (getimma.com) we use Plausible Analytics, a cookie-free analytics tool that stores no persistent identifiers and processes data on EU-based infrastructure, so no cookie consent banner is required for it.
The table below lists every category we process, what it is used for, and how long we keep it.
| Category | Examples | Purpose | Retention |
|---|---|---|---|
| IMMA AI account | email, name, session | Authentication, communication | While the account is active, plus 30 days |
| Platform tokens | access and refresh tokens | Publishing on your instruction | Deleted when you disconnect the account |
| Connected account profile | username, avatar, platform ID | Showing the connected accounts in your dashboard | While the account stays connected |
| Content | captions, media | Publishing to Meta and TikTok | Media deleted 90 days after it is published |
| Metrics | views, likes, followers | Analytics | While connected, plus 30 days |
| Comments | comment text, commenter name or handle | Unified inbox and replies | While connected, plus 30 days |
| Consent evidence | choice, timestamp, IP, user agent | TikTok Direct Post compliance | 1 year |
| Payment | transaction ID (no card numbers) | Billing | As required by tax law |
3. What we never do
We never sell Platform Data (data obtained from Meta or TikTok APIs), never build advertising or behavioral profiles from it, never use it to train AI models, and never share it with other customers. We process it only to run the features you use and on your instruction, per Meta Platform Terms 3.a and 5.b.
4. Sharing data
We share data only with the subprocessors listed on /legal/subprocessors, each bound by a written data processing agreement, and when required by law. We do not sell data to anyone.
5. International transfers
Some subprocessors (for example Cloudflare) process data outside Indonesia. We require contractual safeguards from every subprocessor before data leaves Indonesia, consistent with UU PDP requirements for cross-border transfer.
6. Retention
Retention periods are listed in the table in section 2. When you disconnect an account or delete your workspace, we schedule deletion of the related data as described in section 8.
7. Your rights
Under Indonesia's Law No. 27 of 2022 on Personal Data Protection (UU PDP), you have the right to access, correct, delete your data, and to withdraw consent at any time. To exercise any of these rights, email [email protected] or use the in-app disconnect and delete-workspace controls. We act on these requests within 3x24 hours of receiving them.
8. Deleting your Meta and TikTok data
There are three ways to have your data deleted:
- Disconnect in the dashboard: revokes the platform token where the platform supports it, deletes the stored token, and schedules metrics and comments for deletion within 30 days.
- Meta's Data Deletion Callback: if you remove IMMA AI from your Meta account, Meta notifies us automatically and we delete all data tied to that user ID. You can check the status of that request on the confirmation page at /legal/data-deletion.
- Email us: write to [email protected] and we will delete the data manually.
Full details of each path are on the Data Deletion page.
9. Security
We encrypt platform tokens at rest with AES-256-GCM, encrypt data in transit with TLS, hash API keys, keep audit logs, restrict production access behind SSO and MFA, encrypt backups, and maintain an incident response plan that notifies affected users as required by UU PDP.
10. Changes to this policy
We will post material changes to this page and update the effective date above. Continued use of IMMA AI after a change takes effect means you accept the updated policy.
11. Contact
Questions about this policy: [email protected]. Both the English and Indonesian versions of this policy are equally valid.