Privacy
What justask reads from your connected accounts, what it stores, who else sees it, and how to make it stop.
Last updated 7 September 2026
justask connects to a social account you own and answers the comments and messages that arrive on it. To do that it has to read those comments and messages. This page says exactly what that means in practice.
The short version. justask reads public comments on your own posts and direct messages sent to your account. It stores them so you can see and answer them. It sends the text of a message to a language model provider to classify it and draft replies. It never posts anything you did not choose to send, and it never sells or shares your data with advertisers or data brokers.
1. Who is responsible
justask is operated by Dots Studio. For anything on this page, including a request to delete your data, write to edo@dotsstudio.io.
If you connect an account on behalf of a business, that business is the controller of the messages its customers send it, and justask processes them on the business's instructions.
2. What justask reads, and why
When you connect an Instagram or Facebook account, you grant a specific set of permissions. justask requests only these:
| Permission | What it is used for |
|---|---|
| instagram_business_basic | Your username, profile picture, and the list of your own posts, so a comment can be shown next to the post it was left on. |
| instagram_business_manage_comments | Reading comments on your posts, and posting a reply when you choose to send one. |
| instagram_business_manage_messages | Reading direct messages sent to your account, and sending a reply. |
justask does not request permission to publish posts, read your followers, read anyone else's account, or access advertising data.
3. What is stored
| Data | Why it is kept |
|---|---|
| Account details | Your handle, display name, avatar URL and account id, so the app knows which account it is acting for. |
| Your posts | Caption, thumbnail, permalink, like and comment counts. A reply is impossible to judge without the post it answers. |
| Comments and messages | The text, the author's display name and platform id, and the timestamp. This is the inbox. |
| Drafts and sent replies | What was suggested, what was chosen, who sent it and when. This is the audit trail, and it is what makes an automated reply accountable. |
| Access tokens | Encrypted with AES-256-GCM before they touch disk, bound to the workspace and account they belong to. Every read of a token is logged. |
| Your brand settings | The tone, rules and reference material you give the agent, so replies sound like you. |
justask does not store your Instagram or Facebook password. It never sees one. Authentication happens on Meta's own domain and returns a token.
4. Who else sees the data
The language model provider
To classify a message and draft a reply, justask sends the text of that message, the thread it belongs to, the caption of the related post, and your brand settings to a language model provider. Today that provider is Groq. The provider processes the text to return a result and, under its own terms, does not use it to train models.
What is not sent: your access tokens, your email address, and any data from an account other than the one the message arrived on.
Meta
justask calls Meta's Instagram and Facebook APIs to read comments and messages and to post replies you send. Meta's handling of that data is governed by Meta's own terms.
Nobody else
justask does not sell personal data, does not share it with advertisers or data brokers, and does not use the contents of your inbox to train any model.
5. Automated replies are disclosed
When the agent sends a reply on its own, that reply carries a line saying it was sent automatically. This is on by default. You can turn it off in the app, and if you do, the responsibility for that choice is yours: Meta's platform terms require automated messages to be identifiable as automated.
6. How long it is kept
- While your account is connected. Messages and replies are kept so the inbox has history and the audit trail stays complete.
- When you disconnect an account. The stored token is destroyed immediately.
- When you ask for deletion. Everything belonging to that account is deleted within 30 days.
- If you stop using justask. Data for an account with no activity for 12 months is deleted.
7. Deleting your data
To disconnect: open Connections in justask and remove the account. The token is destroyed at once and no further data is read.
To delete everything: email edo@dotsstudio.io from the address on your account, or from the account you connected. Deletion is completed within 30 days and confirmed by reply.
To revoke access at Meta instead: Instagram, Settings, then Apps and websites, and remove justask. That stops all access immediately, whatever justask does.
8. Where the data lives
Data is stored on servers operated by justask's hosting provider. Where you are in a jurisdiction whose law restricts transfer, tell us and we will say plainly whether we can serve you rather than bury the answer in a clause.
9. Security
- Access tokens are encrypted at rest with AES-256-GCM, bound to the workspace, brand, platform and account they belong to, so a token lifted from one row cannot be replayed against another.
- Every read of a stored token is recorded.
- Sign-in uses Google, so justask holds no passwords.
- Session cookies are HttpOnly, Secure and SameSite, and a session is re-issued rather than extended indefinitely.
- Text arriving from the public is treated as data, never as instructions to the agent, and a message that tries to instruct the agent is refused an automatic reply and flagged for a person.
10. Children
justask is a tool for businesses and is not directed at anyone under 18. It does not knowingly store data from a child. If a child's data has reached us through a comment or message, write to us and it will be removed.
11. Changes
If this policy changes in a way that affects what is collected or who sees it, connected accounts are notified before the change takes effect. The date at the top always reflects the current version.
12. Contact
Dots Studio, edo@dotsstudio.io. Questions about this policy, requests for a copy of your data, and deletion requests all go to the same address and are answered by a person.