James AI — Privacy Policy

Last updated: 17 July 2026

1. Who we are

James AI is an openly-disclosed AI persona operated on a single Instagram account, @james.manly1998, by an individual creator based in Australia ("we", "us"). We are the data controller for the limited data described below. You can contact us at any time at hong.qop1225@gmail.com.

2. Scope

This policy explains what data our software processes when it automatically replies to, and moderates, comments left on our OWN Instagram posts. Our software manages only our own account. It does not access, read, or post to any other person's Instagram account.

3. What data we process

When you comment on one of our posts, we process, via the Instagram API (Instagram API with Instagram Login, graph.instagram.com):

We also process our own account's profile and media (our username, our media IDs, captions, and timestamps) to know which of our own posts to monitor. We do NOT collect your email, phone number, password, private messages, location, or any special-category data, and we never place your data in URLs.

4. How we collect it

Data is received from Instagram through comment webhooks and API reads when you comment on our posts. We do not scrape, buy, or combine your data with data from other sources.

5. Why we use it (purpose)

We use this data only to:

We do not use your data for advertising, profiling, resale, or training third-party models. Replies are rate-limited and safety-filtered; we never auto-like and never send direct messages.

6. Legal basis

Where the GDPR or similar laws apply, we rely on our legitimate interest in engaging with and moderating our own audience on our own posts, balanced against your rights, and on consent where local law requires it. Your comment is already public on Instagram under Instagram's own terms.

7. Who we share it with

We do not sell your data. We use a small number of processors strictly to run this function:

Each processes data only on our instructions. We may also disclose data if required by law.

8. Retention

We keep comment metadata and moderation logs only as long as needed to operate and audit the reply/moderation feature. Stored comment records are automatically deleted after 90 days. You can request earlier deletion at any time (Section 10).

9. Security

Data is stored in access-controlled cloud services over encrypted connections (HTTPS/TLS). Access tokens are stored as server-side secrets and are not exposed to end users.

10. Your rights and how to delete your data

You can ask us to access, correct, or delete the data we hold about you. To delete it, email hong.qop1225@gmail.com from any address with your Instagram @username, or see our Data Deletion Instructions. We will delete all stored records associated with your username within 30 days. Deleting your comment on Instagram removes the public comment there; contact us as described above to ensure the separate safety/audit record is deleted early. Depending on where you live, you may also have the right to object to processing or to complain to your local data-protection authority (in Australia, the OAIC).

11. Children

Our account and this software are not directed to children. Automated checks prevent public engagement when a commenter identifies as a minor; limited safety/audit metadata may still be retained so the system does not repeatedly engage that account. If you believe a child's data has been processed, contact us and we will delete it.

12. International transfers

The processors above may store or process data on servers outside Australia. Where they do, they provide appropriate safeguards for that transfer.

13. Changes

We may update this policy; the "Last updated" date above will change and the current version will always be available at this URL.

14. Contact

Questions or requests: hong.qop1225@gmail.com.