1. If you connected Instagram to Otvetim
If you are the owner or admin of an Instagram business account connected to Otvetim, remove the app from your Instagram or Meta settings. Meta will send us a signed data deletion callback request.
Once we receive a valid callback we:
- zero out the access token, refresh token, and token expiry;
- set the Instagram connection status to
deauthorized; - remove the routing record the webhook used to find the workspace;
- create an audit record of the received request.
After that, Otvetim can no longer read new events or send replies on behalf of that Instagram account.
2. If you messaged a business as a customer
If you sent messages to a business that uses Otvetim, write to support@otvetim.by. In your email, please include:
- the channel: Instagram, Telegram, web widget, or email;
- your username, phone number, email, or other handle on that channel;
- the name of the business or account you wrote to;
- an approximate date of the conversation, if you remember it.
We use these details only to locate your conversation. If the request can be reliably matched to records in our system, we will delete or anonymize the related messages and attachments, unless applicable law or a contract with the business requires us to keep part of the data for a limited time.
3. Confirmation of an automated request
For the Meta data deletion callback, Otvetim returns JSON with a status URL and a confirmation code. The code is a technical receipt — it lets you verify that the callback was accepted.
If a callback does not carry a valid signature or cannot be matched to a connected account, we do not use it to access data. Such cases are logged for diagnostics.
4. What is deleted or anonymized
Depending on the type of request and whether we can match it, we delete or anonymize:
- tokens and technical configuration of the connected channel;
- contact identifiers in conversations;
- message text tied to the matched conversation;
- attachments, if they are stored in our object storage;
- conversation metadata that could be used to identify the user.
5. What is not deleted
- Messages stored inside Instagram, Telegram, or another platform. That is data of the platform itself, not of Otvetim.
- Aggregated analytics, as long as they do not contain a user identifier and cannot be used to reconstruct a conversation.
- Minimal audit records of the fact that a deletion happened, where those are needed for security, compliance, or to defend against repeated disputed requests.
6. Processing time
Automated Instagram deauthorization is handled as soon as the callback is received. Manual deletion requests are typically reviewed within 7 business days. If we need additional verification of account ownership, we may ask for confirmation.