Privacy policy
Last updated 23 September 2026
Margo is an assistant that answers Instagram DMs for local businesses, operated by Upbrew Technologies LLP (upbrew.in). This policy explains what we collect, why, and what you can ask us to delete. We keep it short and specific on purpose.
Who is who
A business is the salon, studio or clinic that signs up for Margo. A client is someone who messages that business on Instagram. For a client's messages the business is the data controller, and Margo is its processor: we handle the data on the business's instructions.
What we collect
From the business
- Name, email and sign-in details. Businesses sign in with an emailed link or Google; we don’t ask them to set a password.
- Business details you enter: services, prices, hours, policies, address.
- An access token for the Instagram account you connect, stored encrypted.
- The private address of a calendar you choose to link, stored encrypted, so Margo can see when you’re busy.
- Billing details, handled by our payment provider. We never see your card number.
- If you turn on Instagram insights: your account’s daily reach, profile visits, follower count and interactions, and how each of your posts did. These are counts about your own account, not about any individual person. Instagram only keeps them for a couple of days, so Margo records each day as it passes.
From clients who message the business
- Your Instagram-scoped ID, username, name and profile picture, as provided by Meta.
- The messages in your conversation with the business, and any photos you send.
- An email address or phone number, if you give one when booking or to receive something the business offers.
- Your bookings with that business, and a payment reference if you choose to give one after paying a deposit.
- A selfie, only if you ask to try on a style and agree when Margo asks. See Try-on.
- Whether you asked to stop reminder emails.
How we use it
- To answer DMs, book appointments, send reminders and ask for reviews.
- To publish the posts, Reels and Stories a business schedules in Margo to its own Instagram account, at the time it chose.
- To send you what you asked for with a keyword (a guide, a link), and your email with it if you gave one.
- If the business turns them on, to email you a reminder to book again a few weeks after a visit. Every one has a link to stop them.
- To make a try-on preview, when you ask for one.
- To show the business its inbox, bookings and weekly summary.
- If the business turns on Instagram insights, to show it how its account and its posts are doing, next to what Margo booked.
- To keep the service working: security, debugging, and preventing abuse.
We do not sell personal data. We do not use client messages to train our own models.
AI processing
To write replies, Margo sends the relevant part of a conversation, plus the business's services and policies, to an AI provider (currently OpenAI, through Cloudflare AI Gateway). The provider processes it to generate a reply and does not use it to train its models. A business can turn AI replies off at any time, and Margo will use simple rules instead.
Two features use DeepInfra, an AI provider, to make images and drafts. When a business asks Margo to draft an article, the topic and the business’s service and style names are sent to it. Try-on is described below.
Try-on
If you ask to see yourself with a style, Margo first asks your permission. Only if you agree and then send a selfie is that photo sent to DeepInfra, which returns a preview of you with the style. Margo does not keep your selfie. The preview is stored for 7 days, because Instagram fetches images from a link, and then deleted. Each person can make a few previews a day.
Payments
If a business asks for a deposit by UPI, you pay it from your own UPI app, straight to the business. Margo is not part of the payment and never sees your bank or card details; it only shows the amount and the business’s UPI ID, and records whether you said you paid and the reference number if you give it.
Who we share it with
These are our processors: they handle data on our instructions, under contract, and for no purpose of their own.
- Meta — to send and receive Instagram messages.
- Cloudflare — hosting, storage and AI gateway.
- OpenAI — generating replies.
- DeepInfra — try-on previews and article drafts, as described above.
- Google — sign-in, if a business chooses to sign in with Google.
- Dodo Payments — billing for businesses (merchant of record).
How long we keep it
- Message content: 12 months, then deleted.
- Try-on selfies: not kept. Try-on previews: 7 days, then deleted.
- Bookings: kept while the business uses Margo, because it is their business record.
- Account data: until the business closes its account, then deleted within 30 days.
- Instagram insights: kept while the business uses Margo, because the history is the point of them. Deleted with the account.
Your choices
You can ask for a copy of your data or ask us to delete it by emailing privacy@bymargo.co. If you messaged a business through Instagram, you can also ask Meta to remove Margo's access, and we will delete your messages, contact details and any try-on previews automatically. See data deletion for how that works. To stop reminder emails, use the link at the bottom of any of them.
If a business removes Margo from its Instagram account, Margo stops using that account straight away. If it also asks Meta to delete its data, we delete the conversations and client details that came through that account; the business’s own settings stay unless it closes its Margo account.
Security
Access tokens are encrypted at rest. Access to production data is limited to people who need it. We log what Margo sends on a business's behalf so it can be audited.
Contact
Upbrew Technologies LLP (trading as Margo)
privacy@bymargo.co · upbrew.in
This policy is written to be clear rather than exhaustive. If you operate in a regulated field, have your own counsel review how you use Margo.