Data Deletion Policy
Last updated: 10th May 2026
This Data Deletion Policy explains how you can request deletion of your personal data from BeCreator, operated by Agen Digital LLP. It also describes how we handle data access requests, what data we purge, and our operational process for fulfilling these requests. This policy supplements our Privacy Policy.
1. Your Right to Data Deletion
You have the right to request deletion of the personal data that BeCreator holds about you. This right applies whether you are:
- A creator (BeCreator account holder)
- An end user (someone who interacted with a creator's automation, such as receiving an Instagram Auto DM)
- A visitor (someone who submitted a form, booked an appointment, or provided contact information through a creator's BeCreator profile)
We honour data deletion requests in accordance with applicable data protection laws, including the GDPR (Article 17 — Right to Erasure), UK GDPR, and India's Digital Personal Data Protection Act.
2. How to Request Data Deletion
a) For Creators (Account Holders)
You have two options to delete your data:
- Self-service account deletion: Go to Settings → Delete Account in your dashboard. This initiates a deletion request with a 14-day grace period. During this period, you can cancel the request if you change your mind. After 14 days, your account and all associated data will be permanently deleted.
- Email request: Send an email to [email protected] with the subject line "Data Deletion Request". Include your account email address and confirm that you want your account and all associated data deleted.
b) For End Users (DM Recipients, Form Submitters, Visitors)
If you interacted with a creator's BeCreator-powered automation (received an Auto DM, submitted a form, booked an appointment, or provided your email), you can request deletion of your data:
- Email [email protected] with the subject line "End User Data Deletion Request"
- Include: your Instagram username (if you interacted via Instagram), your email address (if you provided one), and a description of how you interacted with the platform (e.g., "I received DMs from @creatorname")
- We will verify your identity and process the deletion within 30 days
c) Instagram / Meta Data Deletion Callback
When you remove BeCreator from your Instagram account's authorized apps (via Instagram → Settings → Apps and Websites), Meta sends a data deletion callback to BeCreator. Upon receiving this callback, we automatically:
- Revoke and delete your stored Instagram access token
- Delete your Instagram connection record
- Issue a confirmation code that you can use to track deletion status
You can check the status of a Meta-initiated deletion request at becreator.app/deletion-status using your confirmation code.
3. How to Request Data Access
You have the right to request a copy of the personal data BeCreator holds about you. To exercise this right:
- Email [email protected] with the subject line "Data Access Request"
- Include your account email address or other identifying information
- We will verify your identity and provide your data in a portable format (JSON or CSV) within 30 days
The data export will include:
- Your account profile information
- Your Instagram connection details (excluding access tokens)
- Your automation configurations (triggers, templates)
- Conversation and message logs
- Collected email addresses
- Booking records
- Form responses
- Link and analytics data
4. What Data We Delete
Creator Account Deletion
When a creator deletes their BeCreator account, we permanently remove:
- Account data: name, email, profile picture, username, and all account settings
- Profile and link-in-bio data: profile links, gallery photos, social links, and all customizations
- Instagram connection: stored access tokens, Instagram profile data, and cached profile pictures
- Auto DM data: all triggers, templates, conversations, messages, DM jobs, and collected emails
- Booking data: events, availability rules, overrides, custom fields, and all booking records
- Product data: product listings and associated files
- Form data: forms, form pages, form blocks, and all form responses
- Link data: short links, link folders, link tags, click analytics, and UTM templates
- File storage: all uploaded files, images, and media associated with your account
- Google Calendar connections: stored OAuth tokens and calendar sync records
End User Data Deletion
When we process a deletion request from an end user, we remove:
- Instagram profile data: cached Instagram profile (user ID, username, name, profile picture)
- Conversation records: all DM conversation data and message logs involving that user
- DM job records: any pending or completed message delivery records
- Collected email: email address if voluntarily provided during a DM funnel
- Form responses: any form submissions tied to the user's email
5. Data We Retain After Deletion
Certain data may be retained even after a deletion request, as required by law or legitimate interest:
- Billing and transaction records: We retain billing records (subscription history, invoice metadata) as required for legal, tax, and financial compliance obligations. These records do not include full payment card details (which are held by our payment processor, Paddle).
- Legal holds: If data is subject to a legal proceeding, regulatory investigation, or government request, we may be required to retain it until the matter is resolved.
- Aggregated and anonymized data: We may retain anonymized, non-personally-identifiable usage statistics that cannot be traced back to you.
6. Our Deletion Process
Here is exactly how we handle data deletion requests:
- Receipt and acknowledgment (within 3 business days): We acknowledge your request via email and confirm the scope of data to be deleted.
- Identity verification: We verify your identity to prevent unauthorized deletion. For creators, we verify account ownership via your registered email. For end users, we may ask for your Instagram username, email address, or other identifying information you provided during your interaction.
- Data identification: We identify all records associated with your account or identity across our systems (Convex database, file storage, authentication provider).
- Deletion execution: We permanently delete the identified data from our primary database and file storage. This includes removing records from all relevant tables and deleting associated files from Convex storage.
- Third-party notification: Where applicable, we notify our subprocessors (Clerk, Convex, Paddle) to delete data they hold on our behalf.
- Confirmation (within 30 days): We send you a confirmation email once deletion is complete, detailing what data was removed.
Deletion Timelines
- Self-service account deletion: A 14-day grace period begins when you submit the request. You can cancel during this window. After 14 days, data is permanently purged from our primary database. Backups and replicas may take up to an additional 30 days to fully cycle out.
- Email-based requests: Processed within 30 days of receipt, as required by GDPR and applicable regulations.
- Meta/Instagram data deletion callbacks: Processed within 48 hours of receiving the callback.
7. How We Handle Data Day-to-Day
Beyond deletion requests, here is how BeCreator handles data in our regular operations:
Data Storage
- All data is stored in Convex, a managed database platform with US-based infrastructure
- Files (images, media) are stored in Convex's integrated file storage
- Authentication data is managed by Clerk, a dedicated identity provider
- Payment data is managed by Paddle (Merchant of Record) — we never store full card details
Data Security
- All data in transit is encrypted via TLS/HTTPS
- Database access is restricted through Convex's authentication and authorization layer
- Instagram access tokens are stored securely and refreshed automatically before expiry
- Webhook payloads from Meta are verified using HMAC signature validation before processing
- Admin access to production data is restricted and audited
Data Minimization
- We only collect data necessary to provide BeCreator's features
- Raw webhook payloads are not stored — only specific, relevant fields are extracted
- We do not build profiles of end users beyond what is needed for automation delivery
- Collected emails are stored in BeCreator only and are not synced to third-party marketing platforms
8. Automatic Data Purging
BeCreator automatically purges certain data based on retention schedules:
- Expired Instagram tokens: Access tokens that fail to refresh are automatically revoked and deleted
- Completed DM jobs: Message delivery records are retained for analytics and inbox history while the creator account is active, then deleted on account deletion
- Session data: Authentication sessions are managed and expired by Clerk according to their security policies
- Analytics data: Usage analytics collected by PostHog are subject to PostHog's own retention policies
9. Disconnecting Instagram
Creators can disconnect their Instagram account from BeCreator at any time through the dashboard. When you disconnect:
- Your Instagram access token is immediately revoked and deleted
- All Instagram connection data is removed (profile info, cached pictures)
- All Auto DM triggers are deactivated
- Conversation and message history associated with that Instagram account is deleted
- Pending DM jobs are cancelled
You can also revoke BeCreator's access from Instagram directly at Instagram → Settings → Apps and Websites. This triggers Meta's data deletion callback (see Section 2c).
10. Your Rights
In addition to deletion, you have the right to:
- Access: Request a copy of all personal data we hold about you
- Rectification: Correct inaccurate data through your dashboard or by contacting us
- Restriction: Request that we stop processing your data while a dispute or request is resolved
- Portability: Receive your data in a structured, machine-readable format
- Objection: Object to processing based on legitimate interests
- Withdraw consent: Revoke consent at any time (e.g., by disconnecting your Instagram account)
For EU/UK residents, these rights are protected under GDPR (Articles 15–22). To exercise any of these rights, contact [email protected].
11. Changes to This Policy
We may update this Data Deletion Policy from time to time. When we do, we will revise the "Last updated" date at the top of this page. For material changes, we will notify you by email or through a notice on the platform.
12. Contact Us
For data deletion requests, data access requests, or questions about this policy:
Agen Digital LLP
Email: [email protected]
Website: becreator.app/contact
You also have the right to lodge a complaint with your local data protection supervisory authority if you believe your rights have not been adequately addressed.