Inbox Privacy
Privacy Policy – Miralina Influencer Inbox
Last updated: May 11, 2026
This Privacy Policy applies to the application Miralina Influencer Inbox (hereinafter “App”), operated by:
Miralina GmbH Berlin, Germany Email: tayfun.oener@miralina.de
The App is used exclusively for the internal management of direct messages (DMs) and comments from the Instagram Business Account @miralina.halalsweets by Miralina GmbH and authorized employees.
1. What data we process
The App processes the following data provided through the official Instagram Graph API of Meta Platforms Inc.:
- Content of incoming and outgoing Instagram direct messages (text, attachments)
- Instagram user ID and username of the sender
- Message timestamps
- Optional: the sender’s profile picture and public name, where available through the API
- Optional: reactions, postback events, and read receipts
No data is processed from users who have not actively sent a message to @miralina.halalsweets.
2. Legal basis
Processing is carried out on the basis of Art. 6(1)(b) GDPR (performance of a contract, where a business transaction exists) or Art. 6(1)(f) GDPR (legitimate interest in efficient customer communication and community management).
3. Purpose of processing
- Responding to inquiries from our customers and influencer partners
- Organizing and prioritizing incoming messages
- Automatic preliminary classification (e.g., customer vs. influencer vs. spam) using artificial intelligence (Anthropic’s Claude API). The final response is always reviewed and approved by a human.
4. Storage & processors
- Data is stored on servers operated by Supabase (Frankfurt, eu-central-1) within the EU
- Message content is transmitted to Anthropic (Claude API) for preliminary classification. Anthropic processes this data in accordance with its own privacy policy (anthropic.com/legal/privacy) and does not store API data for training purposes.
- We have GDPR-compliant data processing agreements (DPAs) with both providers.
5. Retention period
Messages are stored for the duration of the business relationship, but for no longer than 24 months from the last activity. They are then automatically deleted. Upon request, we will delete data earlier (see Section 7).
6. Disclosure to third parties
We disclose data exclusively to the processors named in Section 4. We do not share data with advertising networks or data brokers.
7. Your rights
You have the right to:
- Access your data stored by us (Art. 15 GDPR)
- Rectification (Art. 16 GDPR)
- Erasure (Art. 17 GDPR) — see the separate Data Deletion Instructions at https://miralina.de/pages/inbox-data-deletion
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Object to processing (Art. 21 GDPR)
- Lodge a complaint with a supervisory authority (Art. 77 GDPR) — responsible authority: Berlin Commissioner for Data Protection and Freedom of Information
For all inquiries, please contact: tayfun.oener@miralina.de
8. Security
- Encryption in transit (HTTPS / TLS 1.3) and at rest
- Access to the App is limited to authorized employees through a separate authentication system
- Webhook signatures (HMAC SHA256) to secure data transmission from Meta
9. Changes
We reserve the right to amend this Privacy Policy if legal requirements or the App’s functionality change. The current version is always available at this URL.
Controller within the meaning of the GDPR: Miralina GmbH, Berlin, represented by Managing Director Tayfun Öner. Email: tayfun.oener@miralina.de
Log in