Privacy Policy
Last updated 1 October 2026
Klone Guard is a service run by Klone Digital ("we", "us") in Australia. It hides or deletes spam and bot comments on Instagram accounts that our customers connect. This policy explains what information we collect, why, and what you can do about it. We handle personal information in line with the Australian Privacy Principles in the Privacy Act 1988 (Cth).
What we collect
If you are a customer:
- Your email address and password. Passwords are stored only as a secure hash by our authentication provider; we never see them.
- The Instagram accounts you connect: their username, Instagram account ID and account type, and an access token that lets us moderate comments. Tokens are encrypted (AES-256) before they are stored.
- Your moderation settings, such as blocked words, whitelisted usernames and pinned posts.
- Billing details: your subscription status, plan and Stripe customer ID. Card details are entered on Stripe's pages and never reach our servers.
- Security information: to stop password-guessing, we record login and signup attempts using a one-way hash of your email and IP address. These records are deleted after one day.
If you comment on a customer's Instagram post: we read comments on our customers' posts to check them for spam. Comments that look normal are not stored. If a comment is hidden or deleted, we keep its text, the commenter's username, the post it was on, the time and the reason, so the account owner can review it and undo mistakes.
Instagram permissions
We ask Instagram only for instagram_business_basic (to identify the account and list its posts) and instagram_business_manage_comments (to read, hide, unhide and delete comments). We never ask for your Instagram password, never post on your behalf and never read your messages.
How we use it
- To provide the service: checking comments, removing spam and showing you what was removed.
- To manage your account, subscription and payments.
- To keep the service secure and fix problems.
- To contact you about your account, for example if an Instagram account needs reconnecting.
We do not sell personal information and we do not use it for advertising.
Who we share it with
We use a small number of providers to run the service. They only process data on our behalf:
- Supabase, for our database and logins. Data is stored in Singapore.
- Stripe, for payments.
- Meta (Instagram), whose API we use to read and moderate comments.
- Our website and server hosting providers.
Because some of these providers store data outside Australia (including Singapore and the United States), your information may be handled overseas. We choose providers with strong security practices. We may also disclose information where the law requires it.
Cookies
We only use the cookies needed to keep you logged in. We don't use advertising or tracking cookies.
How long we keep it
We keep your information while your account is open. If you cancel your subscription, your settings are kept so moderation can resume if you subscribe again, unless you ask us to delete them. When you ask us to delete your data, we delete it within 30 days, except where we must keep records by law (for example, tax records of payments).
How to delete your data
- Email hello@klone.site from the email address on your account and ask us to delete your data. We will delete your account, connected Instagram accounts, access tokens, settings and moderation history.
- You can also remove Klone Guard from your Instagram account at any time: in Instagram, go to Settings, then Website permissions, then Apps and websites, and remove it. This stops us accessing your account immediately.
- If your comment was removed from someone else's post and you want our copy deleted, email hello@klone.site with your Instagram username.
Access and correction
You can ask for a copy of the personal information we hold about you, or ask us to correct it, by emailing hello@klone.site. We will respond within 30 days.
Security
Access tokens are encrypted, each customer can only access their own data, and payments are handled by Stripe. No system is perfectly secure, but if a data breach is likely to cause you serious harm, we will tell you and the Office of the Australian Information Commissioner as the law requires.
Children
Klone Guard is for businesses and creators aged 18 or over. We don't knowingly collect information from children.
Complaints
If you have a privacy concern, email hello@klone.site and we will respond within 30 days. If you're not satisfied, you can contact the Office of the Australian Information Commissioner at oaic.gov.au.
Changes
If we change this policy we will update the date above, and tell customers by email about significant changes.
Contact
Klone Digital, Australia · hello@klone.site