Introduction
MDLMN ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how MDLMN collects, uses, and safeguards your information across our services, including our Chrome Extension and our web platform for business customer messaging (including connected Instagram and Facebook Messenger accounts).
Information We Collect
Information You Provide
- Account ID: You provide your MDLMN account ID through the extension's options page to connect to your account
- Phone Number: Your preferred phone number for making calls (stored locally in your browser)
- Dial Preferences: Your call handling preferences (stored locally in your browser)
Information Collected Automatically
- Selected Phone Numbers: When you use the extension to dial, call, or text, the selected phone number is sent to our API
- Selected Text: When you use the "Clip" feature, the selected text and current page URL are sent to our API
Business Messaging Platform (Connected Instagram & Facebook Accounts)
MDLMN offers a web platform that lets a business connect its own Instagram professional account and/or Facebook Page so that direct messages from that business's customers appear in one unified inbox. This section explains the data involved when a business connects a Meta (Instagram or Facebook) account.
What Connecting Grants
A business owner or authorized admin connects their account through Meta's official login (Instagram Login or Facebook Login for Business) and grants MDLMN permission to receive and respond to that account's messages. We store an encrypted access token so the connection persists; we never ask for or store the account's Instagram or Facebook password.
Information We Receive from Meta
- Message content: the text of direct messages sent to or from the connected business account
- Sender identifiers: the Meta-scoped ID (and, where provided, username) of the person messaging the business, used to organize a conversation
- Message metadata: message IDs, timestamps, and the connected account ID the message was sent to
- Connected account details: the business's own Instagram/Facebook account ID and Page ID
We request only the permissions needed to receive and reply to messages on the connected account. We do not access posts, followers, ad accounts, or other Meta data beyond the messaging scope described here.
How This Data Is Used
- Deliver the unified inbox: display incoming messages and let the business read and reply to them within MDLMN
- Maintain conversation history: associate messages with the correct customer and connected account
- Operate the service: we do not use message content for advertising, and we do not sell it
Your Choices & Deletion
A connected business can disconnect its Instagram or Facebook account at any time, which stops MDLMN from receiving further messages for that account. To request deletion of message data MDLMN holds, see the "Your Rights," "California Privacy Rights," and "European Users (GDPR)" sections below, or contact us using the details in "Contact Us." MDLMN's use of information received from Meta APIs follows Meta's Platform Terms and Developer Policies.
How We Use Your Information
We use the collected information to:
- Authenticate your account with the MDLMN service
- Initiate phone calls through your Twilio account
- Send text messages through your Twilio account
- Process clip requests by sending selected text to your phone
- Deliver the messaging inbox for connected Instagram and Facebook Messenger accounts
Data Storage
- Local Storage: Your account ID, preferred phone number, and dial preferences are stored locally in your browser using Chrome's storage API
- No Cloud Storage: The extension itself does not store any of your data on our servers
- Server Processing: Information sent to our API (phone numbers, text content) is processed in real-time and not permanently stored
Third-Party Services
Twilio
Our service uses Twilio to handle phone calls and text messages. When you use the extension, data is transmitted to Twilio's servers. Please review Twilio's Privacy Policy for more information.
Meta (Instagram & Facebook)
When a business connects an Instagram or Facebook account, MDLMN exchanges data with Meta's messaging APIs to receive and send messages on that account. Please review Meta's Privacy Policy for more information. MDLMN's use of information received from Meta APIs adheres to Meta's Platform Terms and Developer Policies.
MDLMN API
Selected phone numbers and text are sent to our API (api.mdlmn.co) to process your requests. This data is used solely to fulfill your request and is not stored permanently.
Data Sharing
We do not:
- Sell your personal information
- Share your data with third parties for marketing purposes
- Use your data for purposes other than providing the MDLMN service
We may share data:
- With Twilio to process calls and texts
- With Meta to send and receive messages on a connected Instagram or Facebook account
- When required by law or to protect our legal rights
- With your explicit consent
Data Security
We implement appropriate security measures to protect your information:
- HTTPS encryption for all data transmission
- Secure API authentication
- Local browser storage (data never leaves your device unless you use the extension features)
Your Rights
You have the right to:
- Access your data stored in the extension (through Chrome extension settings)
- Delete your data by removing the extension or clearing its storage; for messaging data from a connected Instagram or Facebook account, disconnect the account or contact us to request deletion
- Delete your MDLMN account and personal data — if you have an MDLMN account, you can request permanent deletion of it and your personal information by contacting your administrator or emailing support@mdlmn.co. We verify your identity before anything is deleted. The minimal consent/message records the law requires are retained as compliance evidence.
- Control what information you provide to the extension and which accounts you connect
- Opt-out by not using the extension or by disconnecting a connected messaging account
If you received text messages from a business using MDLMN and want to access or delete your data (as a message recipient), use that business's privacy request page at consentlink.co/{business}/privacy-request, linked from the privacy notice they shared with you.
Children's Privacy
Our extension is not intended for users under the age of 13. We do not knowingly collect information from children under 13.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by updating the "Last Updated" date at the top of this policy.
Contact Us
If you have questions about this Privacy Policy, please contact us:
California Privacy Rights
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
- Right to know what personal information is collected
- Right to delete personal information
- Right to opt-out of the sale of personal information (Note: We do not sell personal information)
European Users (GDPR)
If you are in the European Economic Area (EEA), you have rights under the General Data Protection Regulation (GDPR):
- Right to access your data
- Right to rectification
- Right to erasure
- Right to restrict processing
- Right to data portability
- Right to object
Consent
By using the MDLMN Chrome Extension or platform, or by connecting a messaging account, you consent to this Privacy Policy and agree to its terms.