Legal

Privacy Policy

Last updated: July 20, 2026 · Contact: [email protected]

Who we are

Mutuall is a marketplace where members get real, disclosed posts made about them by other members, and earn tokens by making posts for others. Instagram is the only platform we connect to. For the data described below, Mutuall acts as the data controller. We use Instagram's official API only — we never scrape, never automate actions on your account, and never ask for your Instagram password.

What we collect

Account data. Your email address, a one-way hash of your password (never the password itself), your token balance, your payment records for any package you buy, and the time of your last visit.

Connected Instagram data. With your explicit consent through Instagram's official login, we read your professional account's profile fields (such as your username, name, profile picture, bio, follower and post counts), your posts and their captions, and account-level insights from Instagram's official API. We use this to confirm your account is real and eligible, to show creators and receivers who they are working with, and to verify delivered posts. We collect only account-level metrics — never per-post non-follower breakdowns, which Instagram does not provide.

How the Instagram connection is made. Instagram connections are made through bundle.social, an authorized Meta Tech Provider that acts as our data processor for Instagram, under a data-processing agreement. That is why you see their name on Instagram's consent screen when you connect. What flows through them: the connection token (which they hold and we never see in plain form), and your profile and post data on its way to us, retrieved from Instagram's official API. They process this data only to provide the service to us. When you disconnect your Instagram account or delete your Mutuall account, we also instruct bundle.social to delete the imported posts and analytics they hold and to disconnect the account on their side.

Campaign material and deliverables you upload. When you post a campaign you upload your own photos or clips; when you make a post for someone, you upload the finished image or Reel and write the caption. These files are private to the two members in that campaign (and to our team, for arbitration and safety). They are deleted the moment the campaign wraps — when the token is released, or when the campaign is withdrawn — not kept in a library.

Campaign and token records. We keep the campaign itself (your brief text, who made it, the approved caption, the link to the published post, the approval and verification timeline) and an append-only record of every token earned, spent, granted or reversed. This record is what makes the marketplace auditable and lets us settle disputes honestly.

Post verification reads. When a maker submits a delivered post, we read that post from their own connected account through Instagram's official API to check that it exists, that its caption matches the caption the receiver approved (including the disclosure line), and that the image matches the approved deliverable. We repeat a lighter version of that check about three days later to confirm the post is still up and still disclosed.

Payments. Payments for creator packages are processed by Stripe. We never see or store your card number — we keep only the transaction records Stripe gives us (amount, status, package).

Usage and logs. We record product events (such as posting a campaign or approving a draft) and operational logs (errors, security events) including IP addresses, to run, secure, and improve the service. We use a session cookie and a one-time first-visit cookie that remembers how you found us. We do not run third-party advertising trackers.

Why we process it

To verify that members and their accounts are real and eligible, to run campaigns between them, to confirm delivered posts are live and properly disclosed, to keep the token record accurate, to take payment for packages, to send the emails you have signed up for, to prevent abuse and fraud, and to meet our legal obligations — including the advertising disclosure rules that apply to sponsored posts.

What we show other members

Members need to know who they are working with. Your Instagram username, profile picture, follower count and niche are visible to the other member in a campaign, and your username appears in the paid-partnership disclosure on any post made about you. Your email address, your token balance, and your payment records are never shown to other members.

How long we keep it (retention)

Uploaded files are short-lived: campaign material and deliverables are deleted as soon as the campaign wraps.

Campaign and token records last as long as your account. Tokens never expire, so the record that proves what you earned has to persist — that is the point of it. Payment records are retained as long as tax and accounting law requires. Operational logs are kept for a bounded period and then purged or aggregated. When your account is deleted, the section below applies instead.

Deleting your data

Self-serve. You can delete your account from your account settings at any time. Deletion anonymizes your account in place: your email is scrubbed, your Instagram connection and its encrypted access token are removed, and your campaign and token history is detached from your identity. It cannot be undone. Note that any post you already published stays on your own Instagram account — it is yours, and only you can remove it.

Via Instagram. If you remove Mutuall from your Instagram account settings, access is revoked immediately and we purge the stored access token. If you request data deletion through Meta, their data-deletion callback triggers a purge of your Instagram-derived data and returns a confirmation code with a status page you can check. Disconnecting in Mutuall (or deleting your account) additionally triggers deletion of the imported posts and analytics held at bundle.social and disconnection of the account on their side.

Full step-by-step instructions are on our Data Deletion page.

Sharing

We do not sell personal data. We share data only with the processors needed to run the service — our hosting provider, bundle.social as the integration provider for Instagram connections, Stripe for payments, and our email delivery provider — each bound by their own data-processing terms. We may also disclose data where the law requires it.

Your rights

Depending on where you live, you may have rights to access, correct, export, or erase your personal data, and to object to or restrict processing. Email [email protected] and we will respond within 30 days.

Changes

If this policy changes materially, we will note it here and, for significant changes, email account holders before the change takes effect.