Privacy Policy — BlainLeVilain Social

Last updated: 3 September 2026

BlainLeVilain Social is a private, single-operator application built and run by Guillaume Blain (the designer behind the MakerWorld profile @BlainLeVilain). It exists for one purpose: to manage the Instagram professional account @blain.le.vilain, which belongs to the operator himself. It is not offered to the public, has no other users, and sells nothing.

1. What the application does

Through the Instagram API with Instagram Login, the application lets the operator:

2. Data received from Meta ("Platform Data")

The application receives only data about the connected account and the people who interact with it: the account's identifier, username and media; per-media insight metrics (views, reach, likes, comments, saves, shares); the text, author username and timestamp of comments and messages addressed to the account; and the OAuth access token that authorises these calls.

3. How the data is used

Comments and messages are used solely to draft and post replies from the account owner. Insights are used to report on the performance of the operator's own publications. No data is used for advertising, profiling, resale, or any purpose unrelated to managing the connected account.

4. Where the data is stored and who can see it

All data is processed on a server owned and operated by Guillaume Blain in Canada. Access tokens are stored encrypted at rest (AES-256-GCM) in a self-hosted credential broker reachable only through a private network. No Platform Data is shared with, sold to, or transferred to any third party, service provider, or other person. Automated text drafting may be performed by an AI model operating under the operator's control; only the text of the comment or message being answered is used for that purpose, and it is not retained by the model provider beyond the request.

5. Retention

Comments, messages and insight snapshots are kept for as long as they are needed to reply and to report on the account's publications, and no longer than 24 months. Access tokens are kept until the connection is revoked. Data that Meta signals as deleted or that a user asks to have deleted is removed within 30 days.

6. Your rights and data deletion

If you have interacted with @blain.le.vilain and want the copy of your comment or message held by this application deleted, follow the instructions at policies.blain-projects.ca/data-deletion, or write to the contact below. Requests are honoured within 30 days.

7. Security

The server is protected by a firewall that denies inbound connections by default, SSH key authentication only, encrypted credential storage, and access limited to the operator.

8. Changes

This policy may be updated when the application changes. The date at the top reflects the current version.

9. Contact

Guillaume Blain — gblain03@hotmail.com