> ## Documentation Index
> Fetch the complete documentation index at: https://docs.willosend.com/llms.txt
> Use this file to discover all available pages before exploring further.

# How WilloSend Keeps Your Instagram Account Safe

> WilloSend runs exclusively on Meta's official Instagram Graph API — no bots, no scraping, no password sharing, and automatic rate-limit enforcement.

WilloSend is built entirely on Meta's official Instagram Graph API — the same infrastructure Instagram recommends for business-grade automation. This isn't a marketing claim; it's a technical architecture decision that determines everything from how your account connects to how messages are sent. Understanding what that means in practice helps you automate with confidence and avoid the mistakes that genuinely do put accounts at risk.

## Why the Official API Changes Everything

Before Meta opened the official API in 2021, "Instagram automation" meant browser bots that logged into your account and simulated human clicks. Instagram's machine-learning systems learned to detect those patterns, and accounts using such tools faced action blocks, shadowbans, and permanent bans. That history is why so many creators are still anxious about automation — but the tool category that caused those problems no longer describes what WilloSend does.

<CardGroup cols={2}>
  <Card title="No Bots" icon="robot">
    WilloSend never simulates human actions or clicks through Instagram's web interface. Every action goes through Meta's official server-to-server API — Instagram knows exactly what's happening and explicitly permits it.
  </Card>

  <Card title="No Scraping" icon="ban">
    Comments, user IDs, and engagement data are accessed only through permissioned, official API calls — never by scraping Instagram's web pages or reverse-engineering the app.
  </Card>

  <Card title="No Password Sharing" icon="lock">
    You connect WilloSend to Instagram via OAuth — the same secure login standard used by Meta's own business tools. WilloSend never sees, stores, or transmits your Instagram password.
  </Card>

  <Card title="Automatic Rate Limiting" icon="gauge">
    Meta allows up to approximately 200 automated DMs per hour per account through the official API. WilloSend enforces this limit automatically — you can't accidentally exceed it, even during a viral post surge.
  </Card>
</CardGroup>

## The 24-Hour Messaging Window

Meta's messaging policy exists to protect users from being contacted indefinitely after a single interaction. WilloSend enforces this policy automatically, so you never have to track it yourself.

<Info>
  When a user engages with your content — by commenting a keyword, replying to your story, or sending you a DM — a 24-hour window opens. During that window, WilloSend can send them automated promotional messages. Every time the user replies, the clock resets. After 24 hours of no engagement, the window closes and no further promotional messages are sent until they engage again.
</Info>

WilloSend **only** sends DMs triggered by a real, user-initiated action — a comment, a story reply, or a keyword match. There is no mechanism inside WilloSend to send a message to someone who hasn't engaged with your content first. This design is intentional: it keeps every automated DM compliant with Meta's policy by default, not as an afterthought.

## What WilloSend Will Not Do

Some automation requests fall outside what Meta permits. WilloSend declines to offer these features regardless of plan or request — not because of an arbitrary product limitation, but because offering them would put your account at genuine risk.

<AccordionGroup>
  <Accordion title="Send cold DMs to non-engaged users">
    There is no API path inside Meta's infrastructure that allows promotional cold outreach to users who haven't interacted with your content in the past 24 hours. WilloSend will not send unsolicited DMs to people who haven't first engaged with your post, reel, or story.
  </Accordion>

  <Accordion title="Auto-follow or auto-unfollow accounts">
    Mass following and unfollowing is one of the most reliable triggers for Instagram behavior-based throttling. WilloSend has no follow or unfollow features — full stop.
  </Accordion>

  <Accordion title="Auto-like or auto-comment outside of reply flows">
    Automated liking and commenting outside of direct reply flows mimics bot behavior and falls outside Meta's permitted API usage. WilloSend does not offer these actions.
  </Accordion>

  <Accordion title="Use URL shorteners inside DMs">
    Meta actively deboosts DMs that contain shortened URLs (bit.ly, tinyurl, and similar services). WilloSend does not permit URL shorteners in DM message templates — always use your full destination URL.
  </Accordion>
</AccordionGroup>

<Warning>
  If another tool offers you cold DM outreach, auto-follow, or mass-DM to all your followers regardless of engagement, that tool is operating outside Meta's official API. Using it puts your account at risk of messaging restrictions or permanent bans — regardless of how it's marketed.
</Warning>

## Viral Post Protection

A viral post is one of the best problems you can have — but it shouldn't penalize you for being successful.

<Info>
  If an unexpected viral post causes you to surpass your monthly DM limit, WilloSend provides **1 free overage per account**. Your automations keep running through the viral surge. If you consistently exceed your plan's DM limit, you'll be prompted to upgrade — but a single unexpected spike won't interrupt your campaigns or charge you automatically.
</Info>

## How to Verify WilloSend Is Legitimate

You don't have to take our word for it. Instagram lets you see every app connected to your account through the official OAuth system.

<Steps>
  <Step title="Open Instagram Settings">
    Tap your profile picture, then tap the three-line menu in the top right. Go to **Settings and Privacy**.
  </Step>

  <Step title="Navigate to Security">
    Tap **Security**, then tap **Apps and Websites**.
  </Step>

  <Step title="Find WilloSend in the active apps list">
    WilloSend should appear in your list of active connected apps. Its presence here confirms it connected through the official OAuth flow — not through a password hand-off or browser session hijacking.
  </Step>

  <Step title="Remove anything you don't recognize">
    While you're here, review the full list. Remove any app you don't recognize or haven't used recently — especially anything you may have connected before switching to official API tools. Then change your Instagram password to invalidate any active sessions from removed apps.
  </Step>
</Steps>

<Tip>
  Make checking your Apps and Websites list a monthly habit. It's the fastest way to audit your account's security posture and catch any unauthorized app access before it causes problems.
</Tip>

## The Safety Record in Context

Meta's own data on compliant API-based automation tools shows an account restriction rate of roughly **0.4% per quarter** — compared to **11–17% per quarter** for unofficial browser-based bots and automation scripts. The difference isn't marginal. Building your DM strategy on the official API is the single most impactful thing you can do to protect your account while scaling your outreach.

<Note>
  For a comprehensive guide to protecting your Instagram account — including safe engagement limits, how to check Account Status, and recovery steps — see [Instagram Safety](/help/instagram-safety).
</Note>
