Skip to content
Privacy

Privacy policy

Last updated September 25, 2026

Short version: we store the conversations your automations have, we keep them for 12 months, we never sell them, and anyone can have their data deleted in a few minutes.

1. Who we are and what this policy covers

Replyz is a messaging automation tool for Instagram, operated by [legal entity], [registered address]. This policy covers the Replyz website, the dashboard and the automated conversations the product sends through the official Instagram API.

It does not cover Instagram itself. What Meta Platforms collects when you use Instagram is governed by Meta's own privacy policy, and we have no control over it.

2. Our role: processor for your audience, controller for your account

The distinction decides who answers a request about someone's data, so it is stated first rather than buried.

  • Customer account data. For the account you open with us, your email address, your workspace and your billing records, we are the controller. We decide what is stored and for how long.
  • Audience data. For the people who comment on your posts and receive your automated messages, you are the controller and we are the processor. We store and transmit that data on your instruction, in order to run the automations you built. We do not use it for our own purposes, we do not sell it, and we do not build audiences across customers.

If you are a subscriber and want your data removed, the fastest route is to contact the account that messaged you. You can also reply STOP in the conversation, or use our data deletion page, and we will act on it.

3. What we collect

From you, the customer

  • Email address, display name and profile picture when you sign in.
  • Workspace name, plan, and the automations, keywords and messages you write.
  • The Instagram account you connect: its Instagram-scoped user id, username, name and profile picture, plus an access token issued by Meta. The token is encrypted at rest and never leaves our servers.
  • Billing data handled by our payment provider: we store a customer identifier, the plan and the invoice history. We never see or store your full card number.

From the people your automations talk to

  • Instagram-scoped user id, username and display name.
  • The content of messages exchanged in the conversation, in both directions, including the comment that started it.
  • Answers to questions your automation asks, and tags your automation assigns.
  • Proof of how the conversation began: the keyword used, the post or reel, and the invitation text shown at that moment. This exists so a consent question can be answered with a fact.
  • Whether the person opted out, and when.

Technical data

  • Server logs: request time, route, status code, truncated error messages and a coarse location derived from the IP address.
  • A session cookie that keeps you signed in. It is httpOnly, so page scripts cannot read it. We do not use advertising cookies and we do not run third party trackers on the dashboard.

4. Why we use it, and on what legal basis

  • To run the service, which means matching keywords, sending messages through the Instagram API, and showing you the conversation. Legal basis: performance of our contract with you, and for your audience, your legitimate interest in responding to people who contacted you first.
  • To bill you and to meet accounting duties. Legal basis: contract and legal obligation.
  • To keep the service safe and within Meta's rules, which means rate limiting, abuse detection and suspending accounts that send unsolicited messages. Legal basis: legitimate interest.
  • To support you when you write to us. Legal basis: contract.

We do not use message content to train machine learning models, and we do not share it with advertisers.

5. What we do with Instagram permissions

Connecting an account gives us a token scoped to that account. We use it for exactly three things: reading comments on your own posts and reels, reading and sending direct messages for your account, and reading your basic profile so the dashboard can show which account is connected.

We do not post on your behalf beyond the public comment replies you configure, we do not read your followers' private data, and we do not access accounts you have not connected. Disconnecting the account in Replyz or removing the app in Instagram deletes the token immediately.

Replyz is independent software that uses the public Instagram API. It is not affiliated with, endorsed by or sponsored by Meta Platforms, Inc.

6. Who else processes the data

We use a small number of providers to run the service. Each is bound by a data processing agreement, and each only receives what it needs.

  • Google Cloud and Firebase, United States: hosting, database, authentication and logs.
  • Meta Platforms, United States: delivery of the messages themselves. Instagram necessarily sees the conversation, because it happens on Instagram.
  • Stripe, United States and Ireland: payments and invoices.

We publish this list before adding a provider. We also disclose data when the law requires it, and we will tell you unless we are legally barred from doing so.

7. How long we keep it

  • Conversations and subscriber records: 12 months after the last message in that conversation, then deleted. A shorter period can be agreed for a workspace.
  • Customer account and workspace: for as long as the account exists. Closing the account deletes it within 30 days.
  • Access tokens: deleted the moment an account is disconnected.
  • Server logs: 90 days.
  • Invoices and accounting records: as long as tax law requires, which is longer than the periods above and applies even after the account is closed.
  • Deletion requests: we keep the confirmation code, the date and the outcome, so we can prove a request was honoured. This record contains no message content.

8. International transfers and security

Our providers operate in the United States, so data is transferred outside the European Economic Area. Those transfers rely on the European Commission's standard contractual clauses, together with the safeguards each provider publishes.

On our side: traffic runs over TLS, access tokens are encrypted at rest with AES-256-GCM, session cookies are httpOnly, and access to production data is limited to the people who need it and is logged. No system is perfect, and we do not claim otherwise. If a breach affects your data, we notify you and, where required, the supervisory authority.

9. Your rights

Depending on where you live, you can ask to access, correct, delete, export or restrict the processing of your data, and you can object to processing based on legitimate interest. You can withdraw consent at any time, which does not affect what happened before.

Write to support@replyz.app. We answer within 30 days. If we are the processor rather than the controller, we forward the request to our customer and help them answer it, and we tell you that we have done so.

If you are in the European Economic Area or the United Kingdom, you can also complain to your local data protection authority.

10. How to delete your data

There are four routes, and all of them work.

  • Reply STOP in the conversation. Messaging ends immediately and permanently for that account.
  • Remove the app from your Instagram settings. Instagram tells us, we drop the access token and start the deletion.
  • Use the data deletion page, which also shows the status of a request by its confirmation code.
  • Write to support@replyz.app from the address on the account, or with the Instagram username involved.

Deletion is completed within 30 days. Records the law requires us to keep, invoices above all, survive the request; nothing else does.

11. Children

Replyz is a business tool and is not directed at children. You must be 18 or older to open an account. If we learn that we hold data about a child under 13, we delete it.

12. Changes and contact

When this policy changes in a way that matters, we update the date at the top and email account owners before the change takes effect. Older versions are available on request.

Questions, requests and complaints: support@replyz.app, or [legal entity], [registered address].