Privacy Policy
How Replyrr handles the information needed to connect Instagram accounts, run automations and AI agents, manage billing, and measure service reliability.
Scope and contact
This policy covers the Replyrr website, dashboard, Instagram automations, Inbox, Builder, AI Agent, analytics, and related support. It does not replace the privacy notices of Meta, Instagram, Clerk, Dodo Payments, OpenAI, Vercel, or Google when those companies process information under their own terms.
Questions and privacy requests can be sent to privacy@replyrr.com.
Information Replyrr processes
- Account data: your name, email address, Replyrr and Clerk account identifiers, sign-in state, and account timestamps.
- Instagram connection data: the professional account ID and username, access token, token expiry, connected media IDs, captions, media URLs and types, and selected posts.
- Automation data: automation names, keywords, triggers, schedules, message text, buttons, links, templates, flow steps, AI instructions, business information, and Inbox Starters.
- Instagram interaction data: app-scoped contact IDs, messages, comments, replies, message and comment IDs, story or share events, timestamps, delivery results, profile details returned by Meta, and follow-relationship fields when available.
- Lead data: names, email addresses, phone numbers, custom answers, consent text, and consent timestamps when an account owner configures a flow to collect them.
- Billing data: plan, checkout, customer, subscription and payment identifiers, status, currency, billing period, and billing-event data received from Dodo Payments. Replyrr does not store full payment-card details in its application database.
- Usage and technical data: dashboard paths, browser user agent, link destinations, click timestamps, referring page, automation outcomes, response times, error details, and security or webhook diagnostics.
- Support data: the messages and contact details you include when asking Replyrr for help or making a privacy request.
Where the information comes from
Replyrr receives information:
- directly from you when you create and configure the Service;
- from Clerk when you authenticate;
- from Meta and Instagram after you authorize an Instagram Professional Account and as Instagram users interact with it;
- from Dodo Payments when you start or manage a subscription; and
- from your browser or device when you use the website, dashboard, or a Replyrr tracking link.
AI features and uploaded files
If you enable or test an AI Agent or ask for an Inbox suggestion, Replyrr sends the current message, a limited recent conversation history, your AI configuration, and relevant knowledge text to OpenAI so that OpenAI can generate a response. Do not place information in an AI instruction, knowledge file, or conversation unless you are authorized to process and send it for that purpose.
Knowledge files and Builder images are stored in Vercel Blob as public-access objects with randomized, unlisted URLs. Anyone who obtains such a URL may be able to retrieve the object. Do not upload passwords, access tokens, government identifiers, financial-account details, health information, or other confidential or sensitive material.
How Replyrr uses information
- authenticate users and maintain Replyrr accounts;
- connect, refresh, and operate authorized Instagram accounts;
- match triggers, send replies, run flows, manage human takeover, and display conversation history;
- generate AI replies and suggestions when those features are used;
- process subscriptions, enforce plan limits, and reconcile billing;
- provide analytics, attribute tracked-link clicks, troubleshoot errors, prevent duplicate events, and improve reliability;
- protect the Service against fraud, abuse, and forged webhooks; and
- respond to support, privacy, and legal requests.
Replyrr does not sell Meta Platform Data or use it for third-party behavioral advertising.
Service providers and disclosures
Replyrr uses the following providers to operate the Service:
- Meta and Instagram for authorization, webhooks, account information, messaging, comments, and media APIs;
- Clerk for authentication and identity management;
- Dodo Payments as payment provider and merchant of record for checkout, subscriptions, invoices, tax, and payment administration;
- OpenAI to generate AI responses and suggestions when an AI feature is invoked;
- Vercel for application hosting, file storage, analytics, and performance measurement; and
- Google Analytics for website-usage analytics.
Replyrr may also disclose information when required to comply with law, protect users or the Service, or investigate abuse.
Analytics and browser technologies
The website loads Google Analytics after a user interaction or a short delay, and uses Vercel Analytics and Speed Insights. These services may receive device, browser, page, performance, and network information and may use cookies or similar identifiers under their own policies. The dashboard also records a limited session event with the visited path and browser user agent. You can use browser controls, content blockers, or provider opt-out tools to limit analytics technologies.
Retention
- Raw Instagram webhook payloads, which can contain message and comment text, are redacted after 48 hours. The remaining event rows are deleted after 30 days.
- Short previews of a comment and the reply sent to it are stored on the matching activity record so you can see what your automations actually said. These previews are redacted on the same 48-hour schedule as the raw payloads they come from; the activity record itself, without that text, remains for 30 days.
- Webhook de-duplication identifiers are deleted after 48 hours.
- Conversation history, contacts, leads, flow sessions, automations, account analytics, and uploaded content otherwise remain associated with the Replyrr account until you delete them or delete the account; they do not currently have a separate automatic expiry.
- Billing, identity, hosting, AI, and analytics providers may retain records under their contracts, security practices, and legal obligations. Dodo Payments may retain invoices, tax, and transaction records after a Replyrr account is deleted.
Disconnecting and deleting data
Disconnecting Instagram in Replyrr, or removing Replyrr in Instagram settings, revokes or removes the connection used for future API access. It does not by itself delete information already stored in the Replyrr account.
To delete the Replyrr account and associated application data, use the self-service process at replyrr.com/delete or email hello@replyrr.com from the registered address if you cannot sign in. Self-service deletion first confirms that active billing has stopped, then hard-deletes the account's Postgres records. It also attempts to remove associated Vercel Blob objects, matching raw webhook logs, and the Clerk identity. Provider backups, security logs, and records a provider or law requires to retain may remain for the applicable retention period.
Security
Replyrr uses authenticated server-side operations, authorization checks, webhook-signature verification, scoped access controls, and retention jobs to protect information. No network, database, or storage system is completely secure, so Replyrr cannot guarantee absolute security.
Your choices and rights
Depending on where you live, you may have rights to request access, correction, deletion, restriction, objection, or portability of personal information. You may also disconnect Instagram, change or remove automation content, and delete your Replyrr account. Send a request to privacy@replyrr.com. Replyrr may need to verify your identity before completing a request.
Changes and contact
Replyrr may update this policy as the Service or legal requirements change. The current version and its update date will remain available on this page. Questions can be sent to privacy@replyrr.com.
