Data We Collect
Account Information: Name, email address, and authentication credentials you provide during registration or through OAuth providers.
Google OAuth: If you sign in with Google, we receive your name, email, and profile information from Google. We do not access other Google services or data.
Instagram Data: When you connect your Instagram Business or Creator account, we access and store: username, account ID, profile information, posts, comments, messages, and follower verification data required to operate ReplyFlow automation. We only access data through the official Meta Graph API with your explicit authorization.
Campaign & Automation Data: Keyword triggers, message templates, follow-gate configurations, tracked links, DM logs, and analytics data generated from your use of the service.
Password Security
Passwords are hashed using industry-standard cryptographic algorithms (scrypt) before storage. We never store plaintext passwords. Even ReplyFlow staff cannot retrieve your original password. Password reset is the only recovery method.
How We Use Your Data
Your data is used exclusively to:
- Operate Instagram comment-to-DM automation as configured in your campaigns
- Display analytics, logs, and dashboards
- Send transactional emails (verification, password reset, service notifications)
- Improve service functionality and troubleshoot issues
- Comply with legal obligations
We do not sell your data to third parties. We do not use your Instagram content or messages for advertising, training AI models, or purposes unrelated to operating ReplyFlow.
Data Storage & Security
Data is stored in secure cloud infrastructure with encryption in transit (TLS) and at rest. Instagram access tokens are encrypted (AES-256-GCM) before database storage. We implement security best practices including access controls, rate limiting, and regular security audits.
No system is 100% secure. While we take reasonable precautions, we cannot guarantee absolute security. You are responsible for safeguarding your login credentials.
Third-Party Services
ReplyFlow integrates with:
- Meta/Instagram: To send DMs and access Instagram data per your authorization. Subject to Meta's Privacy Policy.
- Google OAuth: Optional sign-in method. Subject to Google's Privacy Policy.
- Email Provider (Nodemailer/SMTP): To send transactional emails (verification, password reset).
Each third-party service has its own privacy policy. We recommend reviewing them.
Data Retention & Deletion
We retain account data, campaign configurations, and DM logs as long as your account is active. If you delete your account, data is removed within 30 days, except where retention is required by law or for fraud prevention.
Webhook events and operational logs may be retained for up to 90 days for troubleshooting and compliance.
Your Rights
You have the right to:
- Access your data through the dashboard and account settings
- Update or correct your information
- Delete your account and associated data
- Disconnect Instagram authorization at any time
- Export campaign data (where technically feasible)
To exercise these rights, use account settings or contact support.
Children's Privacy
ReplyFlow is not intended for users under 13 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect data from children. If we learn a child has provided data, we will delete it.
Changes to This Policy
We may update this Privacy Policy. Material changes will be notified through the service or via email. The "Last updated" date reflects the most recent revision. Continued use after changes constitutes acceptance.
Contact
For privacy questions or data requests, contact us through the dashboard or support channels.

