🔒 Your Privacy Matters

Privacy Policy

We're committed to transparency. This policy explains exactly what data we collect, why we need it, and how we protect it.

Effective Date: July 13, 2026
Last Updated: July 13, 2026
Applies to: Replyly.io App & Services
1

Who We Are

Replyly.io ("we", "our", or "us") is an Instagram automation platform that helps content creators and businesses automate direct message replies, comment responses, and audience engagement workflows on Instagram.

This Privacy Policy governs your access to and use of our mobile application, web dashboard, and associated backend services (collectively, the "Service"). By using Replyly.io, you agree to the collection and use of information in accordance with this policy.

Legal Basis

We process your personal data on the basis of your explicit consent (provided when connecting your Instagram account), contractual necessity (to deliver the Service you subscribe to), and legitimate interest (to maintain security and improve our platform).

2

Data We Collect

We collect only the minimum data required to provide the Service. Below is a complete breakdown of every category of data we may collect.

📱
Instagram Account Data
Your Instagram User ID, username, display name, and account type (business/creator).
🔑
Access Tokens
Instagram OAuth access tokens that allow us to send DMs and read comments on your behalf.
📧
Google Account Info
Your Google account email address and display name, used for account identification and login.
🔔
Device Token (FCM)
Your device's Firebase Cloud Messaging token, used to deliver push notifications to your device.
⚙️
Automation Configuration
Your automation rules, message templates, trigger keywords, and flow settings you configure.
💳
Subscription & Credits
Your subscription tier, credit balance, and transaction history related to our paid features.
📊
Usage Logs
Logs of automation events such as DMs sent, comments replied to, and webhook triggers received.
🌐
Technical Data
IP address, device type, OS version, and app version data collected for security and diagnostics.

What We Do NOT Collect

We do not collect, read, or store the content of your private Instagram messages or your followers' personal data. We do not store passwords. We do not use cookies for tracking. We do not sell your data to any third party.

3

How We Use Your Data

Your data is used strictly for the following purposes:

  • Service Delivery: Executing your configured automation workflows — sending DMs, replying to comments, and managing follow-up sequences on your Instagram account.
  • Account Authentication: Verifying your identity via Google Sign-In and maintaining your session securely.
  • Instagram API Communication: Using your access token to interact with Instagram's Graph API on your behalf, only as directed by your automation rules.
  • Push Notifications: Sending you app alerts and important updates via Firebase Cloud Messaging using your device token.
  • Subscription Management: Tracking your subscription plan, credit balance, and processing billing-related events.
  • Security & Fraud Prevention: Monitoring for unusual activity, protecting our platform from abuse, and maintaining audit logs.
  • Service Improvement: Analyzing aggregated, anonymized usage patterns to improve reliability and performance of the Service.
  • Customer Support: Using account information to respond to your support inquiries effectively.

No Profiling or Selling

We never use your data to build advertising profiles. We never sell, rent, or lease your personal information to any third party for commercial purposes.

4

Data Storage & Security

All data is stored and processed using enterprise-grade, globally distributed infrastructure. We implement multiple layers of security:

  • Encryption in Transit: All data transmitted between your device, our servers, and third-party APIs is encrypted using TLS 1.2/1.3.
  • Encryption at Rest: Your access tokens and sensitive account data are stored in encrypted databases (Cloudflare D1 with AES-256 encryption at the infrastructure level).
  • Secrets Management: API keys, private keys, and service credentials are stored as encrypted secrets via Cloudflare's secrets management system — never in source code or plain configuration files.
  • Access Controls: Backend API endpoints are protected by API key authentication. Only authorized service components can access user data.
  • Token Security: Instagram access tokens are stored securely and are never exposed in frontend code, logs, or error messages.
  • Edge Security: Our backend runs on Cloudflare's global edge network, which provides built-in DDoS protection and WAF capabilities.

Important Notice

While we implement industry-standard security measures, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security. In the event of a data breach affecting your rights and freedoms, we will notify you as required by applicable law.

5

Instagram & Meta Platform Data

Replyly.io integrates with the Meta (Instagram) Graph API. By connecting your Instagram account, you grant us access to specific permissions as outlined during the OAuth authorization flow. We only request the permissions strictly necessary to operate the features you use.

  • We act as a data processor on behalf of Meta's platform policies. Your use of Replyly.io is also subject to Meta's Terms of Service and Privacy Policy.
  • We do not share your Instagram data with other users of Replyly.io or any third-party advertisers.
  • We do not use your Instagram data to train machine learning models.
  • You can revoke Replyly.io's access to your Instagram account at any time via your Instagram Settings → Apps and Websites.
  • Upon revocation, we will promptly delete your stored access token and cease all automated actions on your account.

Meta Platform Policy Compliance

Replyly.io operates in accordance with the Meta Platform Terms and Developer Policies. We do not scrape, crawl, or collect data beyond what is explicitly authorized through the official Meta Graph API and Instagram Messaging API.

6

Third-Party Services

We use the following third-party services to power Replyly.io. Each of these services has its own privacy policy governing their use of your data:

Service Purpose Data Shared Policy
Cloudflare Backend infrastructure, edge network, DDoS protection, database (D1) All backend traffic, stored user records View Policy ↗
Meta (Instagram) Instagram automation via Graph API and Messaging API Instagram User ID, username, access token View Policy ↗
Google Firebase Push notifications (FCM), authentication Device FCM token, Google account email & name View Policy ↗
Google Sign-In User account authentication Google account ID, email, display name View Policy ↗
SendGrid (Twilio) Transactional email notifications (alerts & system emails) Email address View Policy ↗

We enter into Data Processing Agreements (DPAs) with sub-processors where required under applicable data protection law.

7

Your Rights

Depending on your country of residence, you may have the following rights regarding your personal data. We will respond to all valid requests within 30 days.

👁️
Right to Access
Request a copy of all personal data we hold about you in a machine-readable format.
✏️
Right to Rectification
Request correction of inaccurate or incomplete personal data we hold about you.
🗑️
Right to Erasure
Request deletion of your personal data ("right to be forgotten"), subject to legal obligations.
⏸️
Right to Restriction
Request that we restrict the processing of your personal data in certain circumstances.
📦
Right to Portability
Receive your data in a structured, commonly used format to transfer to another service.
🚫
Right to Object
Object to processing of your personal data based on our legitimate interests.
🔙
Right to Withdraw Consent
Withdraw your consent at any time without affecting the lawfulness of prior processing.
⚖️
Right to Complain
Lodge a complaint with your local data protection authority if you feel your rights are violated.

To exercise any of these rights, please contact us at privacy@replyly.io. We may ask you to verify your identity before processing your request.

8

Data Retention

We retain your data for the following periods:

  • Active Account Data (Instagram tokens, account info, automation configs): Retained for the duration of your account and 90 days after account deletion or disconnection.
  • Automation Logs & Event History: Retained for 30 days for active accounts, then automatically purged.
  • Transaction & Billing Records: Retained for 7 years as required by financial and tax regulations.
  • Security Logs & Audit Trails: Retained for 90 days to detect and investigate security incidents.
  • Device FCM Tokens: Retained while you have an active account. Automatically invalidated when you uninstall the app or revoke permissions.
  • Deleted Account Data: Upon account deletion request, all personal data is removed within 30 days, except where retention is legally required.
9

Push Notifications

Replyly.io uses Firebase Cloud Messaging (FCM) to send push notifications to your mobile device. These notifications may include:

  • Alerts about your automation activity (e.g., automation paused due to token expiry)
  • Account and billing notifications (e.g., subscription renewal, credit low)
  • Service status updates and announcements
  • Promotional notifications about new features (with your permission)

We collect and store your device's unique FCM registration token to deliver these notifications. This token identifies your device — it does not contain any personally identifiable information by itself.

Opt Out Anytime

You can disable push notifications at any time through your device's system settings (iOS: Settings → Notifications → Replyly / Android: Settings → Apps → Replyly → Notifications). Disabling notifications will not affect the functionality of your automations.

10

Payments & Credits

Replyly.io operates a credit-based subscription model. When you make a purchase or earn credits (through referrals, promotions, or ad rewards), we record these transactions in our systems.

  • Payment Processing: All payment transactions are processed by third-party payment gateways (such as Razorpay or Stripe). We do not store your full credit card numbers, CVV, or banking details on our servers.
  • Credit Ledger: We maintain a credit ledger recording every credit transaction (earned, spent, or expired) associated with your account, including the reason for the transaction (e.g., referral bonus, ad reward, subscription payment).
  • Referral Data: If you refer another user to Replyly.io, we associate the referral with your account to award credits. We store only the User ID of the referred user, not their personal details.
  • Transaction History: You can view your complete credit and transaction history within the Replyly app.
11

Children's Privacy

Replyly.io is not directed to children under the age of 13 (or under 16 in certain jurisdictions, such as the European Union). We do not knowingly collect personal information from children.

If you are a parent or guardian and believe your child has provided us with personal information without your consent, please contact us immediately at privacy@replyly.io. We will promptly delete such information from our systems.

By using Replyly.io, you represent that you are at least 13 years of age (or 16 years in the EU) and have the legal capacity to enter into this agreement.

12

International Users & Data Transfers

Replyly.io is operated on Cloudflare's global edge network, meaning your data may be processed in data centers around the world, including countries outside your country of residence.

  • EU/EEA Users: If you are located in the European Union or European Economic Area, your data may be transferred to and processed in countries that do not have the same level of data protection as your home country. We ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) where required.
  • Indian Users: We comply with applicable provisions of India's Digital Personal Data Protection Act (DPDPA), 2023.
  • California Residents (CCPA): You have the right to know what personal information we collect, to delete your personal information, and to opt-out of the sale of personal information (we do not sell personal information). To exercise CCPA rights, contact us at privacy@replyly.io.
13

Android App Permissions

The Replyly Android app requests the following system permissions. We request only what is strictly necessary to provide the Service. You can manage these permissions at any time in your device's Settings → Apps → Replyly → Permissions.

Permission Why We Need It Type
INTERNET Required to connect to the Replyly backend servers and the Instagram Graph API. Without this, the app cannot function. Required
POST_NOTIFICATIONS Required on Android 13+ (API 33+) to show you push notifications about your automation activity, account alerts, and subscription status. Required
RECEIVE_BOOT_COMPLETED Allows the app to restart background services after the device reboots, ensuring your automation monitoring continues uninterrupted. Optional
VIBRATE Allows the device to vibrate when a push notification is received, for tactile notification alerts. Optional
ACCESS_NETWORK_STATE Allows the app to check whether a network connection is available before making API requests, improving error handling. Optional

No Sensitive Permissions

Replyly does not request access to your camera, microphone, contacts, precise location, files/storage, call logs, SMS, or any other sensitive Android permissions. Our functionality is entirely API-based and does not require access to your device's hardware sensors or local data.

14

Google Play Store Data Safety

The following reflects the information declared in the Google Play Store Data Safety section for the Replyly app. This information is provided for transparency and to help you understand our data practices at a glance.

Data Collected
Yes
Account info, device ID, app activity
Data Shared with Third Parties
Yes
Firebase, Meta API only (see Section 6)
Data Used for Advertising
No
We never use your data for ads
Data Sold
No
We never sell personal data
User Can Request Deletion
Yes
Via app settings or email request
Data Encrypted in Transit
Yes
TLS 1.2/1.3 on all connections
In-App Purchases
Yes
Subscriptions & credits via Play Billing
App Targets Children
No
18+ only, business use

Data types collected and their purposes as declared in Play Store:

  • Name & Email Address — Account management (Google Sign-In). Not shared with third parties beyond Firebase Auth.
  • User IDs — Required for account identification and linking your Instagram account. Collected and shared with our backend servers.
  • App Interactions — Automation event logs used to display your activity history within the app. Not shared externally.
  • Device or Other IDs (FCM Token) — Used exclusively for sending push notifications to your device via Firebase Cloud Messaging. Not used for tracking or advertising.
  • Purchase History — In-app subscription and credit purchase records, processed via Google Play Billing. Transaction data is handled by Google Play; we receive only purchase confirmation signals.
  • App Info & Performance — Crash logs and diagnostics collected to improve app stability. Anonymized and not linked to personal identity.

Play Store Data Safety Form Alignment

The data declared in the Google Play Store Data Safety section is consistent with this Privacy Policy. If you notice any discrepancy, please contact us at privacy@replyly.io so we can correct it promptly.

15

Account & Data Deletion

In compliance with Google Play's policy (effective May 2024) and Meta's Platform Policies, users can request deletion of their account and all associated data. You have multiple ways to do this:

🗑️
Request Data Deletion Online
Visit our dedicated deletion page for a step-by-step guide, deletion timeline, and to track your request status.
Delete My Data →
  • Via the App: Go to Replyly App → Profile → Account Settings → Delete Account. This initiates an immediate deletion request from within the app.
  • Via Email: Send a deletion request to privacy@replyly.io from your registered email address.
  • Via Facebook/Instagram: Remove Replyly from your Facebook connected apps (Settings → Apps and Websites) and select "Delete all information" to trigger our automated deletion callback.

All deletion requests are processed within 30 days. You will receive a written confirmation email once your data has been permanently removed. Certain financial records may be retained for up to 7 years as required by law — see our Data Deletion page for the full breakdown.

16

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or for other operational reasons. When we make material changes, we will:

  • Update the "Last Updated" date at the top of this policy
  • Send a push notification to your device (if you have notifications enabled)
  • Display a prominent notice in the Replyly app
  • Require your re-acknowledgment for any changes that materially reduce your privacy rights

Your continued use of Replyly.io after the effective date of the updated policy constitutes your acceptance of the revised policy. We encourage you to review this page periodically.

17

Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please reach out to our dedicated privacy team:

  • Privacy Inquiries: privacy@replyly.io
  • General Support: support@replyly.io
  • Data Deletion: data-deletion page or privacy@replyly.io
  • Website: https://replyly.io
  • Response Time: We aim to respond to all privacy requests within 5 business days and resolve them within 30 calendar days.

Have a privacy question?

Our team is here to help. We'll respond within 5 business days.

📧 privacy@replyly.io
📜 Terms of Service 🗑️ Data Deletion