Privacy policy
Last updated October 6, 2026
Replyooo (“we”) runs Replyooo, a tool that replies to Instagram and Facebook comments and messages for the businesses and creators who connect their accounts (“customers”). This policy explains what we collect, why, and how to get it deleted.
What we collect
- Customer accounts: name, email address, password (stored hashed) or Google sign-in, and workspace membership.
- Connected Instagram and Facebook accounts: account ID, username, name, profile picture, follower count and the access token Meta issues (encrypted with AES-256-GCM).
- People who interact with a connected account (“contacts”): their Instagram or Facebook ID, username, name and profile picture, the comments and messages they send to that account, the replies Replyooo sends, and any email address or phone number they choose to share in the conversation.
- Billing: plan, subscription status and the customer ID from Dodo Payments. We never see or store card details.
How we use it
Only to provide the service our customers set up: matching comments and messages to their automations, sending the replies they wrote, showing their contacts and conversation history in the dashboard, counting usage for billing, and emailing customers about their account (verification, password resets, invitations, and when Meta needs them to reconnect). We don’t sell personal data, use it for advertising, or combine data from different customers.
Data from Meta
We use Instagram and Facebook Platform data only to operate the features the connected account’s owner turned on, in line with Meta’s Platform Terms. Access ends when the owner disconnects the account in Replyooo or removes Replyooo in their Instagram or Facebook settings.
Who processes it for us
- Our hosting provider, which runs our servers and database.
- Dodo Payments, our merchant of record, for subscriptions and invoices.
- Our email provider (Resend or our SMTP provider), to deliver account emails.
- Meta, to receive and send the messages and comments themselves.
How long we keep it
Raw webhook deliveries from Meta are deleted after 30 days. Everything else is kept until the customer deletes it, deletes their workspace, or the account owner asks Meta to delete their data. Deleting a workspace removes its connected accounts, contacts, messages and automations immediately. When Meta sends us a deletion request, we keep a record of it (the confirmation code, the Meta user ID it named, when it arrived and how many accounts were deleted) so we can show its status and prove it was handled.
Your choices
Contacts can ask the business they messaged, or us, to delete what we hold about them. Account owners can delete their data at any time; see how to delete your data. Write to privacy@replyooo.com for any privacy request; we answer within 30 days.
Security
Access tokens are encrypted at rest, passwords are hashed, every request is checked against the signed-in workspace, and Meta’s webhooks are verified by signature before we process them.
Changes
We’ll update the date above when this policy changes, and email customers about material changes.