Last updated: October 3, 2026
This Privacy Policy describes how GiveReply ("we", "us", or "our") collects, uses, and discloses your information when you use our website and services at givereply.com (the "Service"). By using the Service, you agree to the collection and use of information in accordance with this Privacy Policy.
1. Information We Collect
1.1 Account Information
When you create an account, we collect:
- Email address
- Name (if provided)
- Password (stored in hashed form)
1.2 Instagram Account Data
When you connect your Instagram Professional or Business account via OAuth, we collect and store:
- Instagram User ID — Your Instagram Business Account ID, used to match incoming webhook events to your account
- Username — Your Instagram handle, displayed in our dashboard
- Profile Picture URL — Displayed in your dashboard
- Access Token — A long-lived token issued by Meta, used to send Direct Messages and read comments on your behalf. Stored securely and encrypted at rest.
1.3 Comment & Messaging Data
To provide our automation service, we process:
- Comments on your Instagram posts/reels — We receive these via Meta Webhooks to check against your configured automation keywords
- Direct Messages — We send automated DMs on your behalf based on your automation rules. We log the message content, recipient, and delivery status.
- Commenter/Recipient info — Instagram-scoped user ID and username of people who interact with your content, stored as contacts in your CRM.
1.4 Usage & Analytics Data
We automatically collect basic usage data such as pages visited, feature usage, and error logs to improve the Service.
2. How We Use Your Data
We use the information we collect to:
- Provide, operate, and maintain the Service
- Process Instagram comments and send automated Direct Messages as configured by you
- Store your contacts and message history for your CRM dashboard
- Process payments and manage your subscription
- Send you important notifications about your account or the Service
- Improve and develop new features
3. Data Sharing
We do not sell, rent, or trade your personal data. We share data only with:
- Meta/Instagram — To send DMs and read comments via the Instagram Graph API, as authorized by you
- Supabase — Our database provider, for secure data storage
- Upstash — For message queue processing and rate limiting
- Razorpay — For payment processing (Pro plan only)
- Cloudflare — For hosting and content delivery
4. Data Retention
We retain your data for as long as your account is active or as needed to provide the Service. Specifically:
- Account data — Retained until you delete your account
- Message logs — Retained for 90 days, then automatically purged
- Contact data — Retained until you delete your account or remove individual contacts
- Instagram access tokens — Retained until you disconnect your Instagram account or delete your account
5. Data Deletion
You can request deletion of your data in the following ways:
- In-App: Go to Dashboard → Settings → Delete Account. This permanently deletes all your data including workspaces, automations, contacts, message logs, and your account.
- Via Instagram/Facebook: When you remove GiveReply from your Instagram or Facebook connected apps, we automatically receive a data deletion callback and remove all associated data.
- Via Email: Contact us at [email protected] to request data deletion. We will process your request within 30 days.
6. Security
We take the security of your data seriously:
- All data is transmitted over HTTPS/TLS encryption
- Instagram access tokens are stored securely in our database
- Webhook payloads are verified using HMAC-SHA256 signature verification
- Payment processing is handled by PCI-compliant Razorpay — we never store card details
- API endpoints are protected with authentication and rate limiting
While we strive to use commercially acceptable means to protect your data, no method of electronic storage or transmission is 100% secure.
7. Third-Party Services
Our Service integrates with Meta's Instagram API. Your use of Instagram is subject to Meta's Privacy Policy. We only access Instagram data that you explicitly authorize during the OAuth connection flow.
8. Children's Privacy
Our Service is not intended for anyone under the age of 18. We do not knowingly collect personal information from children under 18.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the updated policy on this page and updating the "Last updated" date.
10. Contact Us
If you have any questions about this Privacy Policy or wish to exercise your data rights, contact us: