Last updated August 28, 2026

Privacy Policy

OpenReply helps businesses send a private reply when someone comments on their own Instagram posts and reels or their own Facebook Page posts and Reels.

Data We Collect

From the business using OpenReply:

  • The email address used to sign in, and workspace, team member, and billing metadata.
  • Connected account identifiers, meaning the Instagram professional account ID and username or the Facebook Page ID and name, together with the access token for that account, encrypted at rest.
  • Campaign settings: keywords, targeted posts, message templates, and tracked link destinations.

From people who interact with the connected accounts:

  • The webhook payloads Meta delivers, and the comment that triggered a campaign, including the comment and post IDs and the comment text.
  • The commenter's platform-scoped ID and display name, which are what the platform requires to address a private reply, plus the messaging conversations the business reads and answers in the dashboard.
  • Delivery logs recording each send, skip, and failure with its reason, and, where a campaign uses a tracked link, click records containing a hashed IP address, the user agent, and the referrer.

How We Use Data

We use this data to authenticate users, connect Instagram and Facebook integrations, match comment keywords, send private replies and optional public replies through the official Meta APIs, prevent duplicate sends, report campaign results to the business, troubleshoot failures, and protect the service. We do not sell this data, use it for advertising, or use it to build profiles of the people who comment.

Instagram And Meta Data

OpenReply does not ask for Instagram or Facebook passwords, scrape either platform, or use browser automation. It acts only through the official APIs, and only within the permissions the business granted at authorization. Access tokens for Instagram professional accounts and Facebook Pages are encrypted at rest with AES-256-GCM and are used only to perform actions the connected business account authorized. Incoming webhooks are signature-verified before they are processed.

Data obtained from Meta is used to deliver the feature the business asked for and is not shared with third parties beyond the infrastructure providers named below.

Subprocessors

The hosted service runs on Cloudflare Workers with a PostgreSQL database, and uses an email provider to send sign-in links and invitations. These providers process data only as needed to run the service.

Retention And Deletion

A business can disconnect an Instagram account or a Facebook Page from Settings at any time. That deletes the stored token for it immediately and stops its campaigns. For deletion of workspace, campaign, comment, messaging, and log data, follow the Data Deletion page, which lists exactly what a deletion request covers.

Self-Hosted Instances

OpenReply is open source and can be deployed by anyone on their own infrastructure. This policy describes the hosted service we operate. On an instance run by someone else, that operator controls the database and is the party responsible for the data in it.

Contact

For privacy questions or deletion requests, email privacy@getrecite.app.