Last updated September 14, 2026

Privacy Policy

This OpenReply instance sends Meta-compliant private replies when people comment on the connected Instagram posts or reels.

Who Is Responsible

This instance is a private deployment, run by the operator of the connected Instagram professional accounts and reachable at the address below. It is not a hosted service offered to third parties, and it has no customers, subscriptions, or billing.

For any question about your data, or to exercise the rights described below, write to alberto.devtools@gmail.com.

Data We Collect

If you comment on one of the connected posts or send a direct message to one of the connected accounts, this instance processes your Instagram username and account identifier, the text of your comment or message, the replies sent to you, delivery logs, and — where tracked links are used in a campaign — the fact that a link was clicked.

For the operator account itself, it stores an email address for authentication, the connected Instagram account identifiers, encrypted Instagram access tokens, campaign settings, and operational diagnostics.

How We Use Data

This data is used to match comment keywords, send private replies through the official Meta APIs, prevent duplicate sends, troubleshoot failures, and protect the service. It is not sold, and it is not used to build advertising profiles.

Instagram And Meta Data

OpenReply does not ask for Instagram passwords, scrape Instagram, or use browser automation. Instagram tokens are encrypted at rest and are used only to perform actions authorized by the connected business account.

Where Data Is Stored

The application and its database run on a single private server operated by the controller, located in France. Meta is the source of the comments and the channel for the replies. Resend delivers the sign-in emails for the operator account. There are no other processors: this instance does not use Vercel, Railway, or any managed platform provider.

Retention And Deletion

Comment and message records are kept only as long as they are needed to run and audit the automation. You can ask for your data to be deleted at any time — see the Data Deletion page linked from the footer, or write to alberto.devtools@gmail.com.

Your Rights

You may request access to your data, its correction or deletion, a restriction of its processing, or object to the processing altogether. Write to alberto.devtools@gmail.com and the request will be answered. If you believe your request has not been handled properly, you can lodge a complaint with your national data protection authority — in Spain, the Agencia Española de Protección de Datos.

Contact

alberto.devtools@gmail.com