ReplySuit ("ReplySuit", "we", "us") helps Instagram and Facebook professional account owners reply automatically to comments and messages based on rules they configure. This policy explains what data we process, why, and how to delete it.
Contact: replysuitsupport@gmail.com
1. Information you give us
- Sign-in details. When you sign in with Google we receive your email address, first and last name, and profile picture URL. We do not receive or store your Google password.
- Contact details. If you submit an upgrade request or support ticket, we store the name, phone number, country code, and email address you enter.
- Billing references. If you subscribe to a paid plan, we store the subscription identifier and status returned by our payment processor. We never see or store your card details.
2. Information from the accounts you connect
When you connect an Instagram professional account or a Facebook Page, we store:
- the Instagram user ID or Facebook Page ID, and the username or Page name;
- an access token issued by Meta, which lets us receive events and send replies on your behalf. Access tokens are encrypted at rest using AES-256-GCM and are never displayed or exported.
You can disconnect an account at any time, which revokes our ability to act on it.
3. Information about people who interact with your content
To run the automations you configure, we receive and store data about people who comment on or message your account:
| Data | Why we need it |
|---|---|
| Comment ID, media ID, comment text | To match the comment against your rules and to avoid replying to the same comment twice |
| Commenter's platform-scoped ID and username | To send the private reply and to enforce sending limits |
| Message ID, message text, story ID | To match direct messages, story replies, story mentions, and shared posts against your rules |
| Contact record (interaction counts, last comment, last rule matched) | To show you your leads and to prevent repeatedly messaging the same person |
| Delivery records (recipient ID, status, errors) | To show delivery results and to enforce Meta's messaging rules |
These people are not our users. You are the controller of this data — we process it on your instructions, solely to deliver the replies you configured. You are responsible for ensuring your use of ReplySuit complies with applicable law and with Meta's Platform Terms.
4. Content you create
Your automation rules, keywords, reply templates, attachment links, and any posts or media you schedule through ReplySuit.
5. How we use your data
Solely to operate the service you configured: matching comments and messages against your rules, sending the replies you set up, showing you results, enforcing plan limits, and providing support.
We do not sell your data. We do not use it for advertising. We do not use it to train machine-learning models.
6. Who we share it with
| Recipient | Purpose |
|---|---|
| Meta (Instagram & Facebook Platform APIs) | To receive comment and message events and to send replies on your behalf |
| Sign-in only. We receive your basic profile; Google does not receive your ReplySuit activity | |
| Our payment processor | To take subscription payments, if you are on a paid plan |
| Our email provider | To send transactional email such as password resets and support replies |
We do not share your data with anyone else, except where we are legally required to.
7. How long we keep it
- While your account is active — so the service can work and you can see your history.
- On disconnecting an account — its rules, contacts, events, and delivery logs are deleted.
- On deleting your account — all of the above is deleted.
- Encrypted backups are retained for a rolling period and then overwritten, so deleted data may persist in backups for a short time after deletion.
8. Deleting your data
You can disconnect accounts and delete rules and logs from your dashboard at any time. For full deletion, see our data deletion page.
9. Security
Access tokens are encrypted at rest. All traffic to ReplySuit uses HTTPS. Access to production systems is restricted. No system is perfectly secure, but we take reasonable measures appropriate to the sensitivity of the data.
10. Your rights
You may request access to, correction of, or deletion of your personal data by emailing replysuitsupport@gmail.com. If someone who commented on your content wants their data removed, they should contact you as the account owner, or write to us and we will assist.
11. Children
ReplySuit is a business tool and is not intended for anyone under 18.
12. Changes
If we change this policy we will update the date above and, for significant changes, notify you in the app or by email.