Privacy Policy
This Privacy Policy describes how Repyla ("we", "us", or "our") collects, uses, and shares information when you use our service at repyla.com (the "Service"). By using Repyla, you agree to the collection and use of information in accordance with this policy.
1. Information We Collect
We collect the following types of information:
- Account information: Email address and password (hashed) when you register.
- Instagram data: Your Instagram username, user ID, and OAuth access token when you connect your Instagram account. We use this to read comments on your posts (to detect trigger keywords) and to send Direct Messages on your behalf.
- Trigger and DM data: We store the keywords you define, the DM messages you configure, and a log of triggered interactions. This is necessary to prevent duplicate DMs and to show you your activity history.
- Comment data: Where you use comment engagement tools, we store relevant comment content and interaction logs within your dashboard.
- Usage data: Timestamps, trigger counts, and job logs to provide analytics within your dashboard.
- Payment information: We use Stripe to process payments. We do not store your credit card details — Stripe handles all payment data under their own privacy policy.
2. How We Use Your Information
- To provide and maintain the Service (detecting trigger keywords, sending DMs, managing your comment tools)
- To manage your account and subscription
- To show you your activity history and usage statistics
- To communicate with you about your account or the Service
- To detect and prevent abuse of our platform
3. Instagram Data Usage
Repyla connects to Instagram via Meta's official Graph API. We access the following data on your behalf:
- Your Instagram profile (username, user ID)
- Comments on your recent posts — read-only, to detect trigger keywords
- The ability to send Direct Messages triggered by keyword comments
- Comment engagement tools (read and optionally respond to comments on your posts)
We do not access your followers, your full inbox, or any data not listed above. We do not sell Instagram data to third parties.
4. Data Sharing
We share your data only in the following circumstances:
- Stripe: For payment processing
- OpenAI / Anthropic: Where AI-generated content is used, comment or message context is sent to AI providers. These providers process data under their own privacy policies.
- Meta (Instagram): As required to interact with the Instagram API
- Legal requirements: If required by law or to protect our rights
We do not sell, rent, or trade your personal data.
5. Data Retention
We retain your data for as long as your account is active. If you delete your account, we will delete your personal data within 30 days. Activity logs and interaction data are deleted immediately upon account deletion.
6. Your Rights (GDPR)
If you are located in the European Union, you have the following rights:
- Right to access your personal data
- Right to correction of inaccurate data
- Right to deletion ("right to be forgotten")
- Right to data portability
- Right to object to processing
To exercise any of these rights, contact us at privacy@repyla.com.
7. Data Deletion
You can request deletion of all your data at any time. See our Data Deletion Instructions for details.
8. Cookies
We use only essential cookies required for authentication (JWT tokens stored in localStorage). We do not use advertising or tracking cookies.
9. Security
We implement industry-standard security measures including HTTPS encryption, hashed passwords (bcrypt), and secure token handling. Instagram access tokens are stored encrypted.
10. Children's Privacy
Repyla is not directed at children under 13. We do not knowingly collect data from children. If you believe a child has provided us data, contact us immediately.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by email or via a notice in the app. Continued use of the Service after changes constitutes acceptance.
12. Contact
For privacy-related questions or requests:
- Email: privacy@repyla.com
- See also: Impressum / Legal Notice