Last updated September 13, 2026

Privacy Policy

OpenReply helps businesses send Meta-compliant private replies when people comment on connected Instagram posts or reels.

Data We Collect

We collect account email addresses for authentication, workspace and billing metadata, connected Instagram account identifiers, encrypted Instagram access tokens, campaign settings, webhook payloads, comments needed to process campaigns, delivery logs, and operational diagnostics.

How We Use Data

We use this data to authenticate users, connect Instagram integrations, match comment keywords, send private replies through the official Meta APIs, prevent duplicate sends, troubleshoot failures, and protect the service.

Instagram And Meta Data

OpenReply does not ask for Instagram passwords, scrape Instagram, or use browser automation. Instagram tokens are encrypted at rest and are used only to perform actions authorized by the connected business account.

Subprocessors

This self-hosted installation uses a dedicated server, PostgreSQL, Redis, and Resend for sign-in emails. These services process data as needed to operate this installation.

Retention And Deletion

Customers can disconnect Instagram from settings, which removes the stored Instagram connection and stops campaigns. For account or data deletion, follow the Data Deletion page linked from the footer.

Contact

For privacy questions, send a Direct message to the Instagram profile you interacted with. Include your Instagram username and your request so the team responsible for that profile can assist you.