Effective date: June 13, 2026
This Privacy Policy explains how CommentDM by Replygen ("we", "us", or "our") collects, uses, stores, and protects information when you use the CommentDM by Replygen web application at https://replygen.app/comment-dm (the "Service"). CommentDM by Replygen is operated by Replygen ("Company"), located in India.
By using the Service, you agree to the practices described in this policy. If you do not agree, please do not use the Service.
When you connect an account and activate automation flows, Meta sends webhook events to our servers. We receive and process:
We do not store the full text of DMs we send. The DM template text is set by you and stored as part of your flow configuration. Individual DM send events reference the flow ID but do not duplicate the message body.
All payment processing is handled by our payment processor, which acts as the seller of record. We receive only a subscription ID and subscription status — never your card details.
We do not sell your personal data. We share information only with the following service providers, strictly to operate the Service:
All service providers are bound by data processing agreements. We may disclose data if required by law or court order, or to protect the rights, property, or safety of the Company or its users.
CommentDM by Replygen uses the Meta Graph API under Meta's Platform Terms. We access only the permissions necessary to operate the Service:
instagram_basic — to read account details after connectioninstagram_business_manage_messages — to send DMs and receive message webhookspages_read_engagement and pages_manage_metadata — to subscribe to comment webhooks on linked Facebook Pagespages_messaging — to send Facebook Messenger DMsWe do not use these permissions for any purpose other than operating the features described in this policy. We do not scrape, aggregate, or resell Instagram or Facebook data.
You may request deletion of your account and all associated data at any time by emailing support@replygen.app. We will process deletion requests within 30 days.
If you disconnect your Instagram or Facebook account from within the dashboard, we immediately revoke the associated access token and delete all stored credentials for that account. Existing conversation log entries for that account are retained for 30 days then purged.
Per Meta's Platform Terms, we also maintain a data deletion callback endpoint at https://replygen.app/comment-dm/data-deletion. Meta may call this endpoint to request deletion of data associated with a specific Facebook user.
Depending on your location, you may have the following rights under GDPR, CCPA, or other applicable laws:
To exercise any of these rights, email support@replygen.app. We will respond within 30 days.
Meta access tokens are stored encrypted at rest. We use HTTPS for all data in transit. Access to production data is restricted to authorized personnel only. We conduct periodic reviews of our security practices.
Despite these measures, no system is completely secure. If you become aware of any security issue, please report it to support@replygen.app immediately.
The Service is not directed to children under 13 (or 16 in the EU). We do not knowingly collect personal data from children. Contact us at support@replygen.app if you believe a child has provided us with personal data.
Our infrastructure is primarily located in the United States and European Union. If you access the Service from outside these regions, your data may be transferred internationally. All transfers are subject to appropriate safeguards including Standard Contractual Clauses where required.
We may update this Privacy Policy from time to time. Material changes will be communicated by updating the effective date above and, where appropriate, by email. Continued use of the Service after changes constitutes acceptance.
For privacy questions, data requests, or Meta data deletion requests:
CommentDM by Replygen (operated by Replygen)
India
Email: support@replygen.app
Data deletion callback: https://replygen.app/comment-dm/data-deletion