Privacy Policy
Last updated: August 19, 2026
ReplyMagnet ("we", "us") helps creators and businesses automatically respond to comments on their own Instagram posts and LinkedIn Company Page posts, and deliver the content a commenter asked for. This policy explains what we collect, why, and the controls you and your audience have. It applies to the ReplyMagnet web app and to data we process through Instagram's and LinkedIn's official APIs.
What we collect from creators (our customers)
- Account details: name, email address, and password hash (via our auth provider).
- A mobile phone number, only if you choose to share it (for example during onboarding) and consent to receiving occasional ReplyMagnet product updates on WhatsApp. It is never required, never sold or shared, and you can opt out or have it deleted anytime by emailing privacy@replymagnet.app.
- Instagram professional account data you authorize through Instagram's consent screen: your account ID, username, account type, follower count, profile picture, your posts' metadata (captions, counts), and an access token we store encrypted.
- LinkedIn Company Page data you authorize through LinkedIn's consent screen: the organization ID and name of a page you administer, your page's own posts, and an access token we store encrypted. We only ever access pages you administer.
- Campaign configuration you create: trigger keywords, reply text, DM text, attached files.
- Usage and billing metadata: DM counts, plan, and event logs that power your analytics.
What we collect about commenters (your audience)
When someone interacts with an automated campaign, we process the minimum needed to run the flow the creator configured:
- Their username or name, and their platform ID (an Instagram-scoped ID, or a LinkedIn member URN).
- The text of the comment that matched a trigger keyword.
- Whether they follow the creator — on Instagram, a yes/no from Instagram's API and nothing more; on LinkedIn, only whether they clicked a "follow" link we showed them, since LinkedIn provides no way to verify a follow.
- An email address and/or a mobile phone number, only if they voluntarily submit them on a download page (which details are asked for depends on how the creator configured the campaign).
- Delivery events (DM sent, reply posted, link clicked, file downloaded) tied to the campaign.
We never see anyone's password, private messages outside the automated conversation, or their activity elsewhere on Instagram or LinkedIn.
LinkedIn data, specifically
LinkedIn sets its own limits on what we may keep about a person who comments on a page, and we apply them to every LinkedIn campaign:
- A commenter's name is kept for at most 24 hours, then permanently erased from our records. After that the engagement remains in the page owner's history, but the person is shown only as "LinkedIn member".
- The text of a comment is kept for at most 48 hours, then permanently erased.
- LinkedIn member data is never exported out of ReplyMagnet — not in a CSV download, not to a connected email marketing tool, and not to a customer's own Zapier or webhook integration. It is only ever displayed inside ReplyMagnet, and only to administrators of the same page it came from.
- We do not use LinkedIn member data for advertising, sales prospecting, recruiting, audience building, or to enrich any other record about that person.
An email address or phone number a person types into one of our capture pages is different: they gave it to the business directly, it never came from LinkedIn, and it is handled under the rest of this policy rather than the limits above.
How we use data
- To run the automations creators configure — replying, sending DMs, verifying follows, delivering files.
- To show creators analytics about their own campaigns.
- To enforce plan limits and prevent abuse.
- To comply with Instagram and LinkedIn platform policies, including messaging windows, rate limits, and LinkedIn's data storage requirements.
We do not sell personal data, use it for advertising, or train AI models on it. Audience data belongs to the creator whose campaign collected it.
Where data lives
Data is stored with Supabase (Postgres and file storage) with row-level security isolating each workspace. Instagram and LinkedIn access tokens are encrypted at rest. Uploaded files are private and served only through expiring signed links.
Sharing
We share data only with the infrastructure providers needed to run the service (hosting, database, email delivery), each bound by their own data-processing terms, and with Meta/Instagram or LinkedIn when calling their APIs on the creator's behalf, and with Meta Platforms (advertising measurement) as described below. We disclose data if legally required. As described above, LinkedIn member data is excluded from every outbound path — exports, email marketing integrations, and webhooks alike.
Advertising and analytics
We use the Meta Pixel on our marketing and app pages to measure how well our own advertising works. It sets an advertising cookie (_fbp) in your browser, and when you sign up or purchase a plan we share that event with Meta Platforms, Inc. along with a one-way hashed (SHA-256) version of your email address — never the address itself in readable form — so we can tell which ads led to real signups. We also record, at signup, which campaign link first brought you to our site (UTM parameters and click identifiers). None of this applies to your audience: commenters and leads captured through your campaigns are never shared with Meta for advertising, and no advertising pixel runs on delivery or capture pages. You can block the pixel with any standard content blocker without affecting the product.
We also use PostHog, a product-analytics service, on our marketing site and app to understand how visitors and creators use them — which pages you visit and which actions you take — and to record sessions so we can find and fix usability problems. Text you type, including passwords and email addresses, is masked and never captured in these recordings, and the same masking is applied to your leads' and commenters' details (emails, phone numbers, and handles) wherever they appear on screen, so they're redacted from these recordings too. As with the pixel, it never runs on delivery or capture pages, so your commenters and leads are never analytics-tracked while interacting with those pages. You can block it with any standard content blocker without affecting the product.
We also use Google Analytics on our marketing site and app to measure which pages visitors view and where they come from. It sets Google's analytics cookies in your browser; the data is shared with Google LLC as our analytics processor. As with the pixel and PostHog, it never runs on delivery or capture pages, so your commenters and leads are never tracked by it. You can block it with any standard content blocker without affecting the product.
Our marketing site (not the signed-in app) also uses a first-party analytics script, served from our own domain, to measure which pages and campaigns bring visitors to us. It does not run on the signed-in product or on delivery or capture pages, so neither creators using the app nor their commenters and leads are ever tracked by it. You can block it with any standard content blocker without affecting the product.
Retention and deletion
- Creators can delete campaigns, leads, and files at any time from the app.
- Deleting a workspace removes all of its data after a 14-day grace period.
- Audience members can request deletion of their data via Instagram's data-deletion flow (we honor Meta's deletion callbacks automatically) or by emailing us.
- LinkedIn commenters' names and comment text are erased automatically on the 24-hour and 48-hour schedules described above — no request needed.
- Disconnecting an Instagram account or LinkedIn page invalidates its stored token.
Your rights
Depending on where you live (including under GDPR and CCPA), you may have rights to access, correct, export, or delete your personal data, and to object to processing. Email us and we'll respond within 30 days.
Contact
Data controller: Techinfy IT Solutions, which operates ReplyMagnet. For any privacy request or question: privacy@replymagnet.app. Changes to this policy will be posted here with a new "last updated" date.