Privacy Policy
Last updated:
1. Who we are and what this covers
SlideReply (“SlideReply”, “we”, “us”, or “our”) provides automation tools for Instagram creators and small businesses. When a person comments a keyword you have configured (for example, “LINK”) on your own post or reel, replies with that keyword to your Instagram story, or comments it during your live broadcast, SlideReply sends that person a private message containing the link or information you set up. This Privacy Policy describes, in a transparent and comprehensive manner, the categories of personal data we collect through our website and dashboard at slidereply.com, the purposes for which we process it, the legal bases we rely on, the parties with whom it is shared, the periods for which it is retained, and the rights and choices available to you.
SlideReply connects to your Instagram professional account using the Instagram API with Instagram Login. Our handling of Instagram data also complies with the Meta Platform Terms and Developer Policies.
For the purposes of data-protection law, the controller (and the “Data Fiduciary” under India’s Digital Personal Data Protection Act, 2023) responsible for your personal data is SlideReply, operating from Hyderabad, India. You can reach us about any privacy matter at privacy@slidereply.com; our Grievance Officer details are in Section 14.
Our role under data-protection law depends on the data in question. In respect of your own account, login, billing, and automation data, we act as the controller (Data Fiduciary). In respect of the personal data of your End Users — the people who comment on, reply to, or message your Instagram content — you determine the purposes of the processing and we process that data on your documented instructions in order to provide the service; in that respect you act as the controller and we act as your processor (Data Processor). You are responsible for having a lawful basis, and any notices or consents required, for your End Users’ data, and we provide the functionality you need to respond to their requests and delete their data.
2. The short version
- We access only the Instagram account you expressly connect, and act only upon your own content — your posts, reels, stories and live broadcasts, the comments and keyword replies made on them, and the direct messages your automations send and receive.
- To operate the features you switch on, we store a limited amount of message-related data: a short preview of an incoming message so it can be shown to you in your Open Leads inbox, and a record of whether a message you sent was seen. These are retained only briefly (see Section 7).
- We never access other people’s accounts or private content.
- We do not sell your personal data, and we never use it for advertising.
- Your Instagram access token is stored in encrypted form and is never shared, displayed in the dashboard, or returned to your browser.
- You may delete your data at any time — disconnect an account, permanently remove a disconnected account and all of its data, delete your entire account, or remove the app from within Instagram. See Data Deletion for exactly what each option does and when it takes effect.
3. Information we collect
a. Account and login data. Your email address and a securely hashed password (we never store your password in readable form). If you sign in with Google, we receive your email address and a Google account identifier from Google instead of a password.
b. Instagram data (accessed through the Meta API). When you connect an account, and solely in respect of the account you connect, we access and process the following, in each case strictly for the purpose stated:
- account information — your Instagram account identifier, username, and account type, used to identify the connected account and operate the integration;
- your own media — a list of your posts and reels, so that you can select the content an automation runs on;
- comments and keyword replies on your content — the text, together with the commenter’s username and identifier, of comments on your posts and reels, comments made during your live broadcasts, and replies to your Instagram stories, which we compare against the keyword you configured in order to decide whether to trigger your automation;
- direct messages — the private messages your automation sends, and the replies received from the recipient within Instagram’s standard 24-hour messaging window, so that any follow-up you have configured can be delivered;
- an Open Leads preview — where a conversation requires your personal attention, we store a short extract (up to approximately 200 characters) of the most recent incoming message, together with a reference to the post, reel, story or live broadcast it relates to, so that it can be surfaced to you in your Open Leads inbox. This extract is held only transiently and expires automatically (see Section 7);
- message-status signals — where Instagram notifies us that a message your automation sent has been seen, we record that a read event occurred, so that we can present accurate delivery and “seen” statistics in your dashboard;
- follow status (only if you enable the follow request) — if you switch on the optional feature that asks a commenter to follow you before the link is delivered, then, after that person taps the “I’m Following” button, we check once whether they follow your account, solely to confirm that condition before sending the message. We do not otherwise collect or store the follower lists of your account.
c. Automation configuration. The automations you create — your keywords, the trigger you select (a comment on your post or reel, a reply to your story, or a comment on your live broadcast), the message templates, links and link-button destinations you write, any follow-up message and its timing, the media you attach, and related settings.
d. Billing data. If you subscribe to a paid plan, our payment processor (Razorpay) handles your card or payment details. We do not store your full card number; we keep records of your plan, subscription status, and invoices/receipts.
e. Usage and technical data. Limited operational data needed to run and protect the service — such as log entries, IP address, and timestamps — used for delivery, debugging, rate-limiting, and abuse prevention.
4. How we use your data
We use the data above to:
- operate the core service — detect a matching comment, story reply or live comment on your content and send the private message you configured, at a safe, paced rate;
- let you build, edit, and manage your automations;
- surface conversations that require your personal reply in your Open Leads inbox, and present accurate usage, activity, delivery and “seen” analytics in your dashboard;
- process payments, manage subscriptions, and send receipts;
- send essential service emails (email verification, password resets, billing and security notices);
- protect account safety and platform integrity — pace sending, prevent spam and abuse, and honor Instagram’s limits;
- provide support and comply with our legal obligations.
We rely on the lawful bases of performing our contract with you (running the service you signed up for), our legitimate interests (security, abuse prevention, and improving the product, balanced against your rights and freedoms), your consent (the Instagram permissions you grant, which you may revoke at any time), and compliance with law. Our access to, use of, and transfer of information received through the Meta APIs adhere to the Meta Platform Terms and Developer Policies, including any applicable limited-use requirements. We do not use your Instagram data for advertising, we do not sell personal data, and we do not subject you to decisions producing legal or similarly significant effects based solely on automated processing.
5. The Instagram permissions we use — and why
SlideReply requests exactly three Instagram permissions, and uses each only for the purpose below:
- instagram_business_basic — to identify the account you connect and to list your own posts and reels, so you can attach an automation to one;
- instagram_business_manage_comments — to receive the comments made on your posts, reels and live broadcasts, and to read the comment text and the commenter’s handle, in order to match the keyword you configured;
- instagram_business_manage_messages — to receive replies made to your stories and messages sent to you in response, to send the private reply you configured to the person who engaged, and to send any follow-up within Instagram’s standard 24-hour window. Where you enable the optional follow request, this permission is also used to read, once and only after the person consents by tapping the button, whether they follow your account.
We act only upon content owned by the creator who authorized us, and only in response to a comment, reply or message concerning that creator’s own content. We do not request, and do not use, any permission for advertising, content publishing, or access to insights or audiences beyond what is described above.
7. How long we keep your data
We retain personal data only for as long as is necessary for the purposes for which it was collected, after which it is deleted or automatically expires. The applicable periods are:
- Account, credential and automation data — retained for as long as your account remains active;
- Saved contacts (your CRM records) — retained in accordance with the retention period you may configure in the dashboard; where you make no selection, a default period of 365 days from the last interaction applies, after which the record is automatically deleted;
- Open Leads and Recent Replies previews and conversation state — held only transiently to operate the inbox and the messaging window, and expire automatically, ordinarily within approximately 24 hours;
- Follow-up instructions — held only for the short period needed to deliver a scheduled follow-up within the 24-hour window, and expire automatically thereafter (ordinarily within a few days);
- Message-status (“seen”) signals — the short-lived operational marker recording a read event expires automatically and, in any event, no later than 90 days;
- Processed-comment and de-duplication records — kept briefly to ensure reliable, non-duplicative delivery and account safety, then expire automatically;
- Instagram access tokens — held in encrypted form only while the account is connected, and deleted immediately upon disconnection;
- Invoices and tax records — retained for the period required by applicable law, and deleted thereafter.
The effect of disconnecting an account, permanently removing a disconnected account and its data, deleting your entire account, or removing the app from within Instagram — including which data is erased immediately and which is retained for a limited, defined grace period before automatic deletion — is set out in full in Section 12 and on the Data Deletion page. Residual copies that may persist transiently in operational logs, caches or encrypted backups are purged, or automatically age out, in the ordinary course and in any event within 90 days.
8. Who we share data with
We do not sell your data. We share it only with the service providers (sub-processors) that help us run SlideReply, and only as needed:
- Meta / Instagram — to operate the Instagram integration (receiving comments, sending DMs) under the Meta Platform Terms.
- Razorpay — payment processing for paid plans.
- Cloud infrastructure — Amazon Web Services (compute, encrypted secrets, storage), and our managed database and cache providers, to host and run the service.
- Email provider — to deliver transactional emails (verification, password reset, receipts, security notices).
- Google Firebase — only if you choose “Continue with Google” to sign in.
Each service provider is permitted to use your data only to provide services to us, under contractual confidentiality and data-protection obligations (including data-processing agreements where required), and not for its own purposes. We may add or replace service providers as the service evolves, and where the law requires we will give notice and, where applicable, a means to object. We may also disclose data if required by law, to enforce our terms, or to protect the rights and safety of our users and the platform. If SlideReply is ever involved in a merger, acquisition, or sale of assets, your data may transfer to the successor, who will remain bound by this policy or a policy at least as protective of your data.
9. International data transfers
SlideReply is operated from India and serves creators worldwide. Your data may be processed in India and in other countries where our infrastructure providers operate. Where data crosses borders — including from the EEA, UK, or other regions — we rely on appropriate safeguards such as standard contractual clauses and our providers’ approved data-transfer mechanisms.
10. How we protect your data
- Instagram access tokens are encrypted at rest and never shown in the dashboard or returned to the browser.
- Passwords are stored only as salted, slow-hashed values — never in plaintext.
- All traffic is served over HTTPS; session cookies are HTTP-only and secured.
- Every account’s data is strictly isolated server-side, so one creator can never read or affect another’s data.
- Incoming Instagram and payment webhooks are cryptographically signature-verified before we act on them.
- Access to production systems is restricted and least-privilege.
No method of storage or transmission is ever completely secure, so we cannot guarantee absolute security. If we become aware of a personal data breach that affects you, we will act promptly to contain it and will notify you and the relevant authority — including the Data Protection Board of India and, where applicable, your regional regulator — within the timeframes the law requires.
11. Your choices and rights
Depending on where you live, you may have rights to access, correct, export, restrict, or delete your personal data, and to withdraw consent. You can exercise most of these directly in the dashboard:
- change your email, password, or data-retention setting in Settings;
- disconnect an Instagram account, which immediately stops all messaging and erases the stored access token (the associated interaction data is then deleted as described on the Data Deletion page);
- delete your entire account and all associated data;
- revoke our access from within Instagram at any time.
EEA / UK (GDPR). You also have the right to data portability and the right to lodge a complaint with your local supervisory authority. Where we rely on consent, you can withdraw it at any time without affecting processing already carried out.
California (CCPA/CPRA). We do not sell or “share” personal information as those terms are defined, and we will not discriminate against you for exercising your rights. You may request access to or deletion of your information as described here.
India (DPDP Act). You have the right to access, correction, and erasure of your personal data, to nominate another person to exercise your rights, and to a readily available grievance-redressal mechanism — our Grievance Officer in Section 14.
To make any request that isn’t self-serve, email privacy@slidereply.com from your account email. We respond within one business day and complete verified requests within 30 days (extendable where the law permits, with notice to you). You may use an authorised agent to submit a request on your behalf, subject to our verifying your identity and the agent’s authority. We will not discriminate or retaliate against you for exercising your rights, and where we decline a request we will explain why and, where the law provides one, how to appeal.
12. Deleting your data
Full, step-by-step deletion instructions — disconnecting an account, deleting your whole account, and removing SlideReply from Instagram (which triggers automatic deletion on our side) — are on the Data Deletion page.
13. Children
SlideReply is a business tool intended for adults and is not directed at children. You must meet Instagram’s minimum age and be at least 18 to use SlideReply. We do not knowingly collect data from children; if you believe a child has provided us data, contact us and we will delete it.
14. Grievance Officer and how to complain
In line with India’s Information Technology Rules and the Digital Personal Data Protection Act, 2023, you can raise any privacy concern, complaint, or data-rights request with our Grievance Officer:
- Grievance Officer: SlideReply Grievance Team
- Operated by: SlideReply, Hyderabad, India
- Email: privacy@slidereply.com
We acknowledge grievances within one business day and aim to resolve them within the timelines the law requires. If you are not satisfied with our response, you may escalate to the Data Protection Board of India or, if you are in the EEA/UK, to your local supervisory authority.
15. Changes to this policy
We may update this Privacy Policy as the product and the law evolve. We will revise the “Last updated” date above and, for material changes, give notice in the dashboard or by email. Continued use after a change takes effect means you accept the updated policy.
16. Contacting us
Questions about privacy or your data? Email privacy@slidereply.com or reach our India-based support team via the Contact page. We operate during India business hours (IST) and reply within one business day.