Official Legal Document • Meta Graph API Compliant
Privacy Policy
Effective Date: August 15, 2026
Last Updated: September 23, 2026
Welcome to Nexa Reply (AutomationDM) ("we", "our", or "us"). We provide an intelligent, cloud-based Instagram Direct Message (DM) & Comment Automation Platform (the "Service"). This Privacy Policy explains how we collect, store, protect, and use your information in compliance with Meta Platform Policies, Google Play Developer Policies, GDPR, and Indian Information Technology (IT) laws.
1. Information We Collect
We believe in strict data minimization. We collect only what is necessary to operate our service:
- Account Credentials: Full Name, Email Address, and Phone Number (collected at registration to facilitate secure Razorpay/Stripe checkout, fraud prevention, and critical DM safety SMS alerts). Passwords are cryptographically salted and hashed using bcrypt.
- Instagram & Meta OAuth Data: Instagram Account ID, Username, Profile Picture URL, linked Facebook Page ID, and secure OAuth access tokens obtained through official Meta OAuth. We never ask for, access, or store your Instagram or Facebook passwords.
- Post & Reel Metadata: Media IDs, captions, media URLs, and post timestamps required to let you configure automated keyword replies.
- Webhook Engagement Events: Incoming comment text, comment IDs, commenter public Instagram handles, and direct message delivery receipts sent to us by Meta Webhooks.
- Usage & Performance Metrics: Total comments processed, automated DMs dispatched, CRM leads generated, and rate limit counters to ensure anti-spam compliance.
2. How We Use Your Information
- Automation Delivery: To automatically send instant, customized private DMs and public replies when users comment on your Instagram posts and Reels.
- Anti-Spam & Account Protection: To enforce strict hourly safety limits (maximum 180 DMs/hour safe cap) with random human delay jitter, ensuring 0% shadowban or account restriction risk.
- Lead Management (CRM): To organize verified customer leads, contact numbers, and emails collected through your automation funnels.
- Billing & Customer Support: To process payments through certified gateways and assist you with technical inquiries.
3. Payment Security & No Card Storage
All subscription payments are handled through PCI-DSS Level 1 certified payment gateways (Razorpay and Stripe). We do not store, process, or transmit full credit card numbers, CVVs, or bank net banking credentials on our servers. All financial transactions are protected with 256-bit SSL encryption.
4. Meta Platform & API Compliance
Our application operates strictly through official Meta Graph API endpoints. We do not use web scraping, unauthorized reverse-engineered bots, or unofficial APKs. Your data is handled in strict accordance with the Meta Developer Platform Terms and Instagram Community Guidelines.
5. Data Storage, Security & Cloud Infrastructure
Your data is stored in enterprise-grade, ISO 27001-certified Amazon Web Services (AWS) data centers in us-east-1. Access tokens are encrypted at rest using AES-256 encryption. Webhooks are cryptographically authenticated using SHA-256 HMAC signature verification.
6. Data Sharing & Third Parties
We never sell, rent, or monetize your personal or customer data to data brokers, advertisers, or third parties. We share data only with essential cloud infrastructure providers:
- Amazon Web Services (AWS): Cloud compute, SQS message queuing, and DynamoDB storage.
- Meta Platforms, Inc.: Direct official API communication over TLS 1.3 encryption.
- Razorpay / Stripe: Certified payment processing.
- Firebase (Google LLC): Authentication and push notification delivery.
7. User Data Deletion & GDPR Rights
You have full ownership of your data. You have the right to access, export, or permanently delete your data at any time:
- Self-Service In-App Deletion: You can disconnect your Instagram account or permanently delete your Nexa Reply account directly from Settings > Danger Zone > Delete Account.
- Facebook Business Integrations Removal: Removing our app from your Facebook account triggers an automatic callback that wipes your stored tokens.
- Instructions Page: Visit our dedicated User Data Deletion Page for complete details.
8. Contact Our Legal & Data Protection Officer