Legal

Privacy Policy

Last updated 25 September 2026. This policy applies to reply.ably.tz and the Replyably app.

The short version
  • We collect only what the reply tray needs: your sign-in details, the account connections you approve, and the posts and comments those connections expose.
  • We never see or store your Instagram or Facebook password, and the access tokens we do hold are encrypted.
  • Nothing is published until you tick it and press Send.
  • We don't sell your data, run ad trackers, or use it for advertising.
01

What Replyably is

Replyably is a comment reply inbox. You connect the Instagram and Facebook accounts you post from, Replyably brings in the posts that have new comments, drafts a reply for each comment in the voice you already use, and posts only the replies you tick and send.

This policy covers the information Replyably handles when you use the site and the app. It does not cover how Meta (Instagram and Facebook), Google or any other platform handles your information under their own policies, or what other people do with comments they can see publicly on your posts. The rules for using the service itself are set out separately in the Terms & Conditions of Service, which read alongside this policy.

02

Information we collect

Account information. Your email address and a hashed password when you register, or your name, email address and profile photo if you sign in with Google. A display name is created from your email or Google profile so the app can greet you.

Connected accounts. When you link Instagram or Facebook you sign in on Meta's own screens. We then receive the account name, username and profile picture, the pages and Instagram business accounts you manage, and an access token with an expiry date. We ask only for the permissions the tray needs: see the pages you manage, read the comments on your posts, and post replies. We never ask for, see or store your Instagram or Facebook password.

Content we sync. To build your tray we store the captions, media links, post links and dates of your posts, the comments other people leave underneath them (including the commenter's display name and the comment text), and the replies you send.

Your reply style. Replies you send through Replyably, and your own replies that were already on your posts when you connected, are kept as examples so new drafts can match your tone.

Technical and diagnostic data. When something breaks, an error report is recorded with basic details such as browser, device, the page involved, approximate time and IP address, so the fault can be traced.

What we do not collect. Your Instagram or Facebook password, direct messages, payment or card details, contacts, advertising identifiers, or a record of the sites you visit outside Replyably.

03

How we use your information

We use it for the running of the service and nothing else:

  • sign you in and keep your account secure
  • connect to the platforms you choose and fetch posts and new comments
  • draft replies that sound like you, and send the ones you approve
  • remember which comments are already answered so nobody gets replied to twice
  • keep the service running, fix faults, and guard against abuse or misuse
  • answer your support requests, and meet legal obligations

We do not sell your information, use it for advertising, or build a marketing profile of you.

04

AI-drafted replies

To suggest a reply, the AI service is sent only the text it needs: the comment itself, the commenter's display name, the caption of the post it sits under, and up to 25 of your own past replies as a tone reference. It returns a suggested reply, which is saved to your account as a draft.

Nothing is published until you select it and press Send. Access tokens, passwords and other credentials are never sent to the AI service. Drafting is done by a third-party model provider whose own terms govern how it handles request data; we keep what we send to the minimum the task requires.

05

Who we share your information with

We share only with the parties needed to deliver the features you use, and we do not sell or share your personal information for advertising across other companies' products.

  • Meta (Instagram, Facebook) — to fetch your posts and comments and to publish the replies you approve. Their platform terms apply to that exchange.
  • Google — to verify your identity when you choose Sign in with Google.
  • AI service provider — the comment, caption and tone examples described above, to generate drafts.
  • Cloud hosting and database provider — stores your account, connections, posts, comments and drafts.
  • Error monitoring — fault reports when something goes wrong.

We may also disclose information if we are required to by law, or to protect the rights, property and safety of our users and the service.

06

How we keep it secure

  • platform access tokens are encrypted with AES-256-GCM before they are stored, with the key held apart from the database itself
  • your browser, our servers and the platforms talk over HTTPS
  • every table is row-level secured, so your posts, comments and drafts are readable only by your own signed-in account
  • platform app credentials and encryption keys live in server secrets, never in the code or in your browser

No method of transmission or storage is perfectly secure. If a breach were to affect your data, we would tell you where the law requires it. Remember that comments people leave on your posts are public on the platform itself: your privacy settings there decide who can see them.

07

How long we keep it

  • account details: while your account exists
  • connection details and tokens: until you remove the connection on the Accounts page
  • posts, comments, drafts and reply examples: removed with the account they came from, or when you delete your account
  • error reports: only as long as needed to trace and fix the fault

Removing a connection deletes its stored token and the posts, comments and drafts synced through it, and stops any further access. Deleting your account removes your profile and everything tied to it from our live systems straight away; copies in backup cycles expire in the ordinary course of that rotation.

08

Your rights and choices

Wherever you live, you can ask us to access, correct, export or delete the personal information we hold about you, restrict or object to how it is used, and withdraw consent at any time. You will not be treated worse for doing so.

  • remove a connection in Replyably at any time, and also remove Replyably inside your Instagram or Facebook settings to cut access at the platform
  • ask for a copy of your data, or for it to be deleted, by writing to us
  • ask us to restrict or stop a particular use of your information
  • complain to the data protection authority where you live

We answer requests within 30 days and may need to confirm it is really you before releasing anything. Most of what we store comes from your own social accounts, so you can also delete it at source. The data deletion page explains exactly how to ask and what happens afterwards.

09

Cookies and browser storage

Replyably keeps a sign-in session in your browser's storage so you stay logged in and the app knows which account you are. We do not use advertising cookies, marketing pixels, or third-party tracking scripts.

10

Where your data is processed

Your information is stored and processed on servers run by our providers, which may operate data centres outside your own country. Where that happens, we rely on the standard safeguards those providers put in place, such as contractual terms and standard data protection clauses.

11

Children

Replyably is a tool for people who run social accounts seriously, and is not directed at anyone under 16. We do not knowingly collect their information. If you believe a child has given us data, write to us and we will delete it.

12

Changes to this policy

We may update this policy as the service changes. The date at the top always shows the latest version, and if a change materially affects how your information is handled we will tell you in the app or by email before it takes effect.

Contact

For a question about this policy, or a request to access, export, correct or delete your information, write to data_protection@thinkzone.com. We reply within 30 days and may need to confirm it is really you. To ask for your account and data to be removed, see the data deletion page.