Privacy Policy
Summary: ReplyMint connects to your Instagram, Facebook and/or Threads account through Meta's official APIs to help you manage buyer comments, replies and DMs. We only process messages to deliver the service. We use Google Analytics and Microsoft Clarity (with customer content masked in the app), plus Sentry for errors and Vercel for aggregate performance metrics. Your data is never sold or shared for ads.
Last updated October 4, 2026 · Questions: privacy@replymint.app
In plain English Summary
We use your data only to provide and improve the ReplyMint service—not to sell it to advertisers or share it with third parties for their own marketing.
Comments, DMs, and author details needed to show who sent them. ReplyMint does not access Threads direct messages.
Message text is sent to classify intent and suggest replies. Generated reply suggestions are not stored.
Verified deletion requests are completed within 30 days. Stored media copies are deleted automatically after 90 days.
Google Analytics and Microsoft Clarity help us improve the product. Customer-facing areas of the app are masked in Clarity so message text, usernames, and avatars are not recorded.
We notify you of material changes via email at least 14 days before they take effect.
1. Who We Are
ReplyMint ("ReplyMint," "we," "us," or "our") is a software service that helps sellers manage buyer comments and direct messages on Instagram, Facebook and Threads and close sales more efficiently. Our registered address is in India.
This Privacy Policy explains how we collect, use, store, and protect your personal data when you use the ReplyMint platform, including our website at replymint.app and the ReplyMint application.
2. Data We Collect
When you visit our marketing site we set a first-party cookie (rm_ft, 30 days) recording how you found us — landing page, referring site, and campaign tags — so we can understand which content leads to signups. It contains no personal information.
If you contact us through our website form, we store your name, email, optional Instagram handle, your message, and the page you sent it from, so we can reply. You can ask us to delete it at any time.
2.1 Account and Identity Data
When you create a ReplyMint account, we collect:
- Your email address and password (hashed — we never store plain-text passwords)
- Your business name, category, and description (entered during onboarding)
- Your product catalog, pricing, and FAQs (entered during onboarding, used to power reply suggestions)
- Your preferred communication tone and style settings
2.2 Instagram, Facebook, Threads and Meta platform data
ReplyMint integrates with Meta's APIs under Meta's Platform Terms. When you authorize ReplyMint to connect to your Instagram Business or Creator account, your Facebook Page and/or your Threads profile, we access and store only what is needed to run the service:
- Comment data: Text content, timestamp, and author of comments on your Instagram and Facebook posts, and replies to your Threads posts (as connected) — received in real time where available
- Direct message data: Content and metadata for buyer-related messages you receive through your connected accounts, as permitted by the permissions you grant (Instagram and Facebook; ReplyMint does not access Threads direct messages)
- Author metadata: Public usernames and user or page identifiers needed to display who sent each message in your inbox. We may also store message authors' public profile pictures so your inbox can show who sent each message.
- Post and conversation identifiers: IDs that associate each message with your content or conversation thread
- Connected account details: Account and Page IDs and display names — used only for routing events to your workspace
- Media attachments: Photos, voice notes, videos and files sent to you in messages. On Free plans we store no copies. On paid and trial plans we store copies of Instagram voice notes (up to 5 MB) and documents (up to a size limit) only, because Meta does not let us retrieve them later. We do not store photos, videos, Facebook voice notes, story mentions, reels or shared posts: when you open the message, your inbox fetches a fresh temporary link from Meta. For shared posts and reels we keep the public instagram.com link to the post. Stored copies are deleted automatically after 90 days.
We do not access data beyond what you authorize for ReplyMint. We do not use your data to build advertising profiles, sell follower lists, or market to your audience.
2.3 Usage and Activity Data
We collect data about how you use ReplyMint to improve the product:
- Which features you use and how frequently
- Reply actions you take (replied, sale confirmed, message dismissed)
- Monthly message volume (used for usage billing)
- Error logs and performance metrics (anonymized)
2.4 Automatically Collected Technical Data
- IP address (used for security, rate limiting, and coarse location analytics)
- Browser type and operating system
- Session tokens (for authentication)
- Device identifiers and screen resolution (for analytics)
- Pages visited and interactions within ReplyMint (for product improvement)
2.5 Analytics and Product Improvement
We use third-party analytics services to understand how ReplyMint is used and improve the product:
- Google Analytics 4: Collects anonymized usage data (pages visited, features used, session duration, device type, coarse location). Google processes this data under their privacy terms. You can opt out using the Google Analytics opt-out browser add-on or Google Ads Settings.
- Microsoft Clarity: Records session replays and heatmaps on our marketing site and in the logged-in app to understand user experience. Customer-facing areas of the app (inbox, messages, profiles, and brand settings) are marked for Clarity masking so message text, usernames, and avatars are not recorded. You can opt out via Microsoft's privacy controls.
- Sentry: Application error monitoring in production. Message text, access tokens, and email addresses are redacted in our logging layer before events are sent.
- Vercel Analytics and Speed Insights: Aggregate page views and performance metrics (for example load times and Web Vitals). They do not receive message content.
These services do not receive direct API access to your Instagram or Facebook accounts or to our database. They receive event and usage data from your browser. Clarity may still capture non-masked parts of the interface (navigation, buttons, empty states); sensitive customer and brand content is wrapped with Clarity mask attributes in the product.
3. How We Use Your Data
We use your data only to provide and improve the ReplyMint service:
| Purpose | Data Used |
|---|---|
| Classify buyer intent in messages | Message text + your business profile |
| Generate reply suggestions | Message text + business profile + products + tone |
| Display the smart inbox | Message data + intent classification |
| Track sales and revenue | Your confirmed sale actions (not customer data) |
| Authenticate your account | Email + session tokens |
| Enforce usage limits | Monthly message count |
| Send transactional emails | Email address (account events only — no marketing spam) |
| Provide customer support | Account data + your support messages |
We use your data to operate ReplyMint—not to sell it to advertisers or share it with third parties for their own marketing. AI processing through Google is subject to Google's applicable API and privacy terms for the services we use.
3.1 Aggregated and De-identified Data for Research and Product Improvement
We may use aggregated and de-identified data derived from customer accounts to understand platform trends, improve the ReplyMint product, and publish research or educational content. This includes:
- Statistical summaries (e.g., "across all accounts, 3% of comments show buyer intent")
- Pattern analysis (e.g., common spam characteristics, language distribution)
- Performance benchmarks (e.g., median AI classification time)
- Blog posts, case studies, and educational content that describe platform usage
Identifiers are always removed: Before using data this way, we strip all personally identifiable information—workspace names, customer names, business niche or product details, usernames, and verbatim message text. We may paraphrase message patterns (e.g., "buyer asked about size and shipping time") without quoting actual comments. Aggregated insights never reveal individual accounts or customers.
This practice is standard across industry platforms (Intercom, HubSpot, Zendesk, and others) and helps us build a better product for everyone. If you have concerns about your data being included in aggregated analysis, contact us at privacy@replymint.app.
4. Meta platform data — compliance
ReplyMint is built on Meta's official APIs and is subject to Meta's Platform Terms. In compliance with these terms:
- We only request the minimum permissions necessary to operate the service (for example, permissions related to comments, messaging, and Page or account metadata, as applicable to your connection)
- Data from Instagram, Facebook and Threads is used solely to provide the ReplyMint service to you — not for any secondary purpose
- We do not transfer Meta platform user data to data brokers, advertisers, or any marketing-related third parties
- Message authors' data (for example username or user ID) is stored only to display who sent each message in your inbox — we do not build profiles of your followers for advertising
- You can disconnect your accounts and request deletion of associated platform data at any time (see Section 8)
- We comply with Meta's data deletion requirements and will delete associated platform data within 30 days of account disconnection where applicable
For Meta's own data practices, see Meta's Privacy Policy.
5. Data Sharing and Third Parties
We share your data with a small number of trusted service providers who help us operate ReplyMint:
- Supabase (database, authentication, and realtime): Stores your account data and message data from connected platforms, plus the limited media copies described in Section 2.2 (file storage). ReplyMint does not operate its own data centers; Supabase provides managed cloud infrastructure for our database and auth with encryption in transit and at rest as described in Supabase's security documentation and privacy policy. Their subprocessors and regions are determined by Supabase, not by a separate contract between you and us for raw infrastructure.
- Google (Gemini API): Receives message text and your business profile (and related context we send in the prompt) to classify intent, run safety checks in our production pipeline, and generate reply suggestions. Processing is governed by Google's Privacy Policy and applicable Google AI / API terms. We configure the service for our use case; we do not use your data to train unrelated products. ReplyMint doesn't train its own AI models on your comments or messages.
- Resend (transactional email): Sends account-related emails (password reset, billing notifications). Does not receive your Instagram or Facebook message thread content for that purpose.
- Dodo Payments: Processes subscription payments as merchant-of-record for paid plans. Receives payment method and billing details you provide at checkout, plus metadata needed to link payment to your workspace. Does not receive Instagram or Facebook message content from us for payment processing.
- Vercel (hosting and infrastructure): Hosts the ReplyMint web application and serverless functions. Receives request-level data (for example IP address and HTTP headers) needed to deliver the site. Vercel Analytics and Speed Insights receive aggregate page views and performance metrics only.
- Upstash (caching and rate limiting): Temporarily stores short-lived technical data, such as rate-limit counters and temporary media links from Meta, to keep the service fast and protected. These entries expire automatically, within 24 hours for media links. Upstash does not receive your message text.
- Sentry (error monitoring): Receives error events and diagnostic context from production. Message text, tokens, and emails are redacted before sending. See Sentry's Privacy Policy.
- Google Analytics 4: Processes usage and behavior data to help us understand product usage. See Google's Privacy Policy.
- Microsoft Clarity: Processes session replay and heatmap data on our website and in the logged-in app. Customer content in the inbox and brand settings is masked in the UI so it is not recorded in replays. See Microsoft's Privacy Statement.
- Meta (platform APIs): ReplyMint connects to Instagram, Facebook and Threads through Meta's APIs under Meta's Platform Terms. Meta's own data practices are described in Meta's policies.
We do not sell your personal data. We do not share it with advertisers. We will disclose data if legally required (e.g., a valid court order) and will notify you when legally permitted.
6. Data Retention
We retain your data for as long as your account is active, plus a reasonable period after:
- Message data (comments, replies and DMs): Retained while your account is active so your inbox history stays available, and deleted within 30 days of a verified deletion request (see Section 8).
- Generated reply suggestions: Not stored — generated on-demand and returned to your browser only
- Business profile data: Retained until you delete it or close your account
- Sale and revenue records: Retained while your account is active, as part of your message history, and deleted together with your messages when you request deletion.
- Account data (email, authentication): Retained while your account is active, and deleted within 30 days of a verified deletion request.
- Usage logs: Usage records (such as monthly message counts used for billing and limits) are calculated from your message history and are deleted with it. Technical error logs are kept by our hosting and monitoring providers for a limited period for debugging and security.
- Media attachments: Stored copies (see Section 2.2) are deleted automatically after 90 days. Temporary media links from Meta are cached for no more than 24 hours.
7. Security
We take the security of your data seriously:
- All data is encrypted in transit using TLS 1.2+
- Database data is encrypted at rest (AES-256)
- Meta webhook signatures are verified with HMAC-SHA256 to prevent spoofing
- Authentication tokens are short-lived and rotated
- Only the founder has administrative access to production systems, and uses it only for support and troubleshooting
In the event of a data breach that affects your personal data, we will notify you via email within 72 hours of discovery, where legally required.
8. Your Rights and Data Deletion
You have the following rights regarding your data:
- Access: Request a copy of all data we hold about you
- Correction: Update your account data at any time from Settings
- Deletion: Email privacy@replymint.app from your account email to delete your account and all associated data. We verify the request and complete deletion within 30 days.
- Portability: Request an export of your account data and sale history in JSON format
- Platform data deletion: Disconnect Instagram, Facebook or Threads from Settings → Channels to stop new data ingestion. Email us to request deletion of historical message data.
- Opt-out of automated processing: Contact us if you wish to opt out of intent classification or suggestion generation
To exercise any of these rights, email us at privacy@replymint.app. We will respond within 7 business days.
Meta data deletion: If you connected ReplyMint to Instagram, Facebook or Threads and later want to remove your data from our servers, you can submit a data deletion request via Meta app settings or by emailing us directly. Step-by-step instructions: Data deletion. We will process all deletion requests within 30 days.
9. Cookies
ReplyMint uses cookies and similar technologies to operate the service and improve the product:
- Essential cookies: Session tokens to keep you logged in (cleared when you log out or they expire)
- Preference cookies: Stores your light/dark mode preference in localStorage
- Analytics cookies: Google Analytics and Microsoft Clarity set cookies to track usage patterns, session behavior, and product performance. These help us understand how the product is used and where to improve.
We do not use advertising cookies or tracking pixels for ad targeting. Analytics cookies are used solely for product improvement. You can opt out of analytics via browser settings or the opt-out links in Section 2.5.
10. Children's Privacy
ReplyMint is not intended for children under 16 years of age. We do not knowingly collect personal data from anyone under 16. If you believe we have inadvertently collected data from a child, contact us immediately at privacy@replymint.app and we will delete it promptly.
11. Changes to This Policy
We may update this Privacy Policy as the product evolves or legal requirements change. We will notify you of material changes via email (at the address on your account) at least 14 days before they take effect. The "Last updated" date at the top of this page always reflects the most recent version.
Continued use of ReplyMint after a policy update takes effect constitutes your acceptance of the new terms.
12. Contact Us
If you have questions, complaints, or requests regarding this Privacy Policy:
- Email: privacy@replymint.app
- Company: ReplyMint, India
- Response time: We aim to respond to all privacy requests within 7 business days
Questions about this policy?
We're a small team and we take privacy seriously. Reach out directly:
privacy@replymint.app