Privacy Policy
Last updated: 9 October 2026
This policy explains what InstaRelay collects, why, how long we keep it, and how you can delete it.
1. What we collect
Your account
- Email and name — for sign-in and communication
- Password, stored as a hash (Argon2id). The plain password is never stored.
From Instagram (with your authorization)
- Your page’s numeric ID and username
- Meta access token — encrypted with AES-256-GCM
- Comment text, commenter username, comment ID and the related post
- The AI category assigned to each comment and the action taken
What we do not collect
- Your Instagram password — never requested
- Direct messages (the current version reads comments only)
- Cross-site tracking data or advertising cookies
2. Why
Only to provide the service: classifying comments, deleting offensive ones when enabled, replying to positive comments, and surfacing questions to you.
3. Artificial intelligence
Comment text is sent to an AI service for classification. That request does not include your username, email or any other identifying data — only the comment text.
4. Sharing
We do not sell your data. It is shared only with the service providers required to run the product (hosting and AI), and only as much as needed.
5. Retention
- Comments and action history: while your account is active
- Access token: until you disconnect your account
- ⚠️ Comment records are never deleted automatically — for transparency. Deleting your account removes everything.
6. Your rights
You can delete your account, disconnect Instagram, or request a data export at any time. See the Data Deletion page for details.
7. Security
All traffic is encrypted with HTTPS. Tokens are stored encrypted and are redacted from logs — not merely hidden.
Questions?
Email us at [email protected]