Privacy Policy
Last updated: August 6, 2026
Replyr (“we”, “us”) is a Shopify application that replies to a merchant’s Instagram direct messages with AI-generated answers grounded in that merchant’s Shopify product catalog. This policy explains what we collect, how we use it, and your choices.
Information we collect
- Shopify store data. When a merchant installs the app we access their store’s product catalog (titles, descriptions, prices, inventory, links) via the
read_productsscope, to ground replies in real products. We store the Shopify session needed to make these requests. - Instagram account & messages. When a merchant connects an Instagram professional account, we receive the account’s ID and username and an access token. When a customer messages that account, we receive the message content and the sender’s Instagram-scoped ID in order to generate and send a reply.
- Conversation history. We store messages exchanged through the app to provide context for replies and basic analytics for the merchant.
How we use information
- To generate and send replies to incoming Instagram DMs.
- To match customer questions against the merchant’s catalog.
- To show the merchant simple usage analytics.
We do not sell personal information or use it for advertising.
Service providers
To operate the app we share the minimum data necessary with:
- Meta / Instagram — to receive messages and send replies through the Instagram messaging API.
- Shopify — to read the merchant’s product catalog.
- Our AI provider — message text and relevant catalog context are sent to a large-language-model provider to compose a reply. This data is processed to produce the response and is not used to train models.
- Langfuse — a record of each AI reply, including the message text sent to and received from the AI provider, is stored so we can monitor quality, diagnose faults and control cost. It is not used to train models.
Data retention
We keep conversation and account data for as long as the merchant uses the app. When a merchant uninstalls the app or disconnects their Instagram account, the associated tokens are revoked and related data is deleted within 30 days.
Your choices & data deletion
A merchant can disconnect Instagram or uninstall the app at any time. To request access to or deletion of your data, email contact@dmreplyr.app and we will respond promptly.
Security
Data is transmitted over HTTPS and access tokens are stored on our server. We restrict access to the data to what is needed to operate the service.
Changes
We may update this policy from time to time. Material changes will be reflected by the “Last updated” date above.
Contact
Questions about this policy? Email contact@dmreplyr.app.