Privacy Policy
Last updated: October 6, 2026
Replyr (“we”, “us”) is a Shopify application that replies to a merchant’s Instagram direct messages with AI-generated answers grounded in that merchant’s Shopify product catalog. This policy explains what we collect, how we use it, and your choices.
Information we collect
- Shopify store data. When a merchant installs the app we access their store’s product catalog (titles, descriptions, prices, inventory, links) via the
read_productsscope, to ground replies in real products. We store the Shopify session needed to make these requests. - Instagram account & messages. When a merchant connects an Instagram professional account, we receive the account’s ID and username and an access token. When a customer messages that account, we receive the message content and the sender’s Instagram-scoped ID in order to generate and send a reply.
- Conversation history. We store messages exchanged through the app to provide context for replies and basic analytics for the merchant.
- Public comments. When someone comments on the merchant’s Instagram post, we receive and store the comment text, the commenter’s Instagram-scoped ID and username, and the reply the app sent, so that the same comment is never answered twice.
How we use information
- To generate and send replies to incoming Instagram DMs.
- To match customer questions against the merchant’s catalog.
- To show the merchant simple usage analytics.
We do not sell personal information or use it for advertising.
Service providers
To operate the app we share the minimum data necessary with:
- Meta / Instagram — to receive messages and send replies through the Instagram messaging API.
- Shopify — to read the merchant’s product catalog.
- Our AI provider — message text and relevant catalog context are sent to a large-language-model provider to compose a reply. This data is processed to produce the response and is not used to train models.
- Langfuse — a record of each AI reply, including the message text sent to and received from the AI provider, is stored so we can monitor quality, diagnose faults and control cost. It is not used to train models.
Data retention
A conversation is deleted automatically once nobody has written in it for 365 days, together with its messages; pending reviews, delivery records and comment records older than 365 days are deleted on the same daily schedule. When a merchant disconnects Instagram, or uninstalls the app, the stored Instagram access token is cleared and every conversation, message, pending review and comment record for that Instagram account is deleted immediately. Shopify notifies us again 48 hours after an uninstall, and we then erase everything that remains — the store record, settings, imported Instagram content and catalog data. Traces held by our tracing provider and copies in backups follow their own retention schedules.
Your choices & data deletion
A merchant can disconnect Instagram at any time, which stops replies and deletes that account’s conversations, or uninstall the app to have all their data deleted. Anyone who has messaged or commented on a store using Replyr can also ask us to erase what we hold about them. To request access to or deletion of your data, email contact@dmreplyr.app — full instructions, and what we can and cannot delete, are on our data deletion page.
Security
Data is transmitted over HTTPS and access tokens are stored on our server. We restrict access to the data to what is needed to operate the service.
Changes
We may update this policy from time to time. Material changes will be reflected by the “Last updated” date above.
Contact
Questions about this policy? Email contact@dmreplyr.app.