Skip to content

SocialReply

Privacy Policy

Effective date: August 4, 2026

Overview

SocialReply is operated by Open Growth Group Inc., a corporation incorporated in the State of Delaware, United States (“Open Growth Group”, “we”, “us”, or “our”). We provide a multi-channel messaging and automation platform that connects to the third-party channels you authorize, including Instagram, Facebook Messenger, WhatsApp, Telegram, TikTok, YouTube, SMS, and email. This Privacy Policy explains what information we collect, how we use it, who we share it with, how long we keep it, and how you can access or delete it. We connect to every channel exclusively through the vendor's official APIs — never by scraping or harvesting credentials. Open Growth Group Inc. is the data controller for account and workspace information, and acts as a processor on your behalf for the contact and conversation data your workspace receives through a connected channel.

Information We Collect

  • Account information you provide when you sign up, such as your name, email, and workspace details.
  • Channel connection data for the third-party accounts you link to your workspace, including encrypted access tokens.
  • Conversation content — inbound and outbound messages, comments, and mentions — needed to power the shared inbox and the automations you configure.
  • Usage and diagnostic data used to operate, secure, and improve the service.

Instagram and Meta Platform Data

Collection. When you connect an Instagram professional account to SocialReply, we collect Meta Platform Data through Meta's official Instagram and Graph APIs only. This includes your Instagram profile information, direct messages, comment and mention content, and delivery and engagement metadata for the messages your workspace sends and receives.

Use. We use Meta Platform Data solely to provide the features you configure: displaying your Instagram conversations in the shared inbox, running the automations and flows you build, enforcing Meta's 24-hour messaging window rules, and reporting on delivery and engagement. We do not sell Meta Platform Data and we do not use it for advertising.

Retention. Instagram and other Meta Platform Data — messages, delivery attempts, flow run history, and related webhook events — is retained for a rolling 24-month window and is then permanently deleted by an automated nightly purge job. Higher-tier plans may configure a longer retention window; no plan retains Meta Platform Data indefinitely. You may request earlier deletion of your data at any time — see the Data Deletion page for both the automatic Meta-triggered path and a direct manual request.

How We Share Information

We do not sell your personal information and we do not share it for cross-context behavioural advertising. We disclose information only to the sub-processors that operate the Service on our behalf, to the channels you explicitly connect (to send and receive the messages you request), and where required by law or to protect our legal rights. Our sub-processors include cloud hosting and storage providers; Meta (Instagram, Messenger, and WhatsApp), Telegram, TikTok, and Google (YouTube) for the channels you connect; Twilio for SMS; Resend and Amazon SES for email delivery; Stripe for subscription billing; and OpenAI and Anthropic for the optional AI features described below. If we are involved in a merger, acquisition, or sale of assets, we will give notice before your information becomes subject to a different privacy policy.

Artificial Intelligence Features

Where you enable AI features — such as suggested replies, intent classification, or automations that include an AI step — the relevant conversation content is sent to our AI provider solely to generate that output for your workspace and that conversation. We do not use your content, or content received from a connected platform, to train or fine-tune any model, and we do not pool it across workspaces. Provider-side training, prompt logging, and reusable prompt caches are disabled where the provider supports those controls. Meta Platform Data is never copied into a durable knowledge base or vector index; only content your workspace authored or uploaded independently of Meta is used that way.

Security

Access tokens are encrypted at rest, every inbound webhook is signature-verified before it is processed, transport is encrypted in transit, and access to your workspace's data is restricted to the roles you assign to your team. No method of transmission or storage is completely secure, so we cannot guarantee absolute security; if we become aware of a breach affecting your personal information, we will notify you and any regulator as required by applicable law.

Your Rights

Depending on where you live, you may have the right to access, correct, delete, or receive a portable copy of your personal information, to object to or restrict certain processing, and to withdraw consent. If you are in the EEA or UK, these rights arise under the GDPR, and our legal bases are performance of our contract with you, our legitimate interests in operating and securing the Service, your consent where required, and compliance with legal obligations. If you are a California resident, you may exercise your rights under the CCPA/CPRA, including the right to know, delete, correct, and opt out of sale or sharing — we do not sell or share personal information as those terms are defined. We will not discriminate against you for exercising these rights. Because Open Growth Group Inc. operates from the United States, your information may be transferred to and processed there and in other countries where our sub-processors operate; where required we rely on Standard Contractual Clauses or another lawful transfer mechanism. Visit our Data Deletion page to start a request, or contact us directly at hello@opengrowthgroup.co. We respond to verified requests within 30 days. See also our Terms of Service for the acceptable-use rules that govern how we connect to your channels.

Children’s Privacy

The Service is not directed to children under 16, and we do not knowingly collect personal information from a child under 16. If you believe a child has provided us with personal information, contact us and we will delete it.

Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will update the effective date above and provide reasonable notice, such as an in-app notice or an email to the address on your account, before the changes take effect.

Contact Us

This Service is provided by Open Growth Group Inc., a Delaware corporation, which is the entity responsible for your information. Questions about this policy, or requests to exercise your rights, can be sent to hello@opengrowthgroup.co or by mail to Open Growth Group Inc., Delaware, United States.