Privacy policy
Last updated: 18 September 2026
This explains what Riplo collects, why, and what you can ask us to do with it.
What we never collect
Your Instagram password. Riplo connects through Meta's official API, you approve access on Meta's own screen, and the password never reaches us.
What we do collect
- Account details — the email address and business name you register with.
- Instagram connection — the access token Meta issues, stored encrypted, plus the account's public username and profile picture.
- Automation data — the rules you write and a record of which ones ran.
- Conversation data — messages and comments that trigger your rules, so replies can be sent and shown to you.
- Payment records — plan, amount and a reference from the payment provider. We do not store full card numbers.
Why we need it
To run the service you asked for: matching keywords, sending replies, showing you what happened, and billing the right plan. We do not sell personal data and we do not use your conversations to advertise to you.
How long we keep it
Account and automation data stays while your account is open. Conversation data is kept for a limited period and then removed automatically. When you close your account we delete your data, except records we must keep for accounting or legal reasons.
Access tokens
The Instagram access token is encrypted before it is stored. You can revoke Riplo's access at any time from your Meta settings, which immediately stops the automations.
Your rights
- Ask for a copy of the data we hold about you.
- Ask us to correct anything inaccurate.
- Ask us to delete your account and its data.
- Withdraw the Instagram access you granted, at any time, from Meta.
Write to hello@riplo.co and we will respond.
Changes
If we change this policy in a way that affects you, we will tell account holders before it takes effect.