Privacy Policy
Last updated: June 3, 2026 · Effective: June 3, 2026
MyChatReply is a messaging management platform that connects your Facebook and Instagram pages. We take your privacy seriously and are committed to protecting your personal data.
1. Who We Are
MyChatReply ("we", "us", "our") operates the website mychatreply.com and provides a SaaS platform for managing social media messages. For privacy enquiries, contact us at [email protected].
2. Information We Collect
Account Information
- Name and email address when you create an account
- Password (stored as a hashed value — we never store plain-text passwords)
- Billing information (subscription plan, payment status)
Facebook / Instagram Data
When you connect a Facebook or Instagram page, we collect and store:
- Page name and Page ID
- Page access token (used to send messages on your behalf)
- Messages sent to and from your connected pages
- Sender IDs of people who message your pages
- Message delivery and read receipt timestamps
- Attachments (images, videos, audio, files) shared in conversations
Usage Data
- Log data (IP address, browser type, pages visited, timestamps)
- API usage and webhook delivery logs
3. How We Use Your Information
- To provide and operate the MyChatReply service
- To display messages from your connected Facebook/Instagram pages in your dashboard
- To send messages via Facebook/Instagram on your behalf when you reply in the dashboard
- To process subscription payments and send invoices
- To send transactional emails (account confirmation, subscription notices, renewal reminders)
- To deliver webhook notifications to your configured endpoints
- To improve and maintain the platform
We do not sell your data or your customers' data to any third party. We do not use message content for advertising.
4. Facebook Platform Data
MyChatReply uses the Meta (Facebook) Platform. By connecting your Facebook or Instagram pages, you authorise us to access and process messaging data on your behalf under the Meta Platform Policy.
- We only access data that is necessary to provide the messaging management service
- We do not use Facebook data for any purpose other than providing the service you requested
- Message data is stored securely in our database and is accessible only to you and your authorised team members
- You can disconnect your pages at any time from the Pages section of your dashboard
- When you disconnect a page, we stop receiving new messages from that page
5. Data Retention
- Messages: Retained for the duration of your account. Deleted 90 days after account closure.
- Account data: Retained while your account is active and for 30 days after deletion
- Billing records: Retained for 7 years for legal/tax compliance
- Log data: Retained for 90 days
6. Data Sharing
We share data with third-party services only as necessary to operate the platform:
- Meta (Facebook): To send and receive messages via the Messenger API
- NowPayments: For processing cryptocurrency subscription payments
- Resend: For sending transactional emails
- DigitalOcean: For hosting infrastructure and database storage
All third-party providers are contractually required to protect your data and may only use it for the specific purpose of providing their service to us.
7. Security
- All data is transmitted over HTTPS (TLS encryption)
- Passwords are hashed using BCrypt before storage
- Page access tokens are stored encrypted in our database
- API keys and secrets use HMAC-SHA256 signing for webhook verification
- Database access is restricted to authorised systems only
8. Your Rights
Depending on your location, you may have the following rights:
- Access: Request a copy of the personal data we hold about you
- Correction: Request correction of inaccurate data
- Deletion: Request deletion of your account and associated data
- Portability: Request your data in a machine-readable format
- Objection: Object to certain types of processing
To exercise any of these rights, email us at [email protected].
9. Cookies
We use essential cookies only:
- Session cookie: Keeps you logged in during your browser session
- Authentication cookie: Maintains your login state between visits
We do not use advertising cookies or third-party tracking cookies.
10. Children's Privacy
MyChatReply is not directed to children under 13. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us at [email protected].
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by email or by posting a notice on the platform. Continued use of the service after changes constitutes acceptance of the updated policy.
12. Contact
For privacy questions, data requests, or to report a concern: