everyreply

Privacy Policy

Last updated: August 2026

Who we are

EveryReply is a comment-to-DM automation tool for Instagram professional accounts. It is operated by 8x Social, Inc., a Delaware C Corporation, and in this policy “EveryReply”, “we”, and “us” mean 8x Social, Inc. acting as the controller of the information described below.

You can reach us at privacy@8x.social. Our postal address is 1111B S Governors Ave STE 47647, Dover, DE 19904, United States.

For data protection questions under the GDPR, contact Muhammad Zaeem Ul Hassan at zaeem@8x.social.

Information you give us

When you create an EveryReply account we collect:

  • Your name and email address.
  • A password, which we store only as a salted hash. We never see or store your password in readable form.
  • The automations, reply templates, keywords, and message text you write inside the product.
  • Billing details if you subscribe to a paid plan. Card numbers go directly to our payment processor and never reach our servers.
  • Anything you send us in a support message.

Information we receive from Meta

When you connect an Instagram professional account, you grant EveryReply permission to access data through Meta’s APIs. We receive and store:

  • Your account profile. Instagram account ID, username, account type, profile picture, follower count, and the Facebook Page linked to the account.
  • Access tokens. The token that lets us act on your behalf. It is encrypted at rest and never shared.
  • Your posts and reels. Media ID, caption, thumbnail, permalink, and timestamp, so you can pick which post an automation watches.
  • Comments on your posts. Comment text, timestamp, comment ID, and the commenter’s Instagram-scoped ID and username. We need this to decide whether a comment matches one of your keywords.
  • Direct messages. Messages sent and received through your connected account, including message content, timestamps, and the Instagram-scoped ID of the person you are talking to. This covers the replies EveryReply sends and the conversation that follows.
  • Aggregate insights. Counts of comments, replies, and conversations, used to build the reporting screens.

We ask only for the permissions the product actually uses. Those are the ability to read your basic account details, read and reply to comments on your own posts, and send and receive direct messages for your account. We do not request permission to publish posts, run ads, or read anything outside the accounts you connect.

Information we collect automatically

  • Log data: IP address, browser type, device type, pages viewed, and timestamps.
  • Cookies that keep you signed in and remember your settings. We do not use advertising cookies or third-party trackers for behavioural advertising.
  • Error reports when something in the product breaks.

How we use this information

  • To run the core feature: watch comments on your posts, match them against your keywords, and send the direct message you configured.
  • To show you your inbox, contacts, automations, and reporting.
  • To authenticate you and keep your account secure.
  • To respond to support requests.
  • To bill you if you are on a paid plan.
  • To detect abuse, spam, and attempts to break the service.
  • To comply with legal obligations and with Meta’s Platform Terms.

We do not sell your data. We do not sell or rent data received from Meta. We do not use data received from Meta to build advertising profiles, to train machine learning models for unrelated purposes, or for any purpose other than delivering the features you enabled.

Legal bases for processing

If you are in the European Economic Area or the United Kingdom, we process your information on these bases. Performance of a contract, for everything needed to deliver the service you signed up for. Legitimate interests, for security, abuse prevention, and product improvement. Consent, for the Instagram permissions you grant, which you may withdraw at any time. Legal obligation, where the law requires us to keep records.

Who we share information with

We share information only with service providers that help us run EveryReply, and only to the extent they need it. These are our cloud hosting and database provider, our transactional email provider, our payment processor, and our error monitoring provider. Each is bound by a contract that limits what they may do with the data.

We may also disclose information if we are legally required to, or to protect the rights and safety of our users. If EveryReply is acquired, information may transfer to the acquirer, and we will tell you before that happens.

How long we keep it

Account data is kept while your account is open. Comment and message records are kept for as long as you need them in your inbox, and are deleted within 90 days of you disconnecting the Instagram account they belong to. Access tokens are deleted immediately when you disconnect an account or delete your EveryReply account. Logs are kept for 30 days. Billing records are kept for as long as tax law requires.

When you delete your account, we delete all data associated with it, including everything received from Meta, within 30 days.

How to request deletion of your data

You can have your data deleted in any of these ways.

  • Open Settings inside EveryReply and choose Delete account. This removes everything, including all data received from Meta, within 30 days.
  • Disconnect a single Instagram account from the Accounts screen. This deletes the access token immediately and the associated Meta data within 90 days.
  • Email privacy@8x.social with the subject “Data deletion request” and the email address or Instagram username on the account. We confirm within 5 business days and complete the deletion within 30 days.
  • Remove EveryReply from your Facebook settings, under Settings & Privacy, then Settings, then Apps and Websites. Meta sends us the request and we delete the associated data.

Full step-by-step instructions live on our data deletion page.

Your rights

Depending on where you live, you may have the right to access the data we hold about you, correct it, delete it, receive a portable copy, object to or restrict certain processing, and withdraw consent. Email privacy@8x.social and we will respond within 30 days. Data exports are provided in a structured, machine-readable format, either JSON or CSV. You also have the right to complain to your local data protection authority, sometimes called a supervisory authority, if you think we have not handled your concern properly.

California residents have the right to know what personal information we collect and to request its deletion. We do not sell personal information as that term is defined under California law.

Security

All traffic runs over HTTPS. Access tokens and message content are encrypted at rest. Access to production systems is limited to the people who need it and is protected by multi-factor authentication. No system is perfect, so if a breach affects your data we will notify you and the relevant authorities as the law requires.

If you find a security vulnerability, report it to security@8x.social rather than disclosing it publicly, and we will work with you on a fix.

International transfers

Our servers are in the United States, and information may also be processed in the European Union. If you use EveryReply from elsewhere, your information is transferred to those countries, which may have different data protection laws from your own.

Where a transfer needs a safeguard, we use one of the following. The European Commission’s Standard Contractual Clauses for transfers out of the EEA or the UK. Adequacy decisions, where the destination country is recognised as providing adequate protection. Data processing agreements requiring GDPR-equivalent protection from every service provider. Encryption and access controls apply throughout.

Children

EveryReply is a business tool and is not intended for anyone under 18. We do not knowingly collect information from children. If you believe a child has given us information, email us and we will delete it.

Meta and Instagram

EveryReply is an independent product. It is not affiliated with, endorsed by, or sponsored by Meta Platforms, Inc. Instagram and Facebook are trademarks of Meta. Your use of Instagram is governed by Meta’s own terms and privacy policy, which we do not control.

Changes to this policy

If we change this policy in a way that materially affects your rights, we will give you at least 30 days notice by email to your registered address, and update the date at the top of this page. If you do not agree with the new policy, you can delete your account before it takes effect.

Contact

Questions about this policy, and any request to exercise your rights, go to privacy@8x.social. For help using the product, write to support@8x.social. You can also reach us by post at 8x Social, Inc., 1111B S Governors Ave STE 47647, Dover, DE 19904, United States.

Back to EveryReply