1. Who this covers

Lavin Reply is a service that reads messages and comments from the Facebook Pages and Instagram accounts you connect, and sends replies on their behalf according to rules you configure. This policy covers the Lavin Reply website and application. It does not cover Meta's own handling of your data, which is governed by Meta's privacy policy.

2. What we collect

Account data you give us directly:

  • Your name and email address, used to identify your account.
  • Your password, stored only as a hash by our authentication provider — we never see or store the password itself.

Data received from Meta when you connect an account:

  • Page and Instagram account identifiers, names and profile pictures for the accounts you select.
  • Page access tokens, which allow Lavin Reply to read messages and send replies as that Page. These are credentials and are treated as secrets.
  • The content of direct messages sent to your connected accounts, including text, attachments' metadata, timestamps, and the sender's platform ID and display name.
  • The content of comments left on your posts, including text, timestamps, and the commenter's platform ID and display name.

Data the service generates:

  • A log of the replies Lavin Reply sent, which rule matched, and when.
  • Webhook delivery records used to avoid replying to the same event twice.
  • Basic technical logs such as error traces and request timestamps.

We do not collect data from your personal Facebook profile beyond what is needed to establish that you administer the accounts you connect, and we do not post to your personal profile.

3. Why we collect it

  • Message and comment content is matched against your reply rules — this is the core function of the service and it cannot work without reading the message.
  • Page access tokens are required by Meta's APIs to read and send on behalf of a Page you administer.
  • The reply log exists so you can see what was sent in your name and correct a rule that behaved unexpectedly.
  • Webhook records prevent duplicate replies when Meta re-delivers the same event.
  • Account data identifies you and controls what you and your team members can access.

We do not sell your data, we do not share it with advertisers, and we do not use message or comment content to train machine learning models.

4. How it is stored

Data is stored in a managed Postgres database provided by Supabase, hosted in a data centre region selected for the project. Access is restricted by row level security so an account can only read its own records. Data is encrypted in transit over HTTPS and encrypted at rest by the hosting provider.

Page access tokens are held server-side only. They are never sent to the browser and never exposed in the application interface.

5. How long we keep Meta Platform Data

DataRetention
Page and Instagram access tokensDeleted immediately when you disconnect the Page, or when you close your account
Message and comment content, and the sender's platform ID and display nameKept for 90 days on a rolling basis while the Page is connected, so you can see your recent reply history. Older content is deleted automatically.
All Meta Platform Data after you disconnect a Page or close your accountDeleted within 30 days
Reply log metadata with no message content (timestamp, rule triggered, delivery status)12 months
Billing and invoice records7 years, as required by Estonian accounting law

You can ask us to delete Meta Platform Data sooner at any time — see our Data Deletion page. We do not use the content of your customers' messages or comments to train any machine-learning model.

6. Who else sees it

Data is shared only with the service providers needed to run Lavin Reply: Meta (to receive events and send replies), Supabase (database and authentication) and our application hosting provider. Each processes data on our instructions. We may disclose data if required by law.

Inside your own account, team members you invite can see the inbox and the reply log for the Pages they are given access to.

7. Disconnecting a Page

You can disconnect a Page or Instagram account at any time from the connection settings in the application. Disconnecting immediately stops Lavin Reply from receiving events for that account and from sending any further replies, and deletes the stored access token for it.

You can also remove Lavin Reply from the outside, in your Facebook settings under Business Integrations. Doing so revokes our access even if you cannot reach the application.

8. Requesting deletion

To have your data deleted, email privacy@allsaferai.com from the address on your account and say which you want: deletion of a specific connected Page's data, or deletion of your whole account.

We will confirm the request and complete it within 30 days, then write back to tell you it is done. Deleting your account removes your profile, your rules, your reply log and all stored message and comment content. Backups are rotated out within a further 30 days.

9. Your choices

You can ask for a copy of the data held about you, ask for it to be corrected, or object to how it is being processed, using the same contact address. If you are in a jurisdiction that grants you statutory data protection rights, this policy is not intended to limit them.

10. Changes

If this policy changes materially, we will update the date at the top and notify account holders by email before the change takes effect.

11. Contact

Questions about this policy or about your data can go to privacy@allsaferai.com.

Privacy Policy — Lavin Reply