Legal

Privacy Policy

Last updated: July 23, 2026

Information We Collect

Repleva collects the information you provide when using our platform, including the email address and name you sign up with, the business details you enter during project intake, website URLs you submit for analysis, and the content generated through the platform. We also collect basic account metadata such as login timestamps and the plan you are on.

How We Use Your Information

Your data is used to power the intelligence engines and generate the strategic outputs you create within your projects. We also analyze project data internally — both at the individual and aggregated level — to improve the platform: identifying which intake patterns produce the most useful strategies, where users encounter friction, and how to make the engines more accurate. This analysis is internal to Repleva. We do not sell your data to third parties, and your projects are never shown to other users.

Connected Social Accounts (Instagram, Facebook, LinkedIn)

Repleva can publish a post you created in the platform — a single image and its caption — to a social account you connect yourself. Connecting an account is optional; if you never connect one, none of the following applies to you. This section describes exactly what we receive from those platforms and what we do with it. The same statement in plain language is on our social publishing page.

What we receive

  • Meta (Instagram and Facebook) — when you connect with Facebook Login, we receive an access token, and your Facebook account name and ID. When you publish, we use that token to look up the Facebook Pages you manage and any Instagram professional account linked to them, so the post reaches the right destination.
  • LinkedIn — when you connect, we receive your name, email address, and a LinkedIn member ID, together with an access token.

What we use it for — two things only

First, to identify the account you connected and to find the Facebook Page — and the Instagram professional account linked to it — that your post should go to. Second, to publish the image and caption you created in Repleva, either straight away or at the time you scheduled. We publish only content you created in Repleva and chose to publish. Repleva never posts on its own.

What we do not do

Publishing is all Repleva does with your connected accounts today. It does not read your messages, your comments, the posts already on your account, your follower counts, or your audience statistics, and it does not currently provide analytics, insights, or performance reporting or call the endpoints that would return that data. Should we add performance reporting in future, it would require additional permissions that you would be asked to grant, and we would update this policy before collecting anything new. We never sell the information we receive from Meta or LinkedIn, and we do not pass it to anyone else. Platform data is not used to train models, is not combined with other customers' data, and is not used for advertising.

What we request from the platform

From Meta we request four permissions, each of which maps to a call the publishing feature actually makes: instagram_basic and pages_show_list, to find the Facebook Page and the Instagram professional account linked to it; and instagram_content_publish and pages_manage_posts, to publish your post. We do not request the insights permissions (instagram_manage_insights, read_insights) at all.

What we store, and for how long

We store the access token (encrypted at rest, and never written to our logs), the name and ID of the connected account, and the posts you create and schedule inside Repleva. Tokens are retained only while the connection is active.

Disconnecting and deletion

You can disconnect any account at any time from your connections settings in Repleva; that deletes the stored access token. If you remove Repleva from your Facebook settings instead, Meta notifies us through its deauthorize callback and we delete the connection on our side automatically. You may also submit a data deletion request through Meta; we honour those requests automatically and issue a confirmation code you can use to check the status at /deletion-status. Deleting your Repleva account removes all connections and stored platform data as described under Data Deletion below.

Data Storage

Project data is stored securely and associated with your owner identifier. All data is isolated per owner — no cross-account data access is possible from within the product. To protect against data loss, we maintain encrypted backups in cloud object storage; backups are accessible only to authorized Repleva personnel and are retained on a rolling 72-hour window.

Data Deletion

You can delete your account and all associated data at any time from Account Settings → Danger Zone. Deletion is permanent: your projects, generated outputs, credits, and personal information are removed from our live database immediately — including any connected social accounts and their stored access tokens. Residual copies in our backup storage are purged within 72 hours as the rolling backup window expires. To remove a single connected social account without deleting your Repleva account, disconnect it from your connections settings, or use the deletion request flow described under Connected Social Accounts above.

Third-Party Services

To operate the platform, we work with carefully selected third-party providers across the following categories. Each provider operates under its own privacy and data-processing terms:

  • AI and machine learning providers — used to generate strategic outputs, marketing content, and creative visuals from the inputs you provide. The intake details and prompts we send are processed under each provider's data processing terms.
  • Cloud infrastructure providers — used to host the application, store encrypted database backups, and deliver content globally. Application data is held in secured cloud environments under standard commercial terms.
  • Web content extraction providers — used as a fallback when extracting text from JavaScript-heavy websites you submit for ingestion.
  • Performance and analytics tools — used to measure aggregated, anonymous traffic patterns. No personal identifiers are collected and no tracking cookies are used.
  • Stripe — used to process payments. Your payment card details are sent directly to Stripe and are never stored on Repleva's servers.
  • Meta Platforms (Facebook, Instagram) — used only if you connect an account, to publish the post you created to your own Instagram professional account and Facebook Page. See Connected Social Accounts above.
  • LinkedIn — used only if you connect an account, to publish the post you created to your own LinkedIn profile. See Connected Social Accounts above.

If you require a specific list of named subprocessors for compliance purposes (for example, a GDPR Data Processing Agreement), contact us through the contact page and we will provide one.

Cookies and Sessions

We use cookies to keep you signed in and to remember your preferences. We do not use third-party advertising or tracking cookies.

Your Rights

Depending on your location, you may have rights under data protection laws such as the GDPR (EU) or CCPA (California), including the right to access, correct, or delete your data. You can exercise the right to delete from your Account Settings. For other requests, contact us through the contact page.

Changes to This Policy

We may update this policy as the product evolves. Material changes will be communicated to users by email or in-app notice. The “Last updated” date at the top of this page reflects the most recent change.

Contact

For privacy-related inquiries, please reach out through our contact page.