Legal
Privacy Policy
Last updated: 1 October 2026
This policy explains what personal information Repliva collects, why, how it is used and shared, and the choices you have, including for data from Facebook, Instagram and WhatsApp accounts you connect.
In short
- We store the messages and contacts from the accounts you connect, so your team can answer them in one inbox.
- We use Meta data only to provide that inbox. We never sell it or use it for ads.
- AI features are optional. When enabled, relevant messages are sent to the AI provider you choose.
- You can disconnect accounts at any time and ask us to delete your data. See Data Deletion.
1. Who we are
Repliva is a unified messaging service. It lets businesses connect their Facebook Pages, Instagram Professional accounts, WhatsApp Business phone numbers and an optional website chat widget, and answer the messages they receive from a single shared inbox.
Repliva is operated by Repliva ([LEGAL FORM AND REGISTRATION NUMBER]), Noapara, Abhaynagar, Jashore, PO: 7460, Bangladesh. In this policy, “Repliva”, “we”, “us” and “our” mean Repliva.
Repliva is an independent service. It is not owned, operated, sponsored or endorsed by Meta Platforms, Inc. or by Facebook, Instagram or WhatsApp.
2. Scope of this policy and our role
This policy covers two groups of people, and our role differs between them:
- Our customers and their team members: the people who sign up for Repliva, create a workspace, connect accounts and use the inbox. For their account information, Repliva is the data controller.
- People who message our customers: for example, someone who sends a Facebook Page, Instagram account, WhatsApp number or website chat a message. We process these messages and the related profile details on behalf of the business that received them, and only to provide the service to that business. For this data the business is the controller and we act as its processor (service provider). If you messaged a business that uses Repliva, please contact that business first. It decides how your conversation is used and how long it is kept. We will help it respond to your request.
This policy also covers visitors to our public pages, such as this one and the sign-in pages.
3. Information we collect
Account information
When you create an account or accept an invitation, we collect your first and last name, email address and password. We never store your password itself, only a salted one-way hash (Argon2id). You can also add a phone number, profile photo URL, time zone and language.
Business and workspace information
When you create a workspace, we collect the business name. You can also add a description, industry, website, logo, time zone, currency and business hours. We also record which people belong to each workspace, their roles, and invitations sent to new team members (the invitee’s email address and role).
Authentication and security information
When you sign in, we create a session record containing the IP address and browser user-agent of the device, when the session was created and last used, and when it expires. You can see and revoke these sessions in your account’s security settings. Security-relevant actions (such as signing in, connecting or disconnecting accounts, or changing team roles) are written to an audit log with the IP address and user-agent of the request.
Contact and conversation information
To provide the inbox, we store the messages your connected accounts send and receive. This includes message text, the time of each message, delivery and read status, and links to any attachments (images, video, audio, files, locations). We also store contact records for the people you talk to: display name, profile picture link, platform-specific identifiers and any details you or your team add (email, phone, country, city, notes, tags and custom fields). Internal notes and conversation assignments your team creates are stored too.
Information you add to other features
- Sales: products, and the orders and parcels you record. These can include a customer’s name, phone number, shipping address, the items ordered and tracking details.
- Calls: call records you log or that a connected telephony tool posts to Repliva: direction, status, time, duration, notes and, if provided, a link to a recording stored elsewhere. Repliva does not place calls or store call audio itself.
- AI assistant: the knowledge base content, business instructions and example question-and-answer pairs you provide to train the assistant. Examples can come from your own inbox if you choose to use a past reply as training material.
- Automations and templates: the rules, message templates and saved replies you create.
Website chat visitors
If a business adds the Repliva chat widget to its website, we store the messages a visitor sends and receives. We also store any name, email address or phone number the visitor enters in the optional pre-chat form (or that the website passes to the widget), the page address the message was sent from, and the browser user-agent. The widget saves a random visitor identifier in the visitor’s browser so the conversation continues across page loads. See our Cookie Policy.
Information from Meta platforms
When you connect Facebook, Instagram or WhatsApp, we receive information from Meta. This is described in detail in the next section.
Visitors to our website
Our web servers process the IP address, browser type and requested page of every visitor in order to deliver the page and protect the service against abuse (for example, by rate limiting). We do not use analytics or advertising trackers on our website or in the app.
4. Information we receive from Facebook, Instagram and WhatsApp
Connecting an account is always your choice. You start it from the Integrations page, and you sign in to Meta and approve the requested permissions on Meta’s own screens. We never see or store your Facebook password. We only receive what you authorize, and only for the Pages, Instagram accounts and WhatsApp numbers you choose to connect.
| Source | What we receive and store | Why |
|---|---|---|
| Your Facebook login | Your Meta user ID and name, and an access token (stored encrypted). | To identify the connection and to list the Pages and business assets you can connect. |
| Facebook Pages | Page ID, name, category, profile picture link and a Page access token (stored encrypted). | To show you which Pages you can connect, receive their Messenger messages and send your replies. |
| Instagram Professional accounts | Instagram account ID, username, name and profile picture link of the account linked to your Page. | To receive Instagram Direct messages and send your replies. |
| WhatsApp Business | WhatsApp Business Account ID, phone number ID, display phone number, verified business name and quality rating. | To receive WhatsApp messages sent to your number and send your replies. |
| People who message you | Their platform-scoped ID (Messenger PSID, Instagram-scoped ID or WhatsApp phone number). Profile details Meta makes available: first and last name, profile picture and locale on Messenger; name, username and profile picture on Instagram; profile name on WhatsApp. | To show who each conversation is with and group their messages into one contact. |
| Messages and events | Message text, attachment links, timestamps, and delivery, read, postback and referral events delivered by Meta webhooks. | To display conversations in your inbox, run your automations and track delivery status. |
Attachments (photos, videos, voice notes, files) are stored as links that point to Meta’s servers. We do not copy the files to our own storage. For troubleshooting, we also keep a technical log of the webhook notifications Meta sends us, which contain the same message information.
We use Meta data only to provide the messaging features you asked for. See our Meta Platform Data commitments below and our Meta Integration Disclosure for the list of permissions and why each is needed.
5. How we use information
- Providing the unified inbox: receiving, storing and displaying messages from your connected channels, and sending the replies you or your team write.
- Message synchronization: keeping conversations, contacts, delivery and read status up to date across your connected accounts.
- Automation and messaging features: running the automation rules you configure (for example greetings, tagging, assignment and follow-ups) and, if you enable it, generating AI replies or reply suggestions (see the next section).
- Team collaboration: assignments, internal notes, notifications and role-based access within your workspace.
- Customer support: answering your questions and investigating problems you report.
- Security and fraud prevention: authenticating users, detecting and preventing abuse, rate limiting, keeping audit logs and enforcing our Acceptable Use Policy.
- Service improvement: understanding how the service performs (for example error rates and delivery failures) so we can fix and improve it. We do not use your conversations to train general-purpose AI models. Conversation text becomes training material only when you add it to your own workspace’s assistant.
- Legal compliance: meeting legal obligations, responding to lawful requests and establishing or defending legal claims.
- Service communications: sending messages about your account, such as security notices, invitations and password resets.
6. Legal bases for processing (EEA and UK)
Where the EU or UK General Data Protection Regulation applies, we rely on the following legal bases:
- Performance of a contract: to create and run your account and workspace and to provide the features you use.
- Legitimate interests: to keep the service secure, prevent abuse, provide support and improve the service. We balance these interests against your rights.
- Legal obligation: where we must keep or disclose information by law.
- Consent: where the law requires it. You can withdraw consent at any time.
For messages and contact data we process on behalf of a business, that business is responsible for having its own legal basis.
7. AI and automation features
AI replies and suggestions are optional and are configured per workspace. When they are enabled, the relevant conversation history, the customer’s latest message and matching passages from your knowledge base are sent to the AI provider selected for your workspace (Anthropic or OpenAI) to generate a response. If OpenAI is selected, knowledge base text may also be sent to OpenAI to create search embeddings. When no external AI provider is configured, a built-in assistant runs entirely on our own servers.
AI-generated and automated messages are sent on your behalf. You decide whether they are sent automatically or suggested for review, and you can turn them off for any conversation.
9. Meta Platform Data commitments
For data we receive from Meta’s platforms:
- We use it only to provide the messaging features you have enabled in Repliva.
- We do not sell, license or rent it, and we do not use it for advertising, profiling, data brokering or building data sets unrelated to your use of Repliva.
- We share it only with the service providers listed above, and only to operate Repliva.
- Access tokens are encrypted at rest (AES-256-GCM) and are never shown in the app.
- When you disconnect, we delete the stored access tokens and stop syncing. You can also ask us to delete the rest of the data at any time (see Data Deletion Instructions).
- We comply with the Meta Platform Terms and Developer Policies.
11. Data retention
- Account and workspace data is kept for as long as the account or workspace exists.
- Conversations, contacts and related records are kept until you delete them, your workspace is deleted, or you ask us to delete them. We do not delete old conversations automatically, because they are your business records. You control their retention.
- Access tokens for Meta accounts are deleted when you disconnect.
- Session records, audit logs and webhook logs are kept while the related account or workspace exists, to secure the service and investigate problems.
- Backups are rotated automatically. Deleted data stays in backup copies until they are overwritten (currently within 14 days).
- Deletion request records (the reference, date, scope and outcome) are kept after the deletion is done, so we can show we honored it.
We may keep limited information for longer where the law requires it, or to resolve disputes and enforce our agreements.
12. Deleting your data
You can:
- Disconnect any Facebook Page, Instagram account or WhatsApp number from the Integrations page, or disconnect Meta entirely.
- Delete individual contacts, which also deletes their conversations and messages.
- Request deletion of your account, your whole workspace, or only the messaging data synced from connected platforms from the Delete account page when signed in, or by emailing support@repliva.site.
We complete verified deletion requests within 30 days. Step-by-step instructions are on our Data Deletion Instructions page.
13. Your rights
Depending on where you live, you may have the right to:
- access the personal information we hold about you and get a copy of it;
- correct inaccurate information;
- have your information deleted;
- restrict or object to certain processing;
- receive your information in a portable format;
- withdraw consent where processing is based on consent; and
- lodge a complaint with your local data protection authority.
You can update most account details yourself in Repliva. For anything else, email support@repliva.site. We may need to verify your identity before acting on a request, and we respond within the time the law requires. If you messaged a business that uses Repliva, please send your request to that business. We will support it in responding.
14. International data transfers
Our servers are located in [HOSTING REGION]. Meta, Anthropic and OpenAI may process data in the United States and other countries. Where personal data from the EEA or UK is transferred to a country without an adequacy decision, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses offered by those providers.
15. Security
We protect information with measures appropriate to its sensitivity, including:
- encryption in transit (HTTPS) between your browser, our servers and Meta;
- encryption at rest for Meta access tokens (AES-256-GCM);
- Argon2id password hashing, and hashing of session refresh tokens;
- HTTP-only, secure session cookies;
- strict separation of each workspace’s data, and role-based permissions inside it;
- rate limiting, verification of Meta webhook signatures, and audit logging.
No system is perfectly secure. If we become aware of a breach affecting your personal information, we will notify you and the relevant authorities as the law requires.
16. Children’s privacy
Repliva is a business tool and is not directed to children. Account holders must be at least 18 years old (or the age of majority where they live). We do not knowingly collect personal information from children through our website or app. Businesses that use Repliva are responsible for how they handle messages from their own customers, including minors. If you believe a child has given us personal information, contact us and we will delete it.
17. Changes to this policy
We may update this policy as the service changes. For example, if we add a new messaging channel or service provider, we will update this page and the “Last updated” date. If a change is material, we will also notify account owners in the app or by email before it takes effect.
18. Contact us
For privacy questions or requests, email support@repliva.site. You can also reach us by post at Noapara, Abhaynagar, Jashore, PO: 7460, Bangladesh.
More ways to reach us are on our Contact page.
