Automating DMs is only worth it if your Instagram account stays protected. Here is exactly how Xreply keeps you compliant with Meta's platform — and what we will never do.
Xreply runs entirely on Instagram's official Graph API. No browser bots, no scraping, no simulated clicks. Every DM and public reply goes through Meta's sanctioned endpoints.
You connect with Instagram Login. We never ask for, store, or touch your Instagram password. Reconnection uses the same official flow.
Access tokens are encrypted before storage and decrypted only in memory for the split second a request is made. They are never logged or exposed.
We pace DMs per account and follow Meta's developer guidelines to avoid rate limits. A failed send is retried with backoff and never spammed.
We keep only what's needed to run your automations — comment text, commenter username, and media ID. Disconnect an account or delete a rule and its data is removed.
This page documents how we handle your account. Questions or deletion requests? Reach out via the support address on the app.
Xreply uses Meta's official Instagram Graph API and Instagram Login. Compliance is reviewed as Meta's platform evolves; we update this page and our docs as policies change. For privacy details see our Privacy Policy, and for usage terms see our Terms of Service.