Safety & Compliance

Your account stays safe with Xreply

Automating DMs is only worth it if your Instagram account stays protected. Here is exactly how Xreply keeps you compliant with Meta's platform — and what we will never do.

Official Meta API only

Xreply runs entirely on Instagram's official Graph API. No browser bots, no scraping, no simulated clicks. Every DM and public reply goes through Meta's sanctioned endpoints.

Instagram Login (OAuth) — no password

You connect with Instagram Login. We never ask for, store, or touch your Instagram password. Reconnection uses the same official flow.

Tokens encrypted at rest

Access tokens are encrypted before storage and decrypted only in memory for the split second a request is made. They are never logged or exposed.

Built-in rate limiting

We pace DMs per account and follow Meta's developer guidelines to avoid rate limits. A failed send is retried with backoff and never spammed.

Minimal data, clear retention

We keep only what's needed to run your automations — comment text, commenter username, and media ID. Disconnect an account or delete a rule and its data is removed.

Safe by design, transparent by default

This page documents how we handle your account. Questions or deletion requests? Reach out via the support address on the app.

What we will never do

  • Ask for your Instagram password.
  • Use browser bots, headless browsers, or scraping.
  • Send messages beyond Meta's rate limits.
  • Share or sell your comment data or audience lists.

Xreply uses Meta's official Instagram Graph API and Instagram Login. Compliance is reviewed as Meta's platform evolves; we update this page and our docs as policies change. For privacy details see our Privacy Policy, and for usage terms see our Terms of Service.