Privacy Policy
Last updated 10 August 2026
Flivy is a social automation tool. This page explains exactly what Instagram and Facebook data we access through Meta's official Graph API, why we access it, how long we keep it, and how you or the people who message you can have it deleted.
Who we are
Flivy (“we”) provides software that lets a business or creator automate replies to public comments and direct messages on Instagram and Facebook. We are not affiliated with, endorsed by, or sponsored by Meta Platforms, Inc.
If you are a member of the public who received a message from a business using Flivy, that business is the data controller for your conversation. We process it on their behalf. Contact them first, or write to us at privacy@flivy.co and we will route your request.
Meta platform data we access
We request the narrowest set of permissions that supports the features we actually ship:
- instagram_basic / instagram_business_basic — your account’s id, username, profile picture and the list of your own posts, so we can show a post picker when you build an automation.
- instagram_manage_comments — read comments on your posts, post public replies, and hide spam on your behalf.
- instagram_manage_messages — receive and send direct messages so automations and your shared inbox work.
- pages_show_list, pages_manage_metadata — let you choose which Facebook Page to connect and subscribe it to webhooks.
- pages_messaging, pages_read_engagement, pages_manage_engagement — Messenger automation and replies to Page post comments.
We do not request permissions for features we have not built, and we never ask for your Instagram or Facebook password. Access is granted by you through Meta’s own OAuth screen and can be revoked at any time from your Meta account settings or from Flivy’s Settings page.
What we store
- Your account. Name, email, workspace, team membership and role.
- Connected accounts. Instagram/Facebook account id, username, granted permissions, webhook subscription state, and an encrypted access token. Tokens are encrypted with AES-256-GCM using a key held outside the database and are never returned to any browser.
- End-user data. For people who comment on your posts or message you: their platform id, username, display name, profile picture URL, the content of comments and messages exchanged with you, and any tags or custom fields your automations record — including an email address or phone number, but only when the person supplies it in reply to a question your flow asked.
- Operational records. Raw webhook payloads, delivery outcomes, and audit entries, used for debugging, replay after a bug, and abuse investigation.
How long we keep it
- Raw webhook payloads: 30 days, then deleted.
- Messages and contact records: for as long as the workspace is active, and 30 days after it is closed.
- Encrypted access tokens: deleted immediately when you disconnect an account.
- Audit log entries: 24 months, because team accounts and App Review both depend on them.
- Opt-out records: kept indefinitely, because forgetting an opt-out would let us message someone again.
Who we share it with
We do not sell personal data and we do not use message content to train models. We use a small number of processors purely to run the service: Supabase (database and authentication, hosted in Mumbai), Vercel (application hosting), Inngest (background jobs), Upstash (rate limiting), Resend (transactional email), Razorpay (payments), Anthropic (only when you enable the AI reply node, and only for the specific message being answered), and Sentry/PostHog (error and product analytics, with message content excluded).
Your rights
You can export your contacts as CSV at any time, delete individual contacts and conversations from the app, and delete an entire workspace from Settings. Under the Indian DPDP Act and the GDPR you may also request access, correction, erasure or portability by writing to privacy@flivy.co. We respond within 30 days.
Anyone who has messaged a business using Flivy can request deletion of their data directly — see our data deletion instructions.
Security
Every tenant table enforces Postgres row-level security with a default-deny policy, so one workspace cannot read another’s data even if application code has a bug. Access tokens are encrypted at rest. Webhook payloads are verified with an HMAC signature before we process them.
Contact
privacy@flivy.co