Privacy information
Updated: 30 September 2026
Service operator: Metis One
Contact: info@metisone.com
Data we use
bots stores your login email, password hash, language, workspace membership, connected Instagram account identifiers and encrypted access tokens. Bot settings include target posts, keywords and response text. Received comment identifiers, content and processing results are used to run your automations and prevent duplicate replies. We do not request your Instagram password.
Purpose and access
We use this data to authenticate users, connect accounts, execute configured bots, display activity and protect the service. Users access their authorized workspaces; authorized service administrators can manage customer accounts, bots and operations. Requests needed for the integration are sent to Meta/Instagram. Application data is processed on the service's hosting infrastructure.
Storage and retention
Connected-account tokens are encrypted at rest. Disconnecting removes local credentials and pauses the account's bots; it does not delete all historical records. Completed processing content is redacted after 30 days; terminal event, job and delivery records are removed after 90 days; audit records after 180 days. Pending/running work is excluded from scheduled cleanup. Operational backups are kept on the server for 14 days. User accounts and bot settings remain until removed through the deletion process.
Cookies and choices
A session cookie is used for sign-in, and local browser storage remembers your language. You can disconnect accounts in Connected accounts. To request access, correction or deletion of your service data, contact the operator using the address below.
Account emails
Invitations and password reset emails are sent through Google Workspace. The recipient address, localized message and single-use link are shared with Google. Submission records remain for 30 days; pending links are encrypted and cleared on send attempt or expiry. Reset links last 30 minutes and invitations 7 days. Opening and reading are not tracked. Account deletion also deletes local email and reset records.
Optional visit measurement
Only after separate consent on the public page, a 24-hour HttpOnly measurement cookie is created. The server stores its identifier hash, consent version/time, language and bounded source label/method. The first new invitation request may be linked to this visit, then to recorded signup and product progress of the invited account; administrators see the source beside the account and in aggregate reports. Full URLs, browsing history, advertising IDs and messages are not collected for this measurement. Records are retained for up to 180 days. Withdrawing via the public page while the cookie is valid deletes this visit record and link while preserving your request/account. Afterwards, request deletion of linked records at the contact below. Refusal is remembered for 30 days in a preference cookie without an identifier. Visits by signed-in panel users are excluded. Refusing does not affect access.
Invitation tracking
The known invitation origin, latest creation/expiry and verified signup time are retained with the customer account until account deletion. Administrators see invitation status alongside account email and recorded pilot progress. Links are single-use and valid for 7 days after creation; only token hashes are stored. Link opening or delivery is not tracked, and no email is sent automatically. Specify the scope of account data in deletion requests at the contact address below.
Pilot usage analysis
For product improvement, we store when a customer account entered measurement, whether it was new or existing, and the first observed connection, activation, accepted reply and completed registration per channel. These account-level dates remain until account deletion; weekly presence of useful activity covers the current and previous 12 UTC weeks. Participant IDs, answer contents, visit sources and browsing history are not added to these records. The administrator report shows aggregates only. Account deletion requests can include these records; specify the scope using the contact address below.
Monthly usage measurement
Active-contact measurement stores workspace, channel, technical event identifier, interaction type and time, and a keyed contact pseudonym, without names or message contents. Records cover the current and previous two UTC calendar months; scheduled cleanup removes older periods. Measurement does not apply charges or quotas. Disconnecting a bot or deleting an individual registration does not reset usage. Request separate deletion of usage data at the contact address below; the operator verifies authority and scope before acting.
Support and feedback
Panel requests store account and workspace identifiers, language, platform, category, desired outcome, current workaround, frequency and email contact preference. Only the submitting user and authorized service administrators see the request and response. Data is used for support and product prioritization and deleted after 180 days. Email follow-up is manual and only with permission; no marketing subscription is created. For earlier deletion or to withdraw email permission, contact info@metisone.com. Do not submit passwords, tokens or other people’s private content.
Costs and support time
For service planning, administrators may record expense date, currency, amount, support minutes and a short description, optionally linked to a customer account. Only authorized administrators have access. Records cover the current and previous 11 UTC months; scheduled cleanup removes older records. Account deletion removes the account association; unlinked expense amounts may remain for the retention period. Request earlier deletion or unlinking at the contact address below. These records do not charge customers.
Telegram
For Telegram, Replivra stores bot identifiers, encrypted BotFather tokens, menu settings, form questions, participant Telegram IDs, submitted answers, registration status and operator notes. Requests and replies are exchanged with Telegram. Answers are shown to the authorized bot operator after the participant chooses to continue. Incomplete forms expire after 24 hours. Processed incoming text and terminal outgoing content are cleared after processing; technical update/reply records are retained for 90 days. Registrations are deleted after 180 days without an update. Disconnecting removes local bot credentials and pauses the bot, while registration records remain accessible. No AI provider receives Telegram content in this release.
Invitation requests
The invitation form stores your email, language, platform preference and contact-consent timestamp. These are used to review your request and contact you about an invitation; linking it to optional visit measurement requires separate consent. Only authorized administrators can see requests; they send email manually through their own email application. A request does not create an account or subscribe you to a newsletter. Request records are retained for at most 180 days. For earlier deletion or to withdraw permission to contact you, email info@metisone.com from the address used in your request. Deletion of an account created after invitation must be requested separately.