«أوتوريبلاي برو» أداة تُشغّلها صاحبة أو صاحب حساب واحد على إنستجرام وفيسبوك،
وتقوم مع مَن يعلّق أو يراسل ذلك الحساب بأمرين فقط: الردّ الآلي على التعليقات
التي تُطابِق كلمة مفتاحية محدّدة مسبقاً، والردّ على الرسائل الخاصة الواردة إليه.
وإن ربط صاحب الحساب حساباً على تيك توك أيضاً، فهي تنشر عليه الفيديوهات وكاروسيلات
الصور التي يجدولها، أو ترسلها إلى مسودّاته فيه، ولا تفعل هناك شيئاً غير ذلك. وإن
ربط قناة على يوتيوب، فهي ترفع إليها مقاطعه القصيرة بوصفها
Shorts، ولا تفعل هناك شيئاً غير ذلك. لا
تقوم الأداة بأي نشاط إعلاني أو تسويقي موجّه، ولا تبيع البيانات.
هذه الصفحة تصف ما يحدث لبياناتك أنت — بوصفك مَن علّق على منشور أو أرسل رسالة
خاصة — لا بيانات صاحب الحساب. وهي مكتوبة بحسب ما يفعله الكود فعلاً، لا بحسب
ما ينبغي أن يفعله. والاستثناء هو تيك توك ويوتيوب: بيانات كلٍّ منهما الموصوفة أدناه
تخصّ صاحب الحساب الذي ربطه، لأن الأداة لا تقرأ على أيٍّ منهما شيئاً من أي شخص آخر.
تعمل الخدمة عبر تطبيق مُسجَّل في «منصّة مطوّري ميتا» باسم
AutoResponseBot، وهو الاسم الذي
تجده لدى ميتا، بينما أوتوريبلاي برو هو اسم المنتج نفسه. ويجري
الوصول إلى تيك توك عبر تطبيق منفصل مُسجَّل في «منصّة مطوّري تيك توك»
(TikTok for Developers)، باستخدام
Login Kit
وContent Posting API
وWebhooks، وكلها من منتجات تيك توك
الرسمية. ويجري الوصول إلى يوتيوب عبر مشروع على
Google Cloud، باستخدام واجهة
YouTube Data API
(خدمات واجهة برمجة يوتيوب —
YouTube API Services) وتسجيل الدخول من جوجل
(OAuth 2.0).
تريد حذف بياناتك؟
الطريقة كاملة، ومدى ما يمكن حذفه فعلاً، في
صفحة حذف البيانات.
1. ما يَصل إلينا، وما يُخزَّن فعلاً
هذان أمران مختلفان، والتمييز بينهما هو أصدق ما يمكن قوله: يَصلنا من ميتا أكثر
مما نحتفظ به.
يُخزَّن: معرّف التعليق، ومعرّف المنشور، واسم المستخدم
الظاهر على إنستجرام (أو الاسم المعروض على فيسبوك)، والمنصّة، وحالة
الإرسال، ونصّ أي خطأ أعادته ميتا.
لا يُحفَظ نصّ تعليقك في سجلّ النشاط. يبقى في طابور المعالجة، ضمن
نسخة الحدث التي أرسلتها ميتا: يُحذف تلقائياً بعد 7 أيام من معالجته، ويبقى
إلى أن يُحذف يدوياً إن فشلت معالجته.
يُخزَّن لمدة 48 ساعة: معرّف حسابك عند ميتا مع وقت الإرسال،
وذلك لتطبيق قاعدة «رسالة آلية واحدة لكل شخص في اليوم».
عندما ترسل رسالة خاصة
نصّ رسالتك كما كتبته، واتجاه الرسالة، ونوعها، وأي زرّ
ضغطته، ومعرّف الرسالة عند ميتا.
الحدث الأصلي كما ورد من ميتا، حرفياً وبالكامل. يحتوي هذا
الحدث على نصّ رسالتك ومعرّف حسابك، وهو نسخة ثانية منهما إلى جانب الأعمدة
السابقة. مدة الاحتفاظ به في القسم 4.
معرّف حسابك عند ميتا ووقت آخر رسالة ومتى أُبلغتَ آخر مرة
بأن الردود آلية. لا يُخزَّن اسم المستخدم الخاص بك في مسار الرسائل الخاصة —
المعرّف فقط.
لا نطلب ولا نتلقّى ولا نخزّن بريدك الإلكتروني أو رقم هاتفك أو عنوانك أو بيانات
الدفع. لكن نصّ رسالتك يُخزَّن كما كتبته: إن ذكرتَ فيه معلومة شخصية، فهي مخزّنة
لأنك كتبتها.
عندما يربط صاحب الحساب تيك توك
هذا الجزء يخصّ بيانات صاحب الحساب نفسه. تطلب الأداة من تيك توك ثلاث صلاحيات، لا
غير: user.info.basic
وvideo.upload
وvideo.publish. ولا تسمح أيٌّ منها
بقراءة التعليقات أو الرسائل أو أي حساب آخر، فلا تصلنا أي بيانات عن مشاهدي تيك توك
إطلاقاً.
يُخزَّن، من Login Kit في
تيك توك (صلاحية user.info.basic):
معرّف الحساب open_id — وهو معرّف
يمنحه تيك توك للحساب خاصاً بهذا التطبيق — والاسم المعروض، ورابط الصورة الرمزية.
يُخزَّن مشفّراً: رمزا الوصول والتحديث
(OAuth) اللذان يُصدرهما تيك توك، مشفّرَين أثناء
التخزين بخوارزمية AES-256-GCM (القسم 7).
يُقرأ ولا يُخزَّن: قبل كل نشر مباشر تقرأ الأداة من تيك توك
إعدادات النشر في الحساب — اسمه، ومَن يُسمح بأن يشاهد منشوراته، وهل أوقف صاحبه
التعليقات أو الثنائي (Duet) أو الدمج
(Stitch)، وأطول مدة فيديو مسموحة له — لتعرض
خيارات المنشور، ثم لتتحقّق منها مجدداً وقت النشر.
الفيديوهات والصور التي يجدولها صاحب الحساب وأوصافها تُخزَّن
لتُنشَر في موعدها. ولا تقبل واجهة تيك توك موعداً للنشر، فيخرج المنشور حين يعمل
طابور الأداة بعد موعده، لا بدقّة الدقيقة. بصلاحية
video.publish يُنشَر مباشرةً على
حسابه في تيك توك («النشر المباشر»)؛ وبصلاحية
video.upload يُرسَل إلى مسودّاته
في تيك توك (صندوق الوارد)، فيُكمله وينشره بنفسه من تطبيق تيك توك. ملف الفيديو
ترسله الأداة إلى تيك توك، أمّا الصور فيجلبها تيك توك بنفسه من عنوان الأداة على
الويب، وهو عنوان مُوثَّق في بوابة مطوّري تيك توك.
إلى أن تعتمد تيك توك التطبيق بعد مراجعته، يُنشَر كل منشور مباشر
بخصوصية «أنا فقط»، ولا يقبله تيك توك إلا والحساب نفسه مضبوط على «خاص». فلا
يُنشَر شيء علناً نيابةً عن صاحب الحساب قبل ذلك.
إعدادات كل منشور مباشر: مَن يمكنه مشاهدته، والسماح بالتعليقات
والثنائي والدمج، والإفصاح عن المحتوى التجاري، وموافقة صاحب الحساب الصريحة على
النشر — يختارها كلها بنفسه في الأداة قبل جدولة المنشور. أمّا منشورات «استوديو
الكاروسيل» فتحمل إعدادات ثابتة: «أنا فقط» إلى أن تعتمد تيك توك التطبيق و«الجميع»
بعد ذلك، والتعليقات مسموحة، ووسم الترويج لعلامته التجارية؛ وضغطته لإرسالها هي
موافقته. وإعدادات المسودّة يختارها في تيك توك نفسه.
نتائج حالة النشر: ما يُبلغ به تيك توك عن كل منشور — قيد
المعالجة، أو وصل إلى المسودّات، أو نُشر، أو فشل — مع نصّ أي خطأ أعاده تيك توك،
ومعرّف المنشور على تيك توك إن كان علنياً. تصل الحالة عبر إشعارات تيك توك
(post.publish.*)، ويسأل عنها
طابور الأداة أيضاً في كل مرة يعمل.
تُستخدم بيانات تيك توك لتقديم ميزة النشر فقط. لا تُباع أبداً، ويُحذف
اتصال تيك توك عندما يفصله صاحب الحساب — الخطوات في
صفحة حذف البيانات. أمّا المنشورات المجدولة التي
أنشأها صاحب الحساب في لوحة التحكم، ومنها حالة نشرها على تيك توك، فتبقى فيها إلى أن
يحذفها بنفسه، كما هو الحال مع منشورات إنستجرام وفيسبوك.
عندما يربط صاحب الحساب يوتيوب
وهذا الجزء أيضاً عن بيانات صاحب الحساب نفسه. تستخدم «أوتوريبلاي برو»
خدمات واجهة برمجة يوتيوب
(YouTube API Services). وبربط قناة على يوتيوب يوافق
صاحب الحساب على الالتزام
بشروط خدمة يوتيوب،
أمّا تعامل جوجل نفسها مع البيانات فتصفه
سياسة خصوصية جوجل.
تطلب الأداة من جوجل صلاحيتين لا غير:
youtube.upload لرفع الفيديوهات إلى القناة،
وyoutube.readonly التي لا تُستخدم إلا
لقراءة اسم القناة وصورتها كي تُظهر لوحة التحكم أيّ قناة مربوطة. ولا تُستخدم أيٌّ منهما
لقراءة التعليقات أو الرسائل أو المشتركين أو قناة أي شخص آخر، فلا تصلنا أي بيانات عن
مشاهدي يوتيوب.
يُخزَّن، من يوتيوب: معرّف القناة واسمها ومعرّفها المختصر
(@handle) ورابط صورتها. وما دامت القناة مربوطة،
يُعاد قراءة الاسم والصورة من يوتيوب مرة كل يوم، فلا يزيد عمرهما على يوم.
يُخزَّن، مشفّراً: رمزا الوصول والتحديث
(OAuth) اللذان تُصدرهما جوجل، مشفّرَين أثناء التخزين
بخوارزمية AES-256-GCM (القسم 7)، وقائمة الصلاحيات
الممنوحة.
الفيديوهات التي يجدولها صاحب الحساب، بعناوينها وأوصافها، تُخزَّن
لتُرفع في موعدها، عند أول تشغيل لقائمة الانتظار في الأداة بعده. يُرفع كلٌّ منها إلى
قناة صاحب الحساب بوصفه Short، مُعلَناً أنه غير موجّه
للأطفال، ويُحفظ معرّف الفيديو الذي يعيده يوتيوب لتربط لوحة التحكم إليه.
إلى أن تُكمل جوجل مراجعتها للتطبيق، يُرفع كل فيديو خاصّاً: يوتيوب
يُبقي فيديوهات التطبيقات التي لم يراجعها خاصّة، والأداة تطلب الخصوصية أصلاً. فلا
يُنشَر شيء علناً باسم صاحب الحساب قبل ذلك.
لا شيء عن أي شخص آخر: لا تقرأ الأداة بيانات عن مشاهدي يوتيوب ولا
تخزّنها ولا تشاركها، ولا تعرض إعلانات، ولا تسمح لأي طرف ثالث بوضع محتوى أو إعلانات
أو ملفات تعريف ارتباط (cookies) عبر ميزات يوتيوب فيها.
تُستخدم بيانات يوتيوب لتقديم ميزة الرفع فقط. لا تُباع أبداً، ولا تُشارَك مع أحد
غير جوجل التي تتلقّى الفيديوهات. ويستطيع صاحب الحساب سحب وصول الأداة في أي وقت:
من لوحة التحكم (الإعدادات ← يوتيوب ← افصل يوتيوب)، فيُلغى الوصول لدى جوجل ويُحذف
الاتصال المحفوظ فوراً، أو من إعدادات الأمان في حساب جوجل على
security.google.com/settings/security/permissions.
والوصول المسحوب من هناك تكتشفه الأداة في فحصها اليومي التالي، فتحذف الرمزين المخزّنين
واسم القناة وصورتها.
2. لماذا نستخدم هذه البيانات
معرفة ما إذا كان التعليق يُطابِق كلمة مفتاحية لحملة قائمة.
إرسال الردّ الآلي إليك، علناً على التعليق أو في رسالة خاصة.
ضمان ألّا يُرَدّ على التعليق نفسه مرتين، وألّا تصلك رسالة آلية أكثر من مرة في اليوم.
تمكين صاحب الحساب من قراءة محادثاته والردّ فيها يدوياً من لوحة التحكم.
نشر الفيديوهات وكاروسيلات الصور التي يجدولها صاحب الحساب على حسابه في تيك توك، أو إرسالها إلى مسودّاته فيه، وإظهار ما أبلغ به تيك توك عن كل منشور.
رفع المقاطع القصيرة التي يجدولها صاحب الحساب إلى قناته على يوتيوب، والربط إلى كلٍّ منها من لوحة التحكم.
تشخيص الأعطال: معرفة سبب فشل ردّ لم يصل.
3. الردّ الآلي و«جيميناي» من جوجل
الردود على الرسائل الخاصة يكتبها نموذج ذكاء اصطناعي، لا إنسان. لتوليد الردّ،
يُرسَل نصّ رسالتك وآخر ثماني رسائل من المحادثة إلى
واجهة Gemini API
من جوجل.
ما يُرسَل إلى جوجل هو النصوص واتجاه كل رسالة فقط. لا يُرسَل اسمك ولا
معرّف حسابك ولا معرّف المحادثة إلى جوجل. ونصوص التعليقات لا تُرسَل
إلى جوجل إطلاقاً — مسار التعليقات لا يستخدم الذكاء الاصطناعي.
وبحسب سياسة ميتا، تُخبرك أول رسالة في المحادثة — ومرة أخرى بعد انقطاع طويل —
بأنك تتحدّث إلى خدمة آلية.
4. مدة الاحتفاظ
الحدث الأصلي الوارد من ميتا: يُمحى بعد أن يتجاوز عمره
30 يوماً. تعمل عملية التنظيف مرة واحدة يومياً، فقد يصل العمر الفعلي إلى
نحو 31 يوماً.
صفوف طابور المعالجة: تحتوي هي أيضاً على نسخة من الحدث
الأصلي. تُحذف بعد 7 أيام من إتمامها بنجاح. أمّا الصفوف التي
فشلت فتبقى بلا حدّ زمني، لأنها هي ما يُفحَص لمعرفة سبب
الفشل — فإن فشل ردّ على رسالتك، فقد تبقى نسخة من حدثها الأصلي مخزّنة
أكثر من 30 يوماً.
سجلّ «رسالة واحدة في اليوم» وعدّادات الحدّ: تُحذف بعد 48 ساعة.
نصوص الرسائل والمحادثات وسجلّ التفاعلات: تبقى بلا مدة
انتهاء تلقائية، حتى يحذفها صاحب الحساب. السبب أنها هي ما يقرأه صاحب
الحساب في صندوق رسائله. هذا يشمل نصّ رسائلك الخاصة. إن
أردتَ حذفها، فالطريق هو صفحة حذف البيانات.
اتصال تيك توك — معرّف open_id
والاسم المعروض ورابط الصورة الرمزية والرمزان: يبقى ما دام تيك توك مربوطاً،
ويُحذف عندما يفصله صاحب الحساب، سواء من الإعدادات في لوحة التحكم أو من «إدارة
أذونات التطبيقات» في تيك توك نفسه. لكن سجلّ التدقيق في الأداة — وهو سجلّ
للإجراءات الإدارية لا تحذف الأداة منه شيئاً — يحتفظ بقيد لكل مرة رُبط فيها تيك
توك، فيه الاسم المعروض للحساب والصلاحيات الممنوحة.
اتصال يوتيوب — معرّف القناة واسمها ومعرّفها المختصر ورابط صورتها
والرمزان: يبقى ما دام يوتيوب مربوطاً، مع تحديث الاسم والصورة يومياً، ويُحذف عندما
يفصله صاحب الحساب من الإعدادات. وإن سُحب الوصول من إعدادات الأمان في حساب جوجل بدلاً
من ذلك، يُحذف الرمزان والاسم والصورة في الفحص اليومي التالي، ويبقى معرّف القناة فقط
لتطلب لوحة التحكم إعادة الربط، إلى أن يفصله صاحب الحساب. وتبقى معرّفات المقاطع
المرفوعة على منشوراته المجدولة إلى أن يحذفها. ويحتفظ سجلّ التدقيق بقيد لكل مرة رُبط
فيها يوتيوب، فيه معرّف القناة والصلاحيات الممنوحة.
5. مَن يعالج البيانات معنا
لا نبيع بياناتك، ولا ننقلها إلى أي جهة لأغراض إعلانية أو تسويقية. نستعين بمزوّدي الخدمة التاليين لتشغيل الأداة فقط:
ميتا (إنستجرام وفيسبوك) — منها تأتي التعليقات والرسائل،
وعبرها تُرسَل الردود.
سياسة خصوصية ميتا.
تيك توك — فقط إن ربطه صاحب الحساب. منه تأتي بيانات الملف
الأساسية للحساب وإعدادات النشر فيه، وإليه تُنشَر الفيديوهات والصور التي يجدولها
صاحب الحساب وأوصافها، أو تُرسَل إلى مسودّاته. لا يُرسَل إلى
تيك توك أي شيء عمّن يعلّق أو يراسل على إنستجرام أو فيسبوك.
سياسة خصوصية تيك توك.
يوتيوب (جوجل) — فقط إن ربطه صاحب الحساب، عبر خدمات واجهة برمجة
يوتيوب. منه يأتي اسم القناة وصورتها، وإليه تُرفع الفيديوهات التي يجدولها صاحب الحساب
بعناوينها وأوصافها. لا يُرسَل إلى يوتيوب أي شيء عمّن يعلّق أو يراسل على إنستجرام أو
فيسبوك.
شروط خدمة يوتيوب ·
سياسة خصوصية جوجل.
جوجل — تتلقّى واجهة Gemini API نصوص الرسائل الخاصة كما
هو موضّح في القسم 3.
سياسة خصوصية جوجل.
Supabase — استضافة قاعدة البيانات التي يُخزَّن فيها كل ما
سبق.
سياسة خصوصية Supabase.
Vercel — استضافة التطبيق. تتلقّى Vercel أيضاً سجلّات
التشغيل، وهي تحتوي على أسماء المستخدمين ومعرّفات ميتا وحالات الأخطاء،
ولا تحتوي على نصوص الرسائل.
سياسة خصوصية Vercel.
6. حذف بياناتك
يمكنك طلب حذف بياناتك في أي وقت. الخطوات، وما يُحذف فعلاً وما لا يُحذف،
في صفحة حذف البيانات.
كل إشعار وارد من ميتا يُتحقَّق من توقيعه قبل معالجته، فلا يمكن لطرف آخر
أن يُدخل أحداثاً مزيّفة إلى النظام.
رمز وصول ميتا الخاص بصاحب الحساب، ورموز الوصول والتحديث الخاصة بتيك توك ويوتيوب،
تُشفَّر قبل التخزين بخوارزمية AES-256-GCM، ومفتاح التشفير
محفوظ خارج قاعدة البيانات.
لوحة التحكم — وهي المكان الوحيد الذي تُقرأ منه المحادثات — محميّة بكلمة مرور.
ولا نزعم أكثر من ذلك: لا يوجد تشفير من طرف إلى طرف، ونصوص الرسائل مخزّنة
كنصّ صريح داخل قاعدة البيانات ليقرأها صاحب الحساب.
8. تغييرات هذه الصفحة
إن تغيّر ما يجمعه النظام أو مدة احتفاظه به، يُحدَّث هذا النصّ ويُحدَّث معه
تاريخ «آخر تحديث» أعلى الصفحة. لا يوجد إشعار مباشر، لأننا لا نحتفظ بأي وسيلة
للتواصل معك.
9. للتواصل
يُشغّل «أوتوريبلاي برو» الأمير منصور (ElAmir Mansour)،
وهو المتحكّم في البيانات الموصوفة في هذه الصفحة.
AutoReply Pro is a tool operated by the owner of a single Instagram and
Facebook account. With the people who comment on or message that account, it
does two things: it replies automatically to comments that match a keyword the
owner configured, and it answers direct messages sent to the account. If the
owner also connects a TikTok account, it posts the videos and photo carousels
the owner schedules to that account, or sends them to its drafts, and does
nothing else there. If the owner connects a YouTube channel, it uploads the
owner's own short videos to that channel as Shorts, and does nothing else there.
It runs no advertising or marketing targeting, and it does not sell data.
This page describes what happens to your data — as someone who
commented on a post or sent a direct message — not the account owner's. It
is written from what the code actually does, not from what it ought to do.
The exceptions are TikTok and YouTube: the TikTok and YouTube data described
below belongs to the account owner who connected them, because nothing on
either is read from anyone else.
The service runs through an app registered on the Meta Developer Platform as
AutoResponseBot, which is the name Meta holds;
AutoReply Pro is the name of the product itself. TikTok
access goes through a separate app registered on TikTok for Developers, using
TikTok's official Login Kit,
Content Posting API and
Webhooks. YouTube access goes through a Google Cloud
project, using the YouTube Data API (YouTube API Services) and
Google's OAuth 2.0 sign-in.
Want your data deleted?
The full procedure — and the limits of what can actually be erased — is on the
data deletion page.
1. What reaches us, and what is actually stored
These are two different things, and the distinction is the most honest thing
we can tell you: Meta sends us more than we keep.
When you comment on a post
Meta sends us the comment ID, the post ID, the text of the comment, your name, and your account ID.
Stored: the comment ID, the post ID, your public
Instagram username (or your display name on Facebook), the platform,
the delivery status, and the text of any error Meta returned.
The text of your comment is not kept in the activity log. It
is held in the processing queue, inside the copy of the event Meta sent:
deleted automatically 7 days after it has been processed, but kept until
it is removed by hand if processing failed.
Stored for 48 hours: your Meta-scoped account ID and a
timestamp, to enforce a limit of one automated DM per person per day.
When you send a direct message
The text of your message as you wrote it, its direction
and type, any button you tapped, and Meta's message ID.
The verbatim event Meta sent us, in full. That event
contains your message text and your account ID, so it is a second copy
of both alongside the columns above. Its retention is in section 4.
Your Meta-scoped account ID, the time of the last
message, and when you were last told the replies are automated. Your
username is not stored on the direct-message path — only the ID.
Replies sent to you are stored the same way, with their text.
We do not ask for, receive, or store your email address, phone number,
postal address, or payment details. Your message text, however, is stored as
written: if you put something personal in it, that is stored because you
wrote it.
When the account owner connects TikTok
This part is about the account owner's own data. The app asks TikTok for three
scopes and no others: user.info.basic,
video.upload and
video.publish. None of them lets it read comments,
messages, or anyone else's account, so no TikTok viewer's data reaches us at
all.
Stored, from TikTok Login Kit
(user.info.basic): the account's
open_id — TikTok's identifier for the account,
specific to this app — its display name, and its avatar URL.
Stored, encrypted: the OAuth access token and refresh
token TikTok issues, encrypted at rest with AES-256-GCM (section 7).
Read, not stored: before every direct post, the app reads
the account's posting options from TikTok — its name, who its posts may be
shown to, whether its owner has switched off comments, Duet or Stitch, and
the longest video it may post — to offer the post's settings, and to check
them again at posting time.
The videos and photos the owner schedules, and their
captions, are stored so they can go out at the scheduled time. TikTok's API
takes no publish time, so a post goes out when the app's queue next runs
after that time, not to the minute. With
video.publish it is posted straight to the owner's
TikTok account (Direct Post); with video.upload it
is sent to their TikTok drafts (inbox), where they finish and post it in the
TikTok app. The app sends a video's file to TikTok; photos are fetched by
TikTok itself from the app's own web address, which is verified in TikTok's
developer portal.
Until TikTok approves the app after its review, every
direct post is private (Only me), and TikTok accepts one only while the
account itself is set to private. Nothing is posted publicly on the owner's
behalf before then.
Each direct post's settings: who can see it, whether
comments, Duet and Stitch are allowed, the commercial-content disclosure,
and the owner's explicit consent to post it — all chosen by the owner in the
app before the post is scheduled. Carousel Studio posts carry fixed
settings instead: Only me until TikTok approves the app and Everyone after,
comments allowed, and labelled as promoting the owner's own brand; the
owner's click to send them is the consent. A draft's settings are chosen in
TikTok itself.
Publish status results: what TikTok reports back about each
post — still processing, delivered to the drafts, published, or failed —
with the text of any error TikTok returned, and TikTok's post ID if the
post is public. The status arrives through TikTok's webhooks
(post.publish.*), and the app's queue also asks
for it each time it runs.
TikTok data is used only to provide the posting feature. It is never
sold, and the TikTok connection is deleted when the owner disconnects
TikTok — the steps are on the data deletion page.
Scheduled posts the owner created in the dashboard, including their TikTok
publish status, stay there until the owner deletes them, exactly as Instagram and
Facebook posts do.
When the account owner connects YouTube
This part is about the account owner's own data too. AutoReply Pro uses
YouTube API Services. By connecting a YouTube channel, the owner
agrees to be bound by the
YouTube Terms of Service,
and Google's own handling of the data is described in the
Google Privacy Policy.
The app asks Google for two scopes and no others:
youtube.upload, to upload videos to the channel, and
youtube.readonly, used only to read the channel's name
and picture so the dashboard can show which channel is connected. Neither is used
to read comments, messages, subscribers or anyone else's channel, so no YouTube
viewer's data reaches us.
Stored, from YouTube: the channel's ID, its name and handle,
and the URL of its profile picture. While the channel is connected, the name
and picture are read from YouTube again once a day, so they are never more
than a day old.
Stored, encrypted: the OAuth access token and refresh token
Google issues, encrypted at rest with AES-256-GCM (section 7), and the list of
scopes granted.
The videos the owner schedules, with their title and
description, are stored so they can be uploaded at the scheduled time, when
the app's queue next runs. Each is uploaded to the owner's channel as a Short,
declared as not made for kids, and the YouTube video ID that comes back is
kept so the dashboard can link to it.
Until Google completes its audit of the app, every upload is
private: YouTube keeps videos from apps it has not audited private, and the app
asks for private. Nothing is published publicly on the owner's behalf before
then.
Nothing about anyone else: the app does not read, store or
share data about YouTube viewers, shows no advertising, and lets no third party
place content, ads or cookies through its YouTube features.
YouTube data is used only to provide the uploading feature. It is never
sold, and it is shared with no one but Google, which receives the videos.
The owner can remove the app's access at any time: in the dashboard (Settings →
YouTube → Disconnect), which revokes it with Google and deletes the stored
connection at once, or in Google's security settings, at
security.google.com/settings/security/permissions.
Access removed there is found at the app's next daily check, which deletes the
stored tokens and the channel's name and picture.
2. Why we use it
To decide whether a comment matches a keyword on an active campaign.
To send you the automated reply, publicly under the comment or as a direct message.
To make sure the same comment is never answered twice, and that you do not receive more than one automated DM a day.
To let the account owner read and manually answer their own conversations from the dashboard.
To post the videos and photo carousels the account owner schedules to their own TikTok account, or send them to its drafts, and to show them what TikTok reported about each one.
To upload the short videos the account owner schedules to their own YouTube channel, and to link to each one from the dashboard.
To diagnose faults: to find out why a reply that should have arrived did not.
3. Automated replies and Google Gemini
Replies to direct messages are written by an AI model, not a person. To
generate one, the text of your message and the last eight messages
in the thread are sent to Google's
Gemini API.
What is sent to Google is message text and the direction of each message,
nothing more. Your username, your account ID, and the conversation
ID are not sent to Google. Comment text is never sent to Google at
all — the comment path does not use AI.
As Meta's policy requires, the first message in a thread — and another one
after a long gap — tells you that you are talking to an automated service.
4. How long it is kept
The verbatim event from Meta: erased once it is more
than 30 days old. The sweep runs once a day, so in practice the age can
reach about 31 days.
Processing-queue rows: these hold a copy of the
verbatim event too. They are deleted 7 days after completing
successfully. Rows that failed are kept with no time
limit, because they are what gets inspected to find out why — so if a
reply to your message failed, a copy of its verbatim event may be stored
for longer than 30 days.
The one-DM-per-day log and the rate counters: deleted after 48 hours.
Message text, conversations, and the interaction log:
kept with no automatic expiry until the account owner deletes them,
because they are what the owner reads in their own inbox.
This includes the text of your private messages. If you
want yours removed, the route is the
data deletion page.
The TikTok connection — the open_id,
display name, avatar URL, and both tokens: kept while TikTok is connected,
and deleted when the owner disconnects it, either from Settings in the
dashboard or from "Manage app permissions" in TikTok itself. The app's audit
log, though — a record of administrative actions that the app never clears —
keeps an entry for each time TikTok was connected, with the account's display
name and the scopes granted.
The YouTube connection — the channel's ID, name, handle,
picture URL and both tokens: kept while YouTube is connected, with the name
and picture refreshed daily, and deleted when the owner disconnects it in
Settings. If access is removed in Google's security settings instead, the
tokens, name and picture are deleted at the next daily check, and the channel
ID is kept only so the dashboard can ask for a reconnect, until the owner
disconnects. The video IDs of uploaded Shorts stay on the owner's scheduled
posts until the owner deletes them. The audit log keeps an entry for each time
YouTube was connected, with the channel ID and the scopes granted.
5. Who else processes it
We do not sell your data and we do not transfer it to anyone for advertising or marketing. We rely on these service providers purely to run the tool:
Meta (Instagram and Facebook) — comments and messages
arrive from Meta, and replies are sent back through it.
Meta's privacy policy.
TikTok — only if the account owner connects it. The
account's basic profile and posting options come from TikTok, and the
owner's scheduled videos, photos and captions are posted to it, or sent to
its drafts. Nothing about people who comment or message on Instagram
or Facebook is sent to TikTok.
TikTok's privacy policy.
YouTube (Google) — only if the account owner connects it,
through YouTube API Services. The channel's name and picture come from
YouTube, and the owner's scheduled videos and their titles and descriptions
are uploaded to it. Nothing about people who comment or message on Instagram
or Facebook is sent to YouTube.
YouTube Terms of Service ·
Google Privacy Policy.
Google — the Gemini API receives direct-message text as
described in section 3.
Google's privacy policy.
Vercel — hosts the application. Vercel also receives
operational logs, which contain usernames, Meta IDs, and error states,
and do not contain message text.
Vercel's privacy policy.
6. Deleting your data
You can ask for your data to be deleted at any time. The steps, and what is
and is not actually erased, are on the
data deletion page.
An account owner who connected YouTube can also remove the app's access from
Google's side, at
security.google.com/settings/security/permissions;
what happens to the stored data then is in section 4.
7. How the data is protected
All traffic runs over HTTPS.
Every incoming notification from Meta has its signature verified before
it is processed, so no one else can inject forged events into the system.
The account owner's Meta access token, and their TikTok and YouTube access
and refresh tokens, are encrypted before they are stored,
with AES-256-GCM, and the encryption key is held outside the database.
The dashboard — the only place conversations are read from — is password-protected.
We claim no more than that: there is no end-to-end encryption, and message
text sits in the database in plain text so that the account owner can read it.
8. Changes to this page
If what the system collects or how long it keeps it changes, this text is
updated and the "last updated" date at the top changes with it. There is no
direct notice, because we hold no way to contact you.
9. Contact
AutoReply Pro is operated by ElAmir Mansour, who is the data controller for the
data described on this page.
For any question about this policy or about your data: