Meta API connection
Instagram professional accounts are connected through supported Meta authorization flows. Crevyro does not ask you to type your Instagram password into the service.
PRIVACY POLICY
Crevyro is built to run Instagram automations without asking for your Instagram password. This page explains what data the service handles, why it is needed, how long it is kept and how you can control or delete it. For implementation-specific protection details, read Security at Crevyro.
BUILT-IN PROTECTIONS
Until Crevyro earns an independent certification, this page shows the controls the current service actually uses rather than displaying unearned certification badges.
Instagram professional accounts are connected through supported Meta authorization flows. Crevyro does not ask you to type your Instagram password into the service.
Stored Instagram access tokens and platform credentials are protected by server-side controls rather than being exposed in normal workspace pages.
Application records use workspace-aware authorization so authenticated users and team members are limited to the workspace and role they are allowed to access.
Incoming Meta webhook traffic is validated before automation events are accepted, and event claiming helps prevent duplicate processing.
Queues, retries, delayed-action records and recovery handling are used so temporary delivery failures do not depend on a browser tab remaining open.
Razorpay processes payment methods. Crevyro stores subscription and transaction references needed for billing, not complete card, bank or UPI credentials.
DATA PRIVACY
Crevyro processes creator account data and the Instagram interaction data required to execute the automations a workspace configures.
Professional-account identifiers, usernames, comments, messages, media references, interaction timestamps and Instagram-scoped user identifiers may be processed when Meta delivers them to a connected workspace.
When a creator enables lead tools or email capture, Crevyro may store contact status, tags, notes, source information, activity history, captured email addresses and conversion information.
Inbox conversations and messages are kept for the most recent 30 days in the current configuration. Other operational records have separate retention periods described below.
Workspace owners can disconnect Instagram and use Account & data controls to request permanent account deletion. Instagram users can also request deletion of interaction data.
Firebase, Cloudflare, Meta/Instagram, Razorpay and configured email-delivery services may process information only as needed for authentication, hosting, automation, billing or support.
Crevyro does not sell Instagram conversation data or use private Instagram interactions to build unrelated advertising profiles.
SECURITY PRACTICES
SECURITY FAQ
No. Supported Instagram connections use Meta authorization and access tokens. Do not send Instagram passwords, OTPs or access tokens through support tickets or automation fields.
Yes, when a connected professional account grants the required Meta permissions. Messages and interaction data delivered through Meta APIs can be processed to run automations, display the shared inbox and maintain lead history according to the workspace configuration.
Crevyro does not sell Instagram conversation data or use it to build unrelated advertising profiles. Information may still be processed by service providers that are necessary to operate authentication, hosting, messaging, billing and support.
The application uses Cloudflare infrastructure, including a shared D1 database with logical workspace separation. Authentication and hosting may also involve Firebase. Providers can process data in locations determined by their own infrastructure and terms.
In the current production policy, Crevyro keeps the most recent 30 days of Instagram inbox conversations and messages. Other categories such as activity records, support tickets, billing records and security logs have different periods described in the full policy below.
Workspace owners can use the Account & data controls or the Data Deletion process. If dashboard access is unavailable, a verified privacy request can be sent to the privacy contact listed below.
Razorpay processes payment methods and payment authorization. Crevyro stores billing references, status, amounts, currencies, invoices and related records needed to operate subscriptions and refunds.
Crevyro does not currently claim those certifications. The security information on this page describes product and operational controls rather than an independent certification.
Automations that depend on the disconnected account can no longer run through that connection. Stored Crevyro records remain subject to the retention and deletion rules in this policy unless the workspace or relevant data is deleted.
FULL PRIVACY POLICY
This Privacy Policy explains how Crevyro for Creators ("Crevyro", "we", "us" or "our"), operated by Sahil Yadav in India, processes personal data when someone visits the website, creates an account, connects an Instagram professional account, uses automations, Inbox or Leads, purchases a subscription, joins a workspace team or contacts support.
Questions, privacy requests and grievances may be sent to srao2445@gmail.com. This policy describes the product configuration supplied with the service; production provider settings must continue to match these disclosures.
Crevyro processes information about two main groups: creators/business users who own or join a Crevyro workspace, and Instagram users who interact with a connected professional account. Workspace owners choose the automation rules, messages, lead fields and other instructions that determine how recipient interactions are handled.
For recipient data processed to execute a creator's instructions, the creator or business is responsible for its own notices, permissions and lawful use of that information. Crevyro also processes certain account, billing, security and operational information for its own service administration.
When a workspace connects an eligible Instagram professional account, Crevyro may receive professional-account identifiers, username and profile information, encrypted access tokens, token-expiry information, connection status, media identifiers, comments, direct messages, Story interactions, Instagram-scoped user identifiers, timestamps and other fields Meta makes available for the enabled features.
Crevyro uses this information to match triggers, send configured replies, verify follow status when that option is enabled, display supported Inbox history, associate interactions with leads and troubleshoot delivery. Crevyro does not require an Instagram password for supported API connections.
For paid plans and top-ups, Crevyro may process subscription status, billing-cycle dates, plan identifiers, amount, currency, invoice information, refund status and Razorpay customer, subscription, payment and refund identifiers. Complete card, bank or UPI credentials are handled by the payment provider rather than stored by Crevyro.
Crevyro may record request times, endpoint and operation information, limited network or browser metadata, authentication events, rate-limit counters, usage totals, webhook identifiers, queue and retry state, error details, security events, incident records and audit information needed to operate, protect and diagnose the service.
Information can come directly from a workspace user, from Meta/Instagram after account authorization, from people who interact with the connected Instagram account, from authentication and payment providers, from automated service operations, or from support communications.
We use information to authenticate users; create and isolate workspaces; connect Instagram accounts; receive and validate webhooks; execute creator-configured automation rules; send replies and follow-ups; verify configured follow conditions; capture requested email submissions; display Inbox and lead information; enforce plan limits; process subscriptions and refunds; provide support; secure the service; investigate failures or abuse; maintain records; and comply with applicable legal obligations.
Creators control the content, triggers, links and lead-collection settings in their automations. A creator must use Crevyro in accordance with applicable law, Meta rules and any notice or consent requirements that apply to their audience. Crevyro does not independently decide which Instagram users a creator should market to or what content a creator should send.
The service may rely on Google Firebase for authentication and hosting, Cloudflare for Workers, D1, Queues and related infrastructure, Meta/Instagram for account authorization and messaging APIs, Razorpay for billing and payment processing, and Resend or another configured delivery provider for operational email notifications. These providers process information according to their own terms and privacy practices.
Cloud and platform providers may process or store information in countries other than the user's own. Where applicable law imposes requirements on cross-border processing, Crevyro and its users must use the service consistently with those requirements and the safeguards made available by the relevant provider.
Workspace owners can disconnect Instagram and use Account & data controls to request permanent deletion of the Crevyro workspace and associated Firebase identity. Where an active paid subscription exists, deletion may first initiate cancellation or cleanup needed to prevent future renewal.
Additional information about the deletion workflow is available on the Data Deletion page. We may retain minimum records when required for billing, fraud prevention, dispute resolution, security or law.
Current production controls include authenticated access, workspace-aware authorization, protected Instagram tokens and platform credentials, Meta webhook-signature validation, idempotent event claiming, rate limiting, durable queue processing, retry and dead-letter handling, audit records and restricted owner administration. These measures reduce risk but no internet or cloud service can guarantee absolute security.
Users must protect their own devices, sign-in account, Meta account and invited team access. Suspected compromise should be reported promptly.
Workspace owners may invite team members where the active plan permits. Roles and account state are used to control access to workspace information and actions. Owners are responsible for removing access when a person no longer needs it and for ensuring invited users are authorized to view the relevant creator or business data.
Depending on applicable law and the context in which Crevyro processes the information, a person may have rights to request access, correction, completion, deletion, withdrawal of consent, restriction or objection, or grievance redressal. Requests can be sent to srao2445@gmail.com. We may request reasonable verification before disclosing or changing account or recipient information.
Workspace owners can also use product controls to disconnect Instagram, manage team access, cancel a subscription and delete the account.
An Instagram user may ask the connected creator or business to remove their interaction data or contact Crevyro directly with enough information to locate the interaction, such as the relevant Instagram username, connected business account and approximate date. Never send a password, OTP or access token with a privacy request.
Because the creator or business controls the purpose and content of its automations, Crevyro may coordinate an Instagram-user request with the relevant workspace owner when appropriate.
Crevyro uses browser storage where needed for authentication flows, session continuity, security checks, interface state, avatar persistence and trusted-browser functionality. This storage is used to operate the product rather than to build unrelated advertising profiles. If optional advertising or analytics technologies are introduced later, this policy will be updated and consent controls will be used where required.
Crevyro is designed for creators, businesses and people who can lawfully enter a contract. It is not directed to children. Workspace owners must not knowingly use automations to collect children's personal data without all notices, permissions and safeguards required by applicable law and platform rules.
We may update this Privacy Policy when the service, providers, retention rules or legal requirements change. The current effective and last-updated dates appear above. Material changes may also be communicated through the website, workspace or account contact information where appropriate.
For privacy questions, deletion requests or grievances, contact:
Crevyro for Creators
Operated by Sahil Yadav, India
srao2445@gmail.com
CONTROL YOUR DATA
Disconnect Instagram, manage team access, review account data or start deletion from one place.