Crevyro

PRIVACY POLICY

Your conversations deserve protection.

Crevyro is built to run Instagram automations without asking for your Instagram password. This page explains what data the service handles, why it is needed, how long it is kept and how you can control or delete it. For implementation-specific protection details, read Security at Crevyro.

BUILT-IN PROTECTIONS

Protection built into Crevyro.

Until Crevyro earns an independent certification, this page shows the controls the current service actually uses rather than displaying unearned certification badges.

Meta API connection

Instagram professional accounts are connected through supported Meta authorization flows. Crevyro does not ask you to type your Instagram password into the service.

Protected credentials

Stored Instagram access tokens and platform credentials are protected by server-side controls rather than being exposed in normal workspace pages.

Workspace isolation

Application records use workspace-aware authorization so authenticated users and team members are limited to the workspace and role they are allowed to access.

Verified webhooks

Incoming Meta webhook traffic is validated before automation events are accepted, and event claiming helps prevent duplicate processing.

Durable processing

Queues, retries, delayed-action records and recovery handling are used so temporary delivery failures do not depend on a browser tab remaining open.

Payment separation

Razorpay processes payment methods. Crevyro stores subscription and transaction references needed for billing, not complete card, bank or UPI credentials.

DATA PRIVACY

Only the information needed to run the service.

Crevyro processes creator account data and the Instagram interaction data required to execute the automations a workspace configures.

IG

Instagram & conversation data

Professional-account identifiers, usernames, comments, messages, media references, interaction timestamps and Instagram-scoped user identifiers may be processed when Meta delivers them to a connected workspace.

CRM

Leads & captured details

When a creator enables lead tools or email capture, Crevyro may store contact status, tags, notes, source information, activity history, captured email addresses and conversion information.

30

Retention that is defined

Inbox conversations and messages are kept for the most recent 30 days in the current configuration. Other operational records have separate retention periods described below.

×

Delete when you leave

Workspace owners can disconnect Instagram and use Account & data controls to request permanent account deletion. Instagram users can also request deletion of interaction data.

Service providers

Firebase, Cloudflare, Meta/Instagram, Razorpay and configured email-delivery services may process information only as needed for authentication, hosting, automation, billing or support.

0

No sale of conversation data

Crevyro does not sell Instagram conversation data or use private Instagram interactions to build unrelated advertising profiles.

SECURITY PRACTICES

How Crevyro protects the service.

1 / 3

SECURITY FAQ

Questions creators should be able to answer before connecting an account.

Does Crevyro know my Instagram password?

No. Supported Instagram connections use Meta authorization and access tokens. Do not send Instagram passwords, OTPs or access tokens through support tickets or automation fields.

Ca Crevyro process my Instagram DMs?

Yes, when a connected professional account grants the required Meta permissions. Messages and interaction data delivered through Meta APIs can be processed to run automations, display the shared inbox and maintain lead history according to the workspace configuration.

Do you sell or share Instagram conversation data for advertising?

Crevyro does not sell Instagram conversation data or use it to build unrelated advertising profiles. Information may still be processed by service providers that are necessary to operate authentication, hosting, messaging, billing and support.

Where is workspace data stored?

The application uses Cloudflare infrastructure, including a shared D1 database with logical workspace separation. Authentication and hosting may also involve Firebase. Providers can process data in locations determined by their own infrastructure and terms.

How long are conversations retained?

In the current production policy, Crevyro keeps the most recent 30 days of Instagram inbox conversations and messages. Other categories such as activity records, support tickets, billing records and security logs have different periods described in the full policy below.

How can I delete my Crevyro data?

Workspace owners can use the Account & data controls or the Data Deletion process. If dashboard access is unavailable, a verified privacy request can be sent to the privacy contact listed below.

Who handles payment information?

Razorpay processes payment methods and payment authorization. Crevyro stores billing references, status, amounts, currencies, invoices and related records needed to operate subscriptions and refunds.

Is Crevyro ISO, SOC 2 or CSA STAR certified?

Crevyro does not currently claim those certifications. The security information on this page describes product and operational controls rather than an independent certification.

What happens if I disconnect Instagram?

Automations that depend on the disconnected account can no longer run through that connection. Stored Crevyro records remain subject to the retention and deletion rules in this policy unless the workspace or relevant data is deleted.

FULL PRIVACY POLICY

The legal details behind the summary above.

More documents
Effective date: August 8, 2026Last updated: August 8, 2026Previous version

1. Scope and operator

This Privacy Policy explains how Crevyro for Creators ("Crevyro", "we", "us" or "our"), operated by Sahil Yadav in India, processes personal data when someone visits the website, creates an account, connects an Instagram professional account, uses automations, Inbox or Leads, purchases a subscription, joins a workspace team or contacts support.

Questions, privacy requests and grievances may be sent to srao2445@gmail.com. This policy describes the product configuration supplied with the service; production provider settings must continue to match these disclosures.

2. Roles and whose data we process

Crevyro processes information about two main groups: creators/business users who own or join a Crevyro workspace, and Instagram users who interact with a connected professional account. Workspace owners choose the automation rules, messages, lead fields and other instructions that determine how recipient interactions are handled.

For recipient data processed to execute a creator's instructions, the creator or business is responsible for its own notices, permissions and lawful use of that information. Crevyro also processes certain account, billing, security and operational information for its own service administration.

3. Information we process

  • Account information: Firebase user ID, email address, sign-in provider, display name, profile image when available, email-verification state, workspace ID, role, account status and account-security events.
  • Workspace information: settings, team membership, plan entitlements, connected-account configuration and administrative actions.
  • Automation information: automation names, triggers, keywords, selected media, public reply variations, DM text, links, follow checks, email-capture settings, follow-up settings and execution state.
  • Lead information: contact identifiers, source, status, tags, notes, activity history, captured email addresses and conversion information when those features are enabled.

4. Instagram and Meta data

When a workspace connects an eligible Instagram professional account, Crevyro may receive professional-account identifiers, username and profile information, encrypted access tokens, token-expiry information, connection status, media identifiers, comments, direct messages, Story interactions, Instagram-scoped user identifiers, timestamps and other fields Meta makes available for the enabled features.

Crevyro uses this information to match triggers, send configured replies, verify follow status when that option is enabled, display supported Inbox history, associate interactions with leads and troubleshoot delivery. Crevyro does not require an Instagram password for supported API connections.

5. Billing and payment data

For paid plans and top-ups, Crevyro may process subscription status, billing-cycle dates, plan identifiers, amount, currency, invoice information, refund status and Razorpay customer, subscription, payment and refund identifiers. Complete card, bank or UPI credentials are handled by the payment provider rather than stored by Crevyro.

6. Technical and security data

Crevyro may record request times, endpoint and operation information, limited network or browser metadata, authentication events, rate-limit counters, usage totals, webhook identifiers, queue and retry state, error details, security events, incident records and audit information needed to operate, protect and diagnose the service.

7. Where information comes from

Information can come directly from a workspace user, from Meta/Instagram after account authorization, from people who interact with the connected Instagram account, from authentication and payment providers, from automated service operations, or from support communications.

8. Why we use information

We use information to authenticate users; create and isolate workspaces; connect Instagram accounts; receive and validate webhooks; execute creator-configured automation rules; send replies and follow-ups; verify configured follow conditions; capture requested email submissions; display Inbox and lead information; enforce plan limits; process subscriptions and refunds; provide support; secure the service; investigate failures or abuse; maintain records; and comply with applicable legal obligations.

9. Creator instructions and recipient data

Creators control the content, triggers, links and lead-collection settings in their automations. A creator must use Crevyro in accordance with applicable law, Meta rules and any notice or consent requirements that apply to their audience. Crevyro does not independently decide which Instagram users a creator should market to or what content a creator should send.

10. Service providers

The service may rely on Google Firebase for authentication and hosting, Cloudflare for Workers, D1, Queues and related infrastructure, Meta/Instagram for account authorization and messaging APIs, Razorpay for billing and payment processing, and Resend or another configured delivery provider for operational email notifications. These providers process information according to their own terms and privacy practices.

11. International processing

Cloud and platform providers may process or store information in countries other than the user's own. Where applicable law imposes requirements on cross-border processing, Crevyro and its users must use the service consistently with those requirements and the safeguards made available by the relevant provider.

12. Sharing and sale

Crevyro may disclose information to service providers as necessary to operate the service, to a workspace owner or authorized team member, to professional advisers where reasonably necessary, or when disclosure is required to comply with law, protect users, investigate fraud or security incidents, or establish or defend legal claims.

Crevyro does not sell Instagram conversation data or use private Instagram interactions to create unrelated advertising profiles.

13. Retention

  • Instagram Inbox conversations and messages stored by Crevyro are retained for the most recent 30 days.
  • Each workspace keeps only its newest 20 notifications and newest 20 activity-log entries.
  • Open support tickets remain while support is ongoing. Closed tickets and their threaded messages are automatically removed after 2 days under the current configuration.
  • Active workspace, automation, lead and contact data required to operate the service is retained while the account is active unless deleted sooner or a longer period is required for security, dispute resolution or law.
  • Completed webhook inbox and event-deduplication records are ordinarily removed after 30 days.
  • Temporary failed jobs and dead-letter payloads are ordinarily removed after resolution or within 90 days.
  • Usage, security and audit records may be retained for up to 18 months.
  • Billing, refund, tax and transaction records may be retained for the period required by accounting, payment, tax or legal obligations.
  • After account deletion, active application records are deleted promptly. Backup copies or provider logs may remain until normal rotation, ordinarily no longer than 90 days, unless preservation is legally required.

14. Deletion

Workspace owners can disconnect Instagram and use Account & data controls to request permanent deletion of the Crevyro workspace and associated Firebase identity. Where an active paid subscription exists, deletion may first initiate cancellation or cleanup needed to prevent future renewal.

Additional information about the deletion workflow is available on the Data Deletion page. We may retain minimum records when required for billing, fraud prevention, dispute resolution, security or law.

15. Security

Current production controls include authenticated access, workspace-aware authorization, protected Instagram tokens and platform credentials, Meta webhook-signature validation, idempotent event claiming, rate limiting, durable queue processing, retry and dead-letter handling, audit records and restricted owner administration. These measures reduce risk but no internet or cloud service can guarantee absolute security.

Users must protect their own devices, sign-in account, Meta account and invited team access. Suspected compromise should be reported promptly.

16. Workspace and team access

Workspace owners may invite team members where the active plan permits. Roles and account state are used to control access to workspace information and actions. Owners are responsible for removing access when a person no longer needs it and for ensuring invited users are authorized to view the relevant creator or business data.

17. Your choices and rights

Depending on applicable law and the context in which Crevyro processes the information, a person may have rights to request access, correction, completion, deletion, withdrawal of consent, restriction or objection, or grievance redressal. Requests can be sent to srao2445@gmail.com. We may request reasonable verification before disclosing or changing account or recipient information.

Workspace owners can also use product controls to disconnect Instagram, manage team access, cancel a subscription and delete the account.

18. Instagram users

An Instagram user may ask the connected creator or business to remove their interaction data or contact Crevyro directly with enough information to locate the interaction, such as the relevant Instagram username, connected business account and approximate date. Never send a password, OTP or access token with a privacy request.

Because the creator or business controls the purpose and content of its automations, Crevyro may coordinate an Instagram-user request with the relevant workspace owner when appropriate.

19. Browser storage

Crevyro uses browser storage where needed for authentication flows, session continuity, security checks, interface state, avatar persistence and trusted-browser functionality. This storage is used to operate the product rather than to build unrelated advertising profiles. If optional advertising or analytics technologies are introduced later, this policy will be updated and consent controls will be used where required.

20. Children

Crevyro is designed for creators, businesses and people who can lawfully enter a contract. It is not directed to children. Workspace owners must not knowingly use automations to collect children's personal data without all notices, permissions and safeguards required by applicable law and platform rules.

21. Changes

We may update this Privacy Policy when the service, providers, retention rules or legal requirements change. The current effective and last-updated dates appear above. Material changes may also be communicated through the website, workspace or account contact information where appropriate.

22. Contact

For privacy questions, deletion requests or grievances, contact:

Crevyro for Creators
Operated by Sahil Yadav, India
srao2445@gmail.com

CONTROL YOUR DATA

Privacy controls live inside your workspace.

Disconnect Instagram, manage team access, review account data or start deletion from one place.

Open Crevyro