Privacy Policy

How we handle your data.

Last updated 23 August 2026. This policy explains what Xuios collects — including Instagram and Meta Platform Data — how we use it, who we share it with, and how you can delete it.

1. Who we are

This Privacy Policy describes how MEEZOY VENTURES PRIVATE LIMITED (“Xuios,” “we,” “us,” or “our”), operator of the Xuios product at https://xuios.com, collects, uses, stores, shares, and deletes personal information when you visit our site, create an account, or use our Instagram automation product (the “Service”).

Xuios helps creators and businesses send private Instagram replies through official Meta APIs when someone comments, replies to a story, mentions their account, or messages them. We are not affiliated with Meta Platforms, Inc., Instagram, or Facebook.

For privacy questions, data access, or deletion requests, email hello@xuios.com or use our contact form.

2. Scope

This policy applies to:

  • People who create a Xuios account (our customers).
  • People who visit our marketing site, sign in, or contact us.
  • People whose Instagram activity is processed because they commented on, replied to, mentioned, or messaged a professional Instagram account connected to Xuios (end users of our customers).

If you interact with a creator on Instagram and they use Xuios, that creator is responsible for their own content and for how they message you. Xuios processes limited Instagram data on their behalf so the automation they configured can run.

3. Information we collect

Account and profile

When you sign up or complete your profile, we collect:

  • Name and email address.
  • Password (stored as a one-way hash) if you register with email.
  • Google account identifiers, name, email, and profile image if you sign in with Google.
  • Optional business description and notification preferences (for example, weekly digest and unmatched-DM AI replies).
  • The date you accepted these terms and this policy.

Product data you create

  • Automation settings: names, trigger types, keywords, selected posts, DM text, public reply text, delays, follow-gate copy, and related flags.
  • Tracked links you create (destination URL, label, short code) and aggregate click counts.
  • Inbox records of messages Xuios queued or sent, including delivery status and error text when a send fails.

Billing

Paid plans are processed by Stripe. We store your Stripe customer ID, subscription plan, interval, status, trial dates, and period end. We do not store full card numbers. Stripe collects payment details under its own privacy policy.

Usage, device, and support

  • Pages you visit, clicks and form interactions, session recordings, performance metrics, and product events used to understand how the Service is used and to keep it reliable.
  • Link-click metadata for tracked links (approximate country derived from IP, and user agent). We do not use this to build advertising profiles.
  • Messages you send us through the contact form or support email.
  • Error diagnostics (via PostHog) such as stack traces, URL, and truncated request context. We configure this to avoid capturing passwords, access tokens, or full message bodies where possible.

4. Instagram and Meta Platform Data

When you connect a professional Instagram account through official Meta OAuth, we receive Platform Data from Instagram and Meta solely to provide the Service you requested. We do not sell this data. We do not use it to create ads, to build a personal credit or eligibility score, or to train generalized/public artificial-intelligence models.

Data from the Instagram account you connect

  • Instagram user ID, username, display name, and profile picture.
  • Account health needed to keep the connection working (including token expiry and reconnect state).
  • Access tokens and related expiry information, stored so we can call Instagram APIs on your behalf until you disconnect or delete your account.
  • Media you can select for automations: post IDs, captions, thumbnails, permalinks, and posted times.

Data from people who interact with that account

To match keywords, respect follow gates, and send a private reply inside Instagram’s permitted windows, we may process:

  • Instagram user ID, username, display name, and profile picture of the person who commented, replied, mentioned you, or sent a DM.
  • Comment ID and comment text; incoming DM, story-reply, or mention text; related media IDs.
  • Whether that person follows the connected professional account, when a follow-gated automation needs that check.
  • A record of the private reply Xuios sent (or attempted to send) and a send-once receipt so we do not message the same person twice for the same automation.

We collect this end-user data because you, the account holder, connected Instagram and configured automations. We use it only to operate those automations, show you an inbox log, and enforce Meta’s messaging windows (including the 24-hour user-message window and the 7-day private-reply window for comments).

Permissions

Depending on Meta’s current Instagram APIs, connecting an account typically involves permissions needed to read professional profile and media, read comments, send private replies and Instagram messages, and receive webhooks for those events. We request only the permissions required to run the features you enable. You can revoke access at any time in Instagram or Facebook settings and by disconnecting or deleting your Xuios account.

5. How we use information

We use personal information to:

  • Create and authenticate your account, including email verification and Google sign-in.
  • Connect Instagram accounts, keep tokens refreshed, and show you the media you pick for automations.
  • Run automations you configure: match keywords or triggers, check follow status when you enable a follow gate, send private replies and optional public comment replies through official APIs, and log results in your inbox.
  • Enforce plan limits, trials, and billing through Stripe.
  • Operate tracked links and show you click counts and a simple country breakdown.
  • Send transactional email (verification, password reset, reconnect alerts, billing, optional weekly digest).
  • Provide optional AI features on Pro when you turn them on: drafting keywords or replies from captions you supply, and classifying or answering unmatched comments or DMs. That processing is described below.
  • Secure the Service, prevent abuse, debug outages, and comply with law or Meta platform requirements.

AI processing. If you enable unmatched-DM AI replies or use drafting tools, limited text you provide (such as a caption or an incoming comment/DM, plus any business description you saved) may be sent to Anthropic to generate a classification or draft. We use this only to provide that feature to you. We do not use Instagram Platform Data to train our own models, and we do not use it to train generalized or public models. You can turn unmatched AI replies off in Settings.

7. How we share information

We do not sell personal information. We do not share Instagram or Meta Platform Data with third parties for their own marketing or advertising. We share information only as needed to operate Xuios:

  • Meta / Instagram. We send API calls and receive webhooks so we can read the events you subscribed to and deliver private replies you configured.
  • Stripe. Name, email, and subscription metadata to process payments.
  • Google. If you choose Google sign-in, Google authenticates you under its terms and privacy policy.
  • Email delivery (Resend). Your email address and the content of transactional messages.
  • Analytics and error diagnostics (PostHog). Product analytics, session recordings, heatmaps, and crash diagnostics used to understand usage and keep the Service reliable — not to sell ads.
  • AI (Anthropic). Only if you use optional AI features, as described above.
  • Infrastructure providers. Cloud database, hosting, and background-job processors that store or transmit data under contract, solely to run the Service.
  • Legal and safety. If required by law, to protect rights and safety, or to respond to a valid request from Meta related to platform enforcement.

If we ever sell or reorganize the business, personal information may transfer to a successor that agrees to honor this policy or provide equivalent protection.

8. Cookies and similar technologies

We use essential cookies or similar storage for authentication and session security (for example, to keep you signed in). We also use PostHog cookies and local storage to measure product usage, remember a visitor across pages, and record sessions so we can fix issues. We do not use advertising cookies or sell this data. You can block non-essential storage in your browser; the Service may not function if essential session storage is blocked.

9. Retention and security

We keep personal information only as long as needed for the purposes above:

  • Account, Instagram connection, automations, inbox logs, tracked links, and billing metadata: until you delete your account or we close it, unless a longer period is required for law, disputes, or platform enforcement.
  • Access tokens: until you disconnect Instagram, the token expires and cannot be refreshed, or you delete your account.
  • Support emails: for a reasonable period to handle your request.
  • Backups: for a limited time after deletion, then purged on the backup cycle.

We use industry-standard safeguards (HTTPS, hashed passwords, access-controlled databases, and limited employee access). No method of transmission or storage is 100% secure. If we become aware of a breach that affects your information, we will notify you and regulators as required by law.

10. Your rights, export, and deletion

Depending on where you live, you may have the right to access, correct, delete, export, restrict, or object to certain processing, and to withdraw consent. You may also lodge a complaint with your local data protection authority.

You can exercise these rights without creating extra hurdles:

  1. Sign in and open Settings to export a JSON copy of your profile, connected Instagram account metadata (excluding access tokens), message log, and tracked links, or to delete your entire account.
  2. Follow the step-by-step instructions on our User Data Deletion page.
  3. Email hello@xuios.com from the address on your account. We will verify the request and complete it within 30 days, or sooner where law requires.
  4. Disconnect Instagram in Xuios, or remove Xuios from Instagram / Facebook Settings → Apps and websites. That stops new Platform Data from flowing to us. Existing Xuios records are removed when you delete your Xuios account or when we process a deletion request.

Deleting your Xuios account removes automations, message logs, tracked links, Instagram connections and tokens, and billing customer records we store. Messages already delivered in Instagram remain in Instagram according to Meta’s policies — we cannot unsend history inside Instagram after the fact.

Under US state privacy laws (including the CCPA/CPRA), we do not sell personal information and we do not share it for cross-context behavioral advertising. To make a “do not sell or share” or deletion request, email hello@xuios.com. We will not discriminate against you for exercising your rights.

11. Children’s privacy

Xuios is a business tool for people who can manage a professional Instagram account and enter a contract. The Service is not directed to children under 13, and we do not knowingly collect personal information from children. You must be at least 18 to create a Xuios account. If you believe we have collected information from a child, email hello@xuios.com and we will delete it.

12. International transfers

We may process information in the United States and other countries where our providers operate. Those countries may have different data-protection laws than your own. Where required, we use appropriate safeguards (such as standard contractual clauses with processors) to protect personal information.

13. Changes to this policy

We may update this Privacy Policy from time to time. The “Last updated” date at the top will change, and we will post the new version at https://xuios.com/privacy. If changes are material, we will provide additional notice (for example, by email or an in-product message). Continued use of the Service after the effective date means you accept the updated policy.

14. Contact

Privacy and data-subject requests: hello@xuios.com

Contact form: https://xuios.com/contact

Data deletion instructions: https://xuios.com/data-deletion

Terms of Service: https://xuios.com/terms