Privacy Policy
How we collect, use, and protect your information.
Last Updated: February 2026
1. Introduction
GreetFan ("we," "us," or "our") provides AI-powered Instagram engagement automation services through our website at greetfan.com and related applications (collectively, the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.
By using GreetFan, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies and practices, do not use our Service.
2. Information We Collect
2.1 Account Information
When you create a GreetFan account, we collect:
- Instagram Business or Creator account information obtained through OAuth authentication
- Instagram username, profile information, and account ID
- Authentication tokens provided by Instagram's API (encrypted at rest)
2.2 Instagram Data
Through the Instagram Graph API, we access and store:
- Your media posts (captions, timestamps, media type)
- Comments on your posts (commenter username, comment text, timestamps)
- Direct message conversations and messages (sender, message text, timestamps)
- Account insights and engagement metrics provided by Instagram
- Top engaged user data for audience analytics
2.3 Usage Data
We automatically collect:
- Activity logs (actions taken within the platform, timestamps, status)
- AI reply generation history (prompts sent, replies received, approval status)
- Reply queue data (scheduled times, delivery status, retry counts)
- Session information and authentication state
2.4 Subscription Information
If you subscribe to a paid plan, we collect:
- Email address (encrypted at rest using Fernet encryption)
- Subscription plan and feature usage data
- Payment processing is handled by Stripe; we do not store credit card numbers
3. How We Use Your Information
We use the information we collect to:
- Provide and maintain the Service, including syncing your Instagram data and generating AI reply suggestions
- Process and deliver AI-generated replies through the Instagram API on your behalf
- Display analytics and engagement insights in your dashboard
- Manage your account, subscription, and feature access
- Monitor API rate limits and ensure compliance with Instagram's usage policies
- Log activity for audit trails and troubleshooting
- Communicate with you about service updates, if applicable
4. AI Processing & Third-Party AI Providers
This is important to understand: GreetFan supports multiple AI providers for generating reply suggestions. The data shared with AI providers depends on which provider you configure:
4.1 OpenAI
When OpenAI is selected as your AI provider, the following data is sent to OpenAI's API for processing:
- Comment text and post captions (for comment replies)
- Message text and conversation history (for DM replies)
- Your custom prompt template content
OpenAI's data usage is governed by their own privacy policy and terms of use.
4.2 Google Gemini
When Google Gemini is selected, the same categories of data listed above are sent to Google's Gemini API. Google's data handling is governed by their own privacy policy and generative AI terms.
4.3 Ollama (Self-Hosted)
When Ollama is selected, AI processing occurs on the Ollama instance you configure (which may be on your own infrastructure or a server you control). In this case, no Instagram data is sent to third-party AI providers through GreetFan. Data handling depends on your Ollama deployment configuration.
4.4 Your Choice
You can change your AI provider at any time from your account settings. If data privacy is a priority, we recommend using Ollama for fully local AI processing.
5. Instagram Data & API Usage
GreetFan accesses your Instagram data through Meta's official Instagram Graph API using the following OAuth scopes:
instagram_business_basic— Read account profile and mediainstagram_business_manage_comments— Read and reply to commentsinstagram_business_manage_messages— Read and send direct messagesinstagram_business_content_publish— Publish content on your behalfinstagram_business_manage_insights— Access engagement analytics
We only access Instagram data that you explicitly authorize through the OAuth consent flow. You can revoke GreetFan's access at any time through your Instagram account settings.
Instagram enforces a 24-hour window for direct message replies. GreetFan respects this constraint and automatically marks messages as expired when they exceed this window.
6. Data Storage & Security
- Your data is stored in a database on our servers
- Sensitive subscription fields (email, license keys) are encrypted at rest using Fernet symmetric encryption
- Data integrity is verified using HMAC-SHA256 signatures
- Instagram access tokens are stored securely and refreshed automatically before expiration
- All connections to greetfan.com use HTTPS/TLS encryption in transit
- Session cookies are configured with HttpOnly, SameSite=Lax, and Secure flags (in production)
While we implement reasonable security measures, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security of your data.
7. Data Retention & Deletion
We retain your data for as long as your account is active and as needed to provide the Service. Specifically:
- Instagram data (posts, comments, messages) is retained while your account is connected
- Activity logs are retained for operational and audit purposes
- AI reply history is retained for your review and analytics
You may request deletion of your data by contacting us at privacy@greetfan.com. Upon receiving a valid deletion request, we will delete your personal data within 30 days, except where retention is required by law.
8. Third-Party Services
GreetFan integrates with the following third-party services:
- Meta / Instagram — For Instagram Graph API access (required for core functionality)
- OpenAI — Optional AI provider for generating reply suggestions
- Google (Gemini) — Optional AI provider for generating reply suggestions
- Stripe — Payment processing for paid subscriptions
Each third-party service has its own privacy policy governing how they handle data. We encourage you to review their respective privacy policies.
9. Cookies & Tracking
GreetFan uses session cookies to maintain your authentication state and preferences (such as theme settings). These are essential cookies required for the Service to function.
We do not currently use third-party analytics cookies, advertising trackers, or cross-site tracking technologies.
10. Your Rights
10.1 GDPR Rights (EEA Residents)
If you are located in the European Economic Area, you have the following rights:
- Access — Request a copy of the personal data we hold about you
- Rectification — Request correction of inaccurate personal data
- Erasure — Request deletion of your personal data
- Portability — Request your data in a structured, machine-readable format
- Restriction — Request limitation of processing of your personal data
- Objection — Object to processing of your personal data
10.2 CCPA Rights (California Residents)
If you are a California resident, you have the right to:
- Know — Request disclosure of the categories and specific pieces of personal information we collect
- Delete — Request deletion of personal information we have collected
- Opt-Out — Opt out of the sale of personal information (we do not sell personal information)
- Non-Discrimination — Not be discriminated against for exercising your privacy rights
To exercise any of these rights, contact us at privacy@greetfan.com. We will respond to your request within 30 days.
11. Children's Privacy
GreetFan is not intended for use by individuals under the age of 16. We do not knowingly collect personal information from children under 16. If we become aware that we have collected personal data from a child under 16, we will take steps to delete that information promptly.
12. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. When you use a cloud AI provider (OpenAI or Google Gemini), your data may be processed in the United States or other jurisdictions where those providers operate. By using the Service, you consent to such transfers.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by updating the "Last Updated" date at the top of this policy. Your continued use of the Service after changes become effective constitutes acceptance of the revised policy.
Contact: For privacy-related inquiries, contact us at privacy@greetfan.com.
Terms of Service
The rules and guidelines for using GreetFan.
Last Updated: February 2026
1. Acceptance of Terms
By accessing or using GreetFan ("the Service"), you agree to be bound by these Terms of Service ("Terms"). If you do not agree to these Terms, you may not use the Service. These Terms constitute a legally binding agreement between you and GreetFan.
2. Service Description
GreetFan is a software-as-a-service platform that provides:
- AI-powered automated reply suggestions for Instagram comments and direct messages
- A review workflow for approving, editing, or rejecting AI-generated replies
- Instagram engagement analytics and audience insights
- Integration with multiple AI providers (OpenAI, Google Gemini, Ollama)
- Scheduled polling and rate-limited reply delivery
The Service operates through Meta's official Instagram Graph API. Availability and functionality are subject to Instagram's API terms and rate limits.
3. Account Requirements
- You must have an Instagram Business or Creator account to use GreetFan
- You must authorize GreetFan through Instagram's OAuth consent flow
- You are responsible for maintaining the security of your account credentials
- You must be at least 16 years of age to use the Service
- You represent that the information you provide is accurate and complete
4. Acceptable Use
When using GreetFan, you agree to:
- Comply with Instagram's Terms of Use and Community Guidelines
- Not use the Service to send spam, unsolicited messages, or harassing content
- Not use the Service to impersonate other individuals or entities
- Not attempt to circumvent Instagram's API rate limits or automation policies
- Not use the Service for any illegal or unauthorized purpose
- Review AI-generated replies for accuracy and appropriateness before sending
We reserve the right to suspend or terminate accounts that violate these guidelines.
5. Subscription & Billing
- GreetFan offers free and paid subscription plans
- Paid plans are billed monthly at the rates displayed on our pricing page
- You may upgrade, downgrade, or cancel your subscription at any time
- Cancellation takes effect at the end of the current billing period
- We do not offer refunds for partial billing periods
- We reserve the right to change pricing with 30 days' notice
6. Intellectual Property
The Service, including its design, code, and documentation, is owned by GreetFan and protected by applicable intellectual property laws. You retain ownership of your Instagram content and any custom prompt templates you create within the Service.
AI-generated replies are provided as suggestions. You are responsible for the content you choose to send through your Instagram account.
7. Limitation of Liability & Disclaimers
THE SERVICE IS PROVIDED "AS IS" AND "AS AVAILABLE" WITHOUT WARRANTIES OF ANY KIND, WHETHER EXPRESS OR IMPLIED.
- GreetFan is not responsible for the accuracy or appropriateness of AI-generated reply suggestions
- GreetFan is not responsible for any actions taken by Instagram against your account, including restrictions, suspensions, or bans resulting from the use of automation tools
- GreetFan is not liable for service interruptions caused by Instagram API changes, rate limiting, or outages
- In no event shall GreetFan's total liability exceed the amount you paid for the Service in the 12 months preceding the claim
You acknowledge that Instagram may change their API terms, rate limits, or functionality at any time, which may affect the Service's availability or features.
8. Governing Law & Dispute Resolution
These Terms shall be governed by and construed in accordance with the laws of the State of California, United States, without regard to its conflict of law provisions.
Any disputes arising from these Terms or the Service shall be resolved through binding arbitration in San Francisco, California, except that either party may seek injunctive relief in any court of competent jurisdiction.
Contact: For questions about these Terms, contact us at hello@greetfan.com.