CRIYO AICRIYO AI Back to home
Legal

Privacy Policy

Effective Date: 25 August 2026Last Updated: 25 August 2026

1. Who We Are

This Privacy Policy ("Policy") explains how Criyo AI ("Criyo AI", "we", "us", "our") collects, uses, discloses, stores, and protects personal information when you visit criyo.ai (the "Website") or use the Criyo AI platform, applications, integrations, and related services (together, the "Services").

Criyo AI is a sole proprietorship operated by Charin Paresh Shah, with a registered place of business at Narayan Dabholkar Road, Mumbai, Maharashtra 400006, India, and registered under GSTIN 27LANPS7535L1ZK in the trade name CRIYO AI.

For the purposes of India's Digital Personal Data Protection Act, 2023 (the "DPDP Act"), we act as a Data Fiduciary in relation to the personal data of our own account holders, and as a Data Processor in relation to end user data that our customers bring into the platform. For the purposes of the EU General Data Protection Regulation ("GDPR") and UK GDPR, where these apply, the equivalent roles are controller and processor respectively. Section 4 explains this split in detail.

You can reach us at any time at support@criyo.ai.

2. Scope of This Policy

This Policy applies to:

  • Visitors to criyo.ai and any subdomain or hosted application operated by us
  • Account holders who register for and use the Services ("Users" or "you")
  • Prospective customers who request a demo, subscribe to updates, or contact us
  • Individuals who communicate with us for support, billing, or any other purpose

This Policy does not apply to how our Users handle the personal data of their own audiences within the platform. Where a User connects their social account and uses Criyo AI to communicate with their followers, leads, or customers, that User determines the purpose of the processing and is responsible under applicable law for that data. Our obligations in that scenario are set out in Section 4.2 and, where we have entered into one with you, in a separate data processing agreement.

This Policy also does not apply to third party websites, platforms, or services we link to or integrate with. Those operate under their own privacy policies.

3. Definitions

  • Personal Data or Personal Information means any data about an individual who is identifiable by or in relation to that data, including name, email address, phone number, account identifiers, and social media handles.
  • Platform Data means any data we obtain from Meta Platforms, Inc. through the Instagram Graph API, including message content, comment content, user identifiers, profile information, and metadata.
  • End User means a follower, lead, subscriber, or customer of one of our Users, with whom that User communicates using the Services.
  • Services means the Criyo AI platform and all associated features, including direct message automation, comment automation, lead capture, broadcast messaging, contact management, in product reporting, and any successor features.

4. Information We Collect

We collect personal information in four ways: information you give us directly, Platform Data you authorise us to access, information collected automatically, and information we receive from third party providers.

4.1 Information You Provide Directly

When you create an account, subscribe, request support, or otherwise interact with us, we may collect:

  • Name and business or brand name
  • Email address
  • Account credentials, or a Google account identifier if you sign in with Google
  • Billing address and GST details where applicable
  • Time zone, display language, and account preferences
  • The content of messages, tickets, and enquiries you send us
  • Any information you voluntarily submit through forms, surveys, or onboarding questionnaires

4.2 Platform Data from Instagram

Criyo AI integrates with Instagram only. We do not integrate with Facebook Pages, WhatsApp, or any other Meta surface, and we do not request permissions for them.

When you connect an Instagram professional account to Criyo AI, you authorise us, through Meta's official Instagram Graph API and the permissions you explicitly grant during the OAuth consent flow, to access data on your behalf.

We request only the following three permissions:

PermissionWhat it allows us to accessWhy we need it
instagram_business_basicYour account ID, username, name, profile picture, and follower count, together with metadata for your posts, reels, and storiesTo identify your account, display it in your dashboard, and let you select the posts and reels that trigger an automation
instagram_business_manage_messagesDirect messages sent to and from your connected account, including message text, timestamps, sender identifier, and story repliesTo deliver the direct message automations you configure. Criyo AI has no inbox and does not sync your conversations. Only the messages that actually trigger one of your automations are shown back to you, in your Activity feed
instagram_business_manage_commentsComments and mentions on your posts, reels, and stories, and the ability to reply publicly, send a private reply, or hide a commentTo deliver the comment automations you configure, including automatic replies and comment to direct message flows, and to show you in your Activity feed which comment each automation acted on

Through these permissions we also receive basic public profile information about End Users who message or comment on your account, limited to what Meta returns through the API. This is typically their name, username, and profile picture.

We do not request permissions relating to advertising, ad accounts, audience creation, content publishing, or any Meta product other than Instagram. If we add a feature that requires an additional permission in future, you will be asked to authorise it separately, and this Policy will be updated before we do so.

We access Platform Data solely to operate the automations you have configured. We do not access data beyond the scope of the permissions you grant. We do not read messages or comments for any purpose other than executing the automations you have configured and showing you the result in your Activity feed. We do not access accounts you have not connected.

4.3 What We Keep From a Message or Comment

Criyo AI has no inbox and no conversation view. We do not sync, mirror, or browse your Instagram messages, and there is no screen that lets you read your audience's messages generally.

There is one place where this data is shown to you: your Activity feed. It lists the comments, story replies, and direct messages that actually triggered one of your automations, so you can see what your automation reacted to and what it did in response. It shows activity on your own connected accounts only.

That distinction decides what we keep:

ItemDo we keep it?For how long
A message or comment that triggered one of your automationsYes, and it is shown in your Activity feedStored with that automation run and deleted with it, within 90 days
A message or comment that did not trigger anythingOnly inside the raw event Meta sent us, and it is never displayed anywhereReadable for 30 days, then the content is stripped; the record is deleted within 90 days
A copy of the text in your contacts, lead records, or exportsNoIt is never written to any of them
The Instagram comment or message identifierYesWith the automation run, until that run is purged on the 90 day cycle
The Instagram username of the person who messaged or commentedYesOn the contact record, for as long as you keep the contact

So nothing accumulates into a searchable archive of your audience's messages. What you can see is the specific interaction each automation acted on, for as long as we keep that run, and nothing else.

4.4 Your Role and Ours

In relation to End User data, you are the Data Fiduciary and we are the Data Processor. You are responsible for having a lawful basis to message your audience, for honouring opt outs, for making your own privacy disclosures to your audience, and for complying with Meta's Platform Terms and messaging policies. We process this data only on your documented instructions, as configured through your account.

4.3 Information Collected Automatically

When you use the Website or the Services, our own systems automatically record:

  • IP address and the approximate geographic location derived from it
  • Browser type and version, operating system, and device type
  • Date and time of access, and session identifiers
  • Pages and features accessed within the application
  • Application logs, error traces, and diagnostic data generated by our infrastructure
  • Essential cookies required for authentication and session management

This information is generated and stored by our own infrastructure. As set out in Section 9, we do not currently use any third party analytics or tracking service.

4.4 Information from Third Parties

  • Google. If you sign in with Google, we receive your name, email address, Google account ID, and profile picture. We request only the minimum scopes needed to authenticate you. We do not access your Gmail, Drive, Calendar, or Contacts.
  • Meta Platforms. As described in Section 4.2.
  • Razorpay. Transaction status, payment method type, the last four digits of the instrument, and invoice records.

5. How We Use Your Information

We use personal information to:

  • Create, authenticate, and maintain your account
  • Provide, operate, and deliver the Services, including executing the automations you configure
  • Process payments, issue invoices, manage subscriptions, and handle renewals and refunds
  • Provide customer support and respond to your enquiries
  • Send transactional and service communications, including security alerts, billing notices, downtime notifications, and product updates
  • Monitor, investigate, prevent, and detect fraud, abuse, spam, security incidents, and violations of our Terms
  • Understand how the Services are used and improve their performance, reliability, and features
  • Generate aggregated, de-identified statistics about platform usage
  • Send marketing communications where you have consented to receive them
  • Comply with legal, tax, accounting, and regulatory obligations
  • Establish, exercise, or defend legal claims

6. Legal Basis for Processing

6.1 Under the DPDP Act, 2023 (India)

We process personal data on the basis of:

  • Consent, obtained at the point of collection, and which is free, specific, informed, unconditional, and unambiguous. This covers purposes including account creation, connecting your social accounts, and marketing communications. You may withdraw consent at any time, and withdrawal is as easy as giving it.
  • Certain Legitimate Uses as permitted under Section 7 of the DPDP Act, including where you voluntarily provide data for a specified purpose, for compliance with any law or judgment, and for responding to a medical emergency or a threat to public health or safety.

6.2 Under the GDPR and UK GDPR (where applicable)

Where you are located in the European Economic Area, the United Kingdom, or Switzerland, we rely on:

  • Performance of a contract, Art. 6(1)(b), to provide and maintain the Services, manage your account, and process payments.
  • Consent, Art. 6(1)(a), for marketing communications, non essential cookies, and connecting third party accounts.
  • Legitimate interests, Art. 6(1)(f), to secure the platform, prevent fraud and abuse, provide support, improve our products, and communicate with existing customers about similar services. Where we rely on legitimate interests, we have assessed that our interests are not overridden by your rights and freedoms, and you may object at any time.
  • Legal obligation, Art. 6(1)(c), to meet tax, accounting, and regulatory requirements.

Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal.

7. Our Commitments Regarding Meta Platform Data

We comply with the Meta Platform Terms, the Meta Developer Policies, and the Instagram Platform Policy. Specifically, and without qualification:

  • We do not sell, license, or rent Platform Data to any party, under any circumstances.
  • We do not use Platform Data for advertising or ad targeting. Platform Data is never used to build advertising audiences, to create lookalike audiences, or for retargeting.
  • We do not transfer Platform Data to data brokers, information brokers, or monetisation intermediaries.
  • We do not use Platform Data to build or enrich user profiles outside the account it belongs to, and we do not combine Platform Data across unrelated Users' accounts.
  • We do not use Platform Data to train general purpose machine learning or AI models. Where AI features are offered within the Services, processing is scoped to your own account and its own data, and is performed only to deliver the feature you have requested.
  • We do not attempt to re-identify de-identified or anonymised data.
  • We access only the permissions you explicitly grant, and only for the duration of your authorisation.
  • We delete Platform Data when you disconnect your account, when you delete your Criyo AI account, when you request deletion, when the data is no longer needed for the purpose for which it was collected, or when required by Meta, whichever occurs first.
  • Our internal access is restricted. Only authorised personnel may access Platform Data, only where necessary for support, security, or debugging, and only where you have requested support or an active incident requires it. All such access is logged.

If Meta requests it, we will comply with audits and provide the information necessary to demonstrate compliance with these commitments.

8. Cookies and Similar Technologies

We use cookies and local storage to operate the Website and the Services.

  • Strictly necessary cookies are required for the Website and application to function. These handle authentication, session management, security, and load balancing. They cannot be disabled.
  • Functional cookies remember your preferences, such as display language and interface settings.

As at the Effective Date of this Policy, we set only strictly necessary and functional cookies. We do not operate any analytics, advertising, or tracking cookies, and we do not host any third party tracking pixels or tags.

If we introduce analytics, advertising, or other non essential technologies in future, we will update Section 9 of this Policy to name the provider and the categories of data involved, and, where the law requires it, we will obtain your consent through a cookie notice before any such technology is loaded.

You can block or delete cookies at any time through your browser settings. Blocking strictly necessary cookies will prevent you from signing in to and using the Services.

Further detail is available in our Cookie Policy at criyo.ai/cookies.

9. Service Providers and Sub-Processors

We rely on a small number of vetted third parties to operate the Services. Each is bound by contract to process personal data only on our instructions and to maintain appropriate security safeguards.

ProviderPurposeData CategoriesLocation
Amazon Web ServicesCloud hosting, storage, database, and backupsAll platform dataIndia, Asia Pacific (Mumbai) ap-south-1
Razorpay Software Private LimitedPayment processing and subscription billingName, email, billing details, transaction recordsIndia
Google LLCAuthentication via Google Sign-InName, email, Google account ID, profile pictureUnited States
Meta Platforms, Inc.Instagram Graph API integrationPlatform Data as described in Section 4.2United States
Resend, Inc.Delivery of transactional email, including account, authentication, billing, and service notificationsName, email address, message contentUnited States

We do not currently engage any third party analytics, advertising, attribution, or visitor identification providers. The list above is complete as at the Effective Date. If we add a provider in future, we will update this table to name the entity, the purpose, the categories of data involved, and its location, and we will obtain your consent where the law requires it.

We do not store your complete card number, CVV, or UPI credentials at any point. All payment credentials are captured and processed directly by Razorpay, which is PCI DSS compliant. We receive only the transaction outcome and a masked reference to the instrument used.

10. Sharing and Disclosure

We do not sell or rent your personal data. We disclose personal data only in the following circumstances:

  • To service providers and sub-processors, as listed in Section 9, strictly to operate and deliver the Services.
  • To our Users, where the data relates to their own End Users. Data belonging to one User's account is never disclosed to another User.
  • For legal reasons, where we believe in good faith that disclosure is necessary to comply with applicable law, a binding court order, or a valid request from a government or law enforcement authority; to enforce our Terms; to protect our rights or property; or to protect the safety of any person.
  • In connection with a corporate transaction, such as a merger, acquisition, financing, reorganisation, or sale of assets, in which case personal data may transfer as part of the transaction, subject to confidentiality and protection obligations at least equivalent to those in this Policy. We will notify you before your data becomes subject to a materially different privacy policy.
  • With your consent, for any other purpose disclosed to you at the time.

Handling of government and law enforcement requests. Before disclosing anything, we review the legality and validity of each request, we challenge requests we consider unlawful or overbroad, we disclose only the minimum data necessary to respond to a valid request, and we maintain a record of each request and our response. Where we are legally permitted to do so, we will notify the affected User.

11. Data Retention

We apply a minimum retention approach. We retain personal data only for as long as necessary for the purposes set out in this Policy, and no longer, unless a longer period is required by law. We do not retain personal data indefinitely.

Data CategoryRetention Period
Raw message and comment content as received from Meta30 days, then the content is stripped from the record
Message and comment event records, without content90 days on a rolling basis, then automatically purged
Automation run records, including the message or comment that triggered the run90 days on a rolling basis, then automatically purged
Contact and subscriber recordsFor the duration of your active account
Automation configurations and flow dataFor the duration of your active account
Account and profile dataFor the duration of your account, plus up to 30 days after you delete it
Data after a subscription endsRetained for as long as your account exists. Your live automations move to Draft and stop running, but nothing is deleted, so renewing restores your setup
Internal audit trail of actions taken in your account365 days
Billing, invoice, and GST records7 years, as required under Indian tax and accounting law
Server, access, and security logs90 days
Marketing contact dataUntil you unsubscribe or withdraw consent
Support correspondence24 months

Platform Data obtained from Meta is subject to a shorter rule that overrides the table above. Message and comment content is purged on a 90 day rolling basis while your account is active, and the readable content is in fact stripped after 30 days. All Platform Data associated with a connection is deleted within 30 days of you disconnecting that account, deleting your Criyo AI account, or submitting a deletion request, whichever occurs first. See Sections 7 and 12.

Two things are kept for longer, and only because deleting them would work against you or against Meta. The first is aggregate daily counters, such as how many automations ran or how many leads were captured. These hold numbers only, with no identifiers and no message content, and they are what your reports are drawn from. The second is the Instagram account identifier on a disconnected account, which is the minimum we need to recognise a reconnection and to honour a deletion request that arrives later referring to that account. Every other field on a disconnected account is erased.

An access token is never held for a grace period. It is deleted the moment you disconnect an account or remove Criyo AI from your Instagram settings.

When personal data is no longer required, we securely delete or irreversibly anonymise it. Backups are purged on their own cycle, which may extend deletion by up to 30 days beyond the periods stated above.

12. Data Deletion and How to Request It

You may delete your data at any time through any of the following routes.

  1. Disconnect a social account. Open Settings, then Connected Accounts, and disconnect the account. All Platform Data associated with that connection is deleted within 30 days.
  2. Delete your Criyo AI account. Open Settings, then Account, then Delete Account. Your account stops working immediately: you can no longer sign in and your automations stop running. Your data is then permanently erased within 30 days, which includes your connected account data, contacts, automations, and every event record we hold. Billing records are retained only for the period required by law. If you sign up again with the same email address inside that window, the pending erasure is completed first and you are given a new, empty account.
  3. Revoke access from Instagram directly. In your Instagram settings, open Apps and Websites, then Active, and remove Criyo AI. This immediately revokes our access. Any Platform Data we hold is deleted within 30 days.
  4. Email us. Send a request from your registered email address to support@criyo.ai with the subject line "Data Deletion Request". We will verify your identity and confirm completion within 30 days.
  5. Request deletion through Instagram. If you ask Meta to delete your data, Meta notifies us directly. We record the request, return a confirmation code, and give you a link where you can check its status at any time until it is complete.

Full step by step instructions are available on our Data Deletion Instructions page.

We may retain certain data after a deletion request where required to comply with a legal or regulatory obligation, to resolve a dispute, to prevent fraud or abuse, or to enforce our agreements. Where we do so, we retain only the minimum necessary and only for as long as necessary.

13. Security

We implement reasonable technical and organisational measures designed to protect personal data against unauthorised access, disclosure, alteration, and destruction. These include:

  • Encryption in transit using TLS, and encryption at rest for stored data
  • Role based access controls and the principle of least privilege
  • Access tokens stored in encrypted form, never in plaintext
  • Network isolation, firewalls, and security group restrictions on our AWS infrastructure
  • Regular backups with restricted access
  • Logging and monitoring of administrative and privileged access
  • Periodic review of our security practices and dependencies

No method of transmission over the internet and no method of electronic storage is completely secure, and we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of your account credentials and for signing out of shared devices.

Breach notification. In the event of a personal data breach, we will notify the Data Protection Board of India and affected Data Principals as required under the DPDP Act. Where the GDPR applies, we will notify the relevant supervisory authority within 72 hours and affected individuals where the breach is likely to result in a high risk to their rights and freedoms, in accordance with Articles 33 and 34.

14. International Data Transfers

Criyo AI is established in India. Personal data is processed and stored in India on Amazon Web Services infrastructure in the Asia Pacific (Mumbai) ap-south-1 region.

Some of our service providers are located outside India, including in the United States. Where personal data is transferred to a jurisdiction that does not provide an equivalent level of protection, we rely on appropriate safeguards, including contractual data protection terms and, where the GDPR applies, the European Commission's Standard Contractual Clauses under Articles 45 and 46, or the recipient's adherence to a recognised adequacy framework.

You may request further information about the safeguards we rely on by emailing support@criyo.ai.

15. Your Rights

15.1 Rights Under the DPDP Act, 2023

As a Data Principal, you have the right to:

  • Access. Obtain a summary of the personal data we process about you, the processing activities undertaken, and the identities of any other Data Fiduciaries with whom it has been shared.
  • Correction and erasure. Have inaccurate or misleading data corrected, incomplete data completed, and data erased where it is no longer needed for the purpose for which it was collected.
  • Grievance redressal. Raise a grievance with us in the first instance, as set out in Section 19.
  • Nomination. Nominate another individual to exercise your rights in the event of your death or incapacity.
  • Withdrawal of consent. Withdraw your consent at any time, with the same ease with which it was given.

15.2 Rights Under the GDPR and UK GDPR

If you are located in the EEA, the United Kingdom, or Switzerland, you additionally have the right to:

  • Access, Art. 15. Obtain confirmation of processing and a copy of your data.
  • Rectification, Art. 16. Have inaccurate or incomplete data corrected.
  • Erasure, Art. 17. Have your data deleted where the conditions apply.
  • Restriction, Art. 18. Limit how we process your data in certain circumstances.
  • Data portability, Art. 20. Receive your data in a structured, commonly used, machine readable format.
  • Objection, Art. 21. Object to processing based on legitimate interests, including direct marketing.
  • Withdrawal of consent, Art. 7(3). Withdraw consent at any time, without affecting prior lawful processing.
  • Not to be subject to automated decision making, Art. 22, producing legal or similarly significant effects.
  • Complaint, Art. 77. Lodge a complaint with your local supervisory authority.

15.3 Exercising Your Rights

Email support@criyo.ai from your registered address. We will verify your identity before acting on any request, in order to protect your data from unauthorised disclosure. We respond within 30 days under the DPDP Act, and within one month under the GDPR. Under the GDPR this period may be extended by a further two months where the request is complex, in which case we will tell you within the first month.

If your request concerns data held by one of our Users, for example if you are a follower whose messages were processed through a brand's Criyo AI account, please contact that brand directly, as they are the Data Fiduciary for that data. If you contact us instead, we will forward your request to the relevant User and assist them in responding.

16. Automated Processing

The Services execute automated actions such as sending replies, tagging contacts, routing conversations, and applying keyword triggers, based on rules that Users configure themselves. These are rule based workflows that operate on your instructions.

We do not make automated decisions that produce legal effects concerning you or that similarly significantly affect you.

17. Children's Privacy

The Services are intended for business use and are not directed at children. We do not knowingly collect personal data from any individual under the age of 18.

Under the DPDP Act, processing the personal data of a child requires verifiable consent from a parent or lawful guardian. We do not undertake tracking, behavioural monitoring, or targeted advertising directed at children. Where the GDPR applies, our Services are not directed to children under 16.

If you believe a child has provided us with personal data, contact support@criyo.ai and we will take steps to delete it.

18. Links to Third Party Sites

The Services may contain links to websites, platforms, and services that we do not operate or control. This Policy does not govern those. We encourage you to review the privacy policy of any third party before providing them with personal data. Providing a link does not imply endorsement.

19. Grievance Redressal

In accordance with the DPDP Act, 2023 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, we have appointed a Grievance Officer to address complaints regarding this Policy or our data practices.

Grievance Officer
Charin Paresh Shah
Criyo AI
Narayan Dabholkar Road, Mumbai, Maharashtra 400006, India
Email: support@criyo.ai

Please include your registered email address, a clear description of the grievance, and any supporting information. We acknowledge grievances within 24 hours and resolve them within 30 days.

If you are not satisfied with our resolution, you may escalate your complaint to the Data Protection Board of India as constituted under the DPDP Act. If the GDPR applies to you, you may lodge a complaint with your local supervisory authority.

20. Changes to This Policy

We may update this Policy to reflect changes in our practices, technology, legal requirements, or business operations. When we make material changes, we will update the Effective Date at the top of this Policy and notify you through the Website, by email, or through an in product notice, as appropriate.

Where a change materially expands how we use personal data collected under a prior version, we will obtain fresh consent where the law requires it. Your continued use of the Services after an update constitutes acknowledgement of the revised Policy.

21. Contact Us

Contact us
Email: support@criyo.ai
Phone: +91 74045 09986
Mail: CRIYO AI, Narayan Dabholkar Road, Mumbai, Maharashtra 400006, India
Criyo AI
Operated by Charin Paresh Shah (Sole Proprietorship)
Narayan Dabholkar Road, Mumbai, Maharashtra 400006, India
GSTIN: 27LANPS7535L1ZK (trade name CRIYO AI)
Email: support@criyo.ai
Website: criyo.ai

This Privacy Policy was last updated on 25 August 2026.

CRIYO AICRIYO AI

Your #1 hire for Instagram. Capture every comment, every DM, every story reply, and turn it into a closed client - on autopilot.

support@criyo.ai +91 74045 09986
Narayan Dabholkar Road, Mumbai, Maharashtra 400006, India
Product
  • Features
  • Pricing
Company
  • About
  • Contact
Legal
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Refund Policy
  • Data Deletion
  • DPDP Compliance
© 2026 CRIYO AI. GSTIN 27LANPS7535L1ZK.
Made in Mumbai, India.•Designed & Developed by HW Infotech
CRIYO AI is not affiliated with, endorsed by, or sponsored by Meta Platforms, Inc. or Instagram. CRIYO AI uses Meta's official Instagram Graph API as a third-party developer.