BetaBeta version of the site. Questions or feedback — email support@wowpostio.com
WowPostio AI
Start free

Privacy Policy

Last updated: August 22, 2026

This Privacy Policy explains how WowPostio AI («WowPostio», «we», «us») collects, uses, stores, shares and protects personal data when you use wowpostio.com and the WowPostio service («Service»). It describes our practices. Using the site does not replace a separate legal basis where the law requires one (for example, optional ads cookies).

1. Who we are

WowPostio is a SaaS that helps small and medium businesses plan, generate and publish Instagram content and handle inbox messages through the official Instagram Graph API. For data about your account and how you use the Service, we decide the purposes and means of processing.

Privacy requests: privacy@wowpostio.com.

2. Roles: your account vs your customers

  • Your account (email, password hash, business profile, billing metadata, settings) — we process this to run the Service for you.
  • People who write to your Instagram (Direct messages, comments, story replies, names, handles, phone or WhatsApp numbers they send, lead fields you capture) — you decide why those messages are handled. We process them on your instructions to show the inbox, draft or send replies you enable, capture leads, and pass a WhatsApp link when that is part of your setup. You are responsible for telling those people how you use their data and for honoring their rights.

3. Data we collect

3.1. Account data (you provide)

  • Name, email, password hash
  • Business profile (name, niche, language, audience, knowledge files)
  • Optional photos (logo, brand assets, face photos for AI avatars)
  • Billing data processed by Stripe

3.2. Instagram (Graph API, scopes you approve)

  • Account ID, username, profile picture, biography
  • Posts, captions and media you publish through the Service
  • Aggregated insights for your own posts and account
  • Comments on your posts and Direct messages in your Business inbox — shown in WowPostio and used to draft or send replies when you turn on auto-reply or send a reply yourself

We do not scrape Instagram, do not read private follower profiles, and do not take data beyond the permissions you grant.

3.3. Inbox automation you can enable

  • Auto-reply to incoming Direct messages, comments and story replies, using your knowledge base — only when you enable it
  • Lead capture (for example name or phone the visitor typed)
  • WhatsApp handoff: if you store a business WhatsApp number, replies may include a wa.me link so the visitor can continue on WhatsApp

We do not use the Service to cold-DM strangers, auto-follow, auto-like, or run other outreach Meta forbids. Replies go to people who already wrote to your account.

3.4. Technical and ads measurement

  • IP address, browser, device, OS, pages, timestamps (server logs)
  • Necessary cookies: session, locale, first-touch campaign tags we store ourselves
  • Google Analytics 4 (page views and basic events)
  • Optional ads cookies, only after you accept: Google Ads (hashed email on sign-up for enhanced conversions) and Meta Pixel (PageView and CompleteRegistration)

4. How we use data

  • Operate the Service, generate content, publish when you approve
  • Inbox, auto-reply, leads and WhatsApp handoff you configured
  • Billing and transactional email
  • Security, abuse prevention, debugging
  • Legal obligations
  • If you accepted ads cookies: measure campaigns and sign-ups

We do not sell personal data. We do not use data obtained from Meta to train foundation AI models.

5. Legal bases

Depending on your country this maps to GDPR, Brazil’s LGPD (Law 13.709/2018), Mexico’s LFPDPPP, or Russia’s 152-FZ:

  • Contract — account, publishing, inbox features you turned on
  • Consent — Instagram connection, optional cookies, face photos for avatars, marketing email
  • Legitimate interest / equivalent — security, first-party diagnostics
  • Legal obligation — tax and invoices

6. Cookies

Necessary cookies and Google Analytics 4 run without a prompt. Advertising cookies (Google Ads and Meta Pixel) and a hashed email to Google load only after you click accept. Without accept, Google may still get cookieless measurement pings (Consent Mode) — no ads cookies and no email. You can change your choice by clearing the wp_cookie_consent cookie and reloading.

7. Sub-processors

We share the minimum needed. Each vendor is under a data-processing term.

  • Meta Platforms — Instagram Graph API; Meta Pixel if you accepted ads cookies
  • Google — Gemini for generation; Analytics 4 for traffic; Ads and a hashed email on sign-up only if you accepted ads cookies
  • OpenAI, Anthropic — text generation for the request
  • HeyGen, ElevenLabs, fal.ai — avatars, voice, video
  • Supabase — database and files
  • Stripe — payments (paid plans are charged in USD)
  • Vercel, Inngest — hosting and background jobs

8. International transfers

Some vendors are in the EU or the United States. Transfers use Standard Contractual Clauses or equivalent safeguards, including mechanisms recognized for Brazil under ANPD Resolution CD/ANPD No. 19/2024 where that law applies.

9. Retention

  • Account and content — until you delete them or the account
  • Instagram tokens — until you disconnect or revoke access in Instagram
  • Inbox messages stored for your workspace — until you delete them or the account
  • Invoices — as tax law requires (often up to 7 years)
  • Technical logs — up to 90 days

After an account deletion request we remove personal data from active systems within 30 days, except records the law says we must keep.

10. Your rights

You can access, correct, export, delete, withdraw consent, or object.

Email privacy@wowpostio.com. We confirm within 3 business days and complete the request within 15 days (or the shorter deadline your local law sets). Full wipe from backups and active systems follows the data deletion page (up to 30 days for technical purge).

You may complain to your data protection authority (for example ANPD in Brazil).

11. Security

TLS in transit, encryption at rest at our cloud providers, 2FA for production access. We do not store plain-text passwords or full card numbers.

12. Children

The Service is for people 18 or older. We do not knowingly collect data from children. If you think we have, write to us and we will delete it.

13. Changes

Material changes are announced by email or in the product at least 30 days in advance.

14. Contact

privacy@wowpostio.com