1. Who We Are
This Privacy Policy ("Policy") explains how Criyo AI ("Criyo AI", "we", "us", "our") collects, uses, discloses, stores, and protects personal information when you visit criyo.ai (the "Website") or use the Criyo AI platform, applications, integrations, and related services (together, the "Services").
Criyo AI is a sole proprietorship operated by Charin Paresh Shah, with a registered place of business at Narayan Dabholkar Road, Mumbai, Maharashtra 400006, India, and registered under GSTIN 27LANPS7535L1ZK in the trade name CRIYO AI.
For the purposes of India's Digital Personal Data Protection Act, 2023 (the "DPDP Act"), we act as a Data Fiduciary in relation to the personal data of our own account holders, and as a Data Processor in relation to end user data that our customers bring into the platform. For the purposes of the EU General Data Protection Regulation ("GDPR") and UK GDPR, where these apply, the equivalent roles are controller and processor respectively. Section 4 explains this split in detail.
You can reach us at any time at support@criyo.ai.
2. Scope of This Policy
This Policy applies to:
- Visitors to criyo.ai and any subdomain or hosted application operated by us
- Account holders who register for and use the Services ("Users" or "you")
- Prospective customers who request a demo, subscribe to updates, or contact us
- Individuals who communicate with us for support, billing, or any other purpose
This Policy does not apply to how our Users handle the personal data of their own audiences within the platform. Where a User connects their social account and uses Criyo AI to communicate with their followers, leads, or customers, that User determines the purpose of the processing and is responsible under applicable law for that data. Our obligations in that scenario are set out in Section 4.2 and, where we have entered into one with you, in a separate data processing agreement.
This Policy also does not apply to third party websites, platforms, or services we link to or integrate with. Those operate under their own privacy policies.
3. Definitions
- Personal Data or Personal Information means any data about an individual who is identifiable by or in relation to that data, including name, email address, phone number, account identifiers, and social media handles.
- Platform Data means any data we obtain from Meta Platforms, Inc. through the Instagram Graph API, including message content, comment content, user identifiers, profile information, and metadata.
- End User means a follower, lead, subscriber, or customer of one of our Users, with whom that User communicates using the Services.
- Services means the Criyo AI platform and all associated features, including direct message automation, comment automation, lead capture, broadcast messaging, contact management, in product reporting, and any successor features.
4. Information We Collect
We collect personal information in four ways: information you give us directly, Platform Data you authorise us to access, information collected automatically, and information we receive from third party providers.
4.1 Information You Provide Directly
When you create an account, subscribe, request support, or otherwise interact with us, we may collect:
- Name and business or brand name
- Email address
- Account credentials, or a Google account identifier if you sign in with Google
- Billing address and GST details where applicable
- Time zone, display language, and account preferences
- The content of messages, tickets, and enquiries you send us
- Any information you voluntarily submit through forms, surveys, or onboarding questionnaires
4.2 Platform Data from Instagram
Criyo AI integrates with Instagram only. We do not integrate with Facebook Pages, WhatsApp, or any other Meta surface, and we do not request permissions for them.
When you connect an Instagram professional account to Criyo AI, you authorise us, through Meta's official Instagram Graph API and the permissions you explicitly grant during the OAuth consent flow, to access data on your behalf.
We request only the following three permissions:
| Permission | What it allows us to access | Why we need it |
|---|---|---|
| instagram_business_basic | Your account ID, username, name, profile picture, and follower count, together with metadata for your posts, reels, and stories | To identify your account, display it in your dashboard, and let you select the posts and reels that trigger an automation |
| instagram_business_manage_messages | Direct messages sent to and from your connected account, including message text, timestamps, sender identifier, and story replies | To deliver the direct message automations you configure. Criyo AI has no inbox and does not sync your conversations. Only the messages that actually trigger one of your automations are shown back to you, in your Activity feed |
| instagram_business_manage_comments | Comments and mentions on your posts, reels, and stories, and the ability to reply publicly, send a private reply, or hide a comment | To deliver the comment automations you configure, including automatic replies and comment to direct message flows, and to show you in your Activity feed which comment each automation acted on |
Through these permissions we also receive basic public profile information about End Users who message or comment on your account, limited to what Meta returns through the API. This is typically their name, username, and profile picture.
We do not request permissions relating to advertising, ad accounts, audience creation, content publishing, or any Meta product other than Instagram. If we add a feature that requires an additional permission in future, you will be asked to authorise it separately, and this Policy will be updated before we do so.
We access Platform Data solely to operate the automations you have configured. We do not access data beyond the scope of the permissions you grant. We do not read messages or comments for any purpose other than executing the automations you have configured and showing you the result in your Activity feed. We do not access accounts you have not connected.
4.3 What We Keep From a Message or Comment
Criyo AI has no inbox and no conversation view. We do not sync, mirror, or browse your Instagram messages, and there is no screen that lets you read your audience's messages generally.
There is one place where this data is shown to you: your Activity feed. It lists the comments, story replies, and direct messages that actually triggered one of your automations, so you can see what your automation reacted to and what it did in response. It shows activity on your own connected accounts only.
That distinction decides what we keep:
| Item | Do we keep it? | For how long |
|---|---|---|
| A message or comment that triggered one of your automations | Yes, and it is shown in your Activity feed | Stored with that automation run and deleted with it, within 90 days |
| A message or comment that did not trigger anything | Only inside the raw event Meta sent us, and it is never displayed anywhere | Readable for 30 days, then the content is stripped; the record is deleted within 90 days |
| A copy of the text in your contacts, lead records, or exports | No | It is never written to any of them |
| The Instagram comment or message identifier | Yes | With the automation run, until that run is purged on the 90 day cycle |
| The Instagram username of the person who messaged or commented | Yes | On the contact record, for as long as you keep the contact |
So nothing accumulates into a searchable archive of your audience's messages. What you can see is the specific interaction each automation acted on, for as long as we keep that run, and nothing else.
4.4 Your Role and Ours
In relation to End User data, you are the Data Fiduciary and we are the Data Processor. You are responsible for having a lawful basis to message your audience, for honouring opt outs, for making your own privacy disclosures to your audience, and for complying with Meta's Platform Terms and messaging policies. We process this data only on your documented instructions, as configured through your account.
4.3 Information Collected Automatically
When you use the Website or the Services, our own systems automatically record:
- IP address and the approximate geographic location derived from it
- Browser type and version, operating system, and device type
- Date and time of access, and session identifiers
- Pages and features accessed within the application
- Application logs, error traces, and diagnostic data generated by our infrastructure
- Essential cookies required for authentication and session management
This information is generated and stored by our own infrastructure. As set out in Section 9, we do not currently use any third party analytics or tracking service.
4.4 Information from Third Parties
- Google. If you sign in with Google, we receive your name, email address, Google account ID, and profile picture. We request only the minimum scopes needed to authenticate you. We do not access your Gmail, Drive, Calendar, or Contacts.
- Meta Platforms. As described in Section 4.2.
- Razorpay. Transaction status, payment method type, the last four digits of the instrument, and invoice records.
5. How We Use Your Information
We use personal information to:
- Create, authenticate, and maintain your account
- Provide, operate, and deliver the Services, including executing the automations you configure
- Process payments, issue invoices, manage subscriptions, and handle renewals and refunds
- Provide customer support and respond to your enquiries
- Send transactional and service communications, including security alerts, billing notices, downtime notifications, and product updates
- Monitor, investigate, prevent, and detect fraud, abuse, spam, security incidents, and violations of our Terms
- Understand how the Services are used and improve their performance, reliability, and features
- Generate aggregated, de-identified statistics about platform usage
- Send marketing communications where you have consented to receive them
- Comply with legal, tax, accounting, and regulatory obligations
- Establish, exercise, or defend legal claims
6. Legal Basis for Processing
6.1 Under the DPDP Act, 2023 (India)
We process personal data on the basis of:
- Consent, obtained at the point of collection, and which is free, specific, informed, unconditional, and unambiguous. This covers purposes including account creation, connecting your social accounts, and marketing communications. You may withdraw consent at any time, and withdrawal is as easy as giving it.
- Certain Legitimate Uses as permitted under Section 7 of the DPDP Act, including where you voluntarily provide data for a specified purpose, for compliance with any law or judgment, and for responding to a medical emergency or a threat to public health or safety.
6.2 Under the GDPR and UK GDPR (where applicable)
Where you are located in the European Economic Area, the United Kingdom, or Switzerland, we rely on:
- Performance of a contract, Art. 6(1)(b), to provide and maintain the Services, manage your account, and process payments.
- Consent, Art. 6(1)(a), for marketing communications, non essential cookies, and connecting third party accounts.
- Legitimate interests, Art. 6(1)(f), to secure the platform, prevent fraud and abuse, provide support, improve our products, and communicate with existing customers about similar services. Where we rely on legitimate interests, we have assessed that our interests are not overridden by your rights and freedoms, and you may object at any time.
- Legal obligation, Art. 6(1)(c), to meet tax, accounting, and regulatory requirements.
Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal.
7. Our Commitments Regarding Meta Platform Data
We comply with the Meta Platform Terms, the Meta Developer Policies, and the Instagram Platform Policy. Specifically, and without qualification:
- We do not sell, license, or rent Platform Data to any party, under any circumstances.
- We do not use Platform Data for advertising or ad targeting. Platform Data is never used to build advertising audiences, to create lookalike audiences, or for retargeting.
- We do not transfer Platform Data to data brokers, information brokers, or monetisation intermediaries.
- We do not use Platform Data to build or enrich user profiles outside the account it belongs to, and we do not combine Platform Data across unrelated Users' accounts.
- We do not use Platform Data to train general purpose machine learning or AI models. Where AI features are offered within the Services, processing is scoped to your own account and its own data, and is performed only to deliver the feature you have requested.
- We do not attempt to re-identify de-identified or anonymised data.
- We access only the permissions you explicitly grant, and only for the duration of your authorisation.
- We delete Platform Data when you disconnect your account, when you delete your Criyo AI account, when you request deletion, when the data is no longer needed for the purpose for which it was collected, or when required by Meta, whichever occurs first.
- Our internal access is restricted. Only authorised personnel may access Platform Data, only where necessary for support, security, or debugging, and only where you have requested support or an active incident requires it. All such access is logged.
If Meta requests it, we will comply with audits and provide the information necessary to demonstrate compliance with these commitments.
8. Cookies and Similar Technologies
We use cookies and local storage to operate the Website and the Services.
- Strictly necessary cookies are required for the Website and application to function. These handle authentication, session management, security, and load balancing. They cannot be disabled.
- Functional cookies remember your preferences, such as display language and interface settings.
As at the Effective Date of this Policy, we set only strictly necessary and functional cookies. We do not operate any analytics, advertising, or tracking cookies, and we do not host any third party tracking pixels or tags.
If we introduce analytics, advertising, or other non essential technologies in future, we will update Section 9 of this Policy to name the provider and the categories of data involved, and, where the law requires it, we will obtain your consent through a cookie notice before any such technology is loaded.
You can block or delete cookies at any time through your browser settings. Blocking strictly necessary cookies will prevent you from signing in to and using the Services.
Further detail is available in our Cookie Policy at criyo.ai/cookies.
9. Service Providers and Sub-Processors
We rely on a small number of vetted third parties to operate the Services. Each is bound by contract to process personal data only on our instructions and to maintain appropriate security safeguards.
| Provider | Purpose | Data Categories | Location |
|---|---|---|---|
| Amazon Web Services | Cloud hosting, storage, database, and backups | All platform data | India, Asia Pacific (Mumbai) ap-south-1 |
| Razorpay Software Private Limited | Payment processing and subscription billing | Name, email, billing details, transaction records | India |
| Google LLC | Authentication via Google Sign-In | Name, email, Google account ID, profile picture | United States |
| Meta Platforms, Inc. | Instagram Graph API integration | Platform Data as described in Section 4.2 | United States |
| Resend, Inc. | Delivery of transactional email, including account, authentication, billing, and service notifications | Name, email address, message content | United States |
We do not currently engage any third party analytics, advertising, attribution, or visitor identification providers. The list above is complete as at the Effective Date. If we add a provider in future, we will update this table to name the entity, the purpose, the categories of data involved, and its location, and we will obtain your consent where the law requires it.
We do not store your complete card number, CVV, or UPI credentials at any point. All payment credentials are captured and processed directly by Razorpay, which is PCI DSS compliant. We receive only the transaction outcome and a masked reference to the instrument used.
10. Sharing and Disclosure
We do not sell or rent your personal data. We disclose personal data only in the following circumstances:
- To service providers and sub-processors, as listed in Section 9, strictly to operate and deliver the Services.
- To our Users, where the data relates to their own End Users. Data belonging to one User's account is never disclosed to another User.
- For legal reasons, where we believe in good faith that disclosure is necessary to comply with applicable law, a binding court order, or a valid request from a government or law enforcement authority; to enforce our Terms; to protect our rights or property; or to protect the safety of any person.
- In connection with a corporate transaction, such as a merger, acquisition, financing, reorganisation, or sale of assets, in which case personal data may transfer as part of the transaction, subject to confidentiality and protection obligations at least equivalent to those in this Policy. We will notify you before your data becomes subject to a materially different privacy policy.
- With your consent, for any other purpose disclosed to you at the time.
Handling of government and law enforcement requests. Before disclosing anything, we review the legality and validity of each request, we challenge requests we consider unlawful or overbroad, we disclose only the minimum data necessary to respond to a valid request, and we maintain a record of each request and our response. Where we are legally permitted to do so, we will notify the affected User.
11. Data Retention
We apply a minimum retention approach. We retain personal data only for as long as necessary for the purposes set out in this Policy, and no longer, unless a longer period is required by law. We do not retain personal data indefinitely.
| Data Category | Retention Period |
|---|---|
| Raw message and comment content as received from Meta | 30 days, then the content is stripped from the record |
| Message and comment event records, without content | 90 days on a rolling basis, then automatically purged |
| Automation run records, including the message or comment that triggered the run | 90 days on a rolling basis, then automatically purged |
| Contact and subscriber records | For the duration of your active account |
| Automation configurations and flow data | For the duration of your active account |
| Account and profile data | For the duration of your account, plus up to 30 days after you delete it |
| Data after a subscription ends | Retained for as long as your account exists. Your live automations move to Draft and stop running, but nothing is deleted, so renewing restores your setup |
| Internal audit trail of actions taken in your account | 365 days |
| Billing, invoice, and GST records | 7 years, as required under Indian tax and accounting law |
| Server, access, and security logs | 90 days |
| Marketing contact data | Until you unsubscribe or withdraw consent |
| Support correspondence | 24 months |
Platform Data obtained from Meta is subject to a shorter rule that overrides the table above. Message and comment content is purged on a 90 day rolling basis while your account is active, and the readable content is in fact stripped after 30 days. All Platform Data associated with a connection is deleted within 30 days of you disconnecting that account, deleting your Criyo AI account, or submitting a deletion request, whichever occurs first. See Sections 7 and 12.
Two things are kept for longer, and only because deleting them would work against you or against Meta. The first is aggregate daily counters, such as how many automations ran or how many leads were captured. These hold numbers only, with no identifiers and no message content, and they are what your reports are drawn from. The second is the Instagram account identifier on a disconnected account, which is the minimum we need to recognise a reconnection and to honour a deletion request that arrives later referring to that account. Every other field on a disconnected account is erased.
An access token is never held for a grace period. It is deleted the moment you disconnect an account or remove Criyo AI from your Instagram settings.
When personal data is no longer required, we securely delete or irreversibly anonymise it. Backups are purged on their own cycle, which may extend deletion by up to 30 days beyond the periods stated above.
12. Data Deletion and How to Request It
You may delete your data at any time through any of the following routes.
- Disconnect a social account. Open Settings, then Connected Accounts, and disconnect the account. All Platform Data associated with that connection is deleted within 30 days.
- Delete your Criyo AI account. Open Settings, then Account, then Delete Account. Your account stops working immediately: you can no longer sign in and your automations stop running. Your data is then permanently erased within 30 days, which includes your connected account data, contacts, automations, and every event record we hold. Billing records are retained only for the period required by law. If you sign up again with the same email address inside that window, the pending erasure is completed first and you are given a new, empty account.
- Revoke access from Instagram directly. In your Instagram settings, open Apps and Websites, then Active, and remove Criyo AI. This immediately revokes our access. Any Platform Data we hold is deleted within 30 days.
- Email us. Send a request from your registered email address to support@criyo.ai with the subject line "Data Deletion Request". We will verify your identity and confirm completion within 30 days.
- Request deletion through Instagram. If you ask Meta to delete your data, Meta notifies us directly. We record the request, return a confirmation code, and give you a link where you can check its status at any time until it is complete.
Full step by step instructions are available on our Data Deletion Instructions page.
We may retain certain data after a deletion request where required to comply with a legal or regulatory obligation, to resolve a dispute, to prevent fraud or abuse, or to enforce our agreements. Where we do so, we retain only the minimum necessary and only for as long as necessary.
13. Security
We implement reasonable technical and organisational measures designed to protect personal data against unauthorised access, disclosure, alteration, and destruction. These include:
- Encryption in transit using TLS, and encryption at rest for stored data
- Role based access controls and the principle of least privilege
- Access tokens stored in encrypted form, never in plaintext
- Network isolation, firewalls, and security group restrictions on our AWS infrastructure
- Regular backups with restricted access
- Logging and monitoring of administrative and privileged access
- Periodic review of our security practices and dependencies
No method of transmission over the internet and no method of electronic storage is completely secure, and we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of your account credentials and for signing out of shared devices.
Breach notification. In the event of a personal data breach, we will notify the Data Protection Board of India and affected Data Principals as required under the DPDP Act. Where the GDPR applies, we will notify the relevant supervisory authority within 72 hours and affected individuals where the breach is likely to result in a high risk to their rights and freedoms, in accordance with Articles 33 and 34.
14. International Data Transfers
Criyo AI is established in India. Personal data is processed and stored in India on Amazon Web Services infrastructure in the Asia Pacific (Mumbai) ap-south-1 region.
Some of our service providers are located outside India, including in the United States. Where personal data is transferred to a jurisdiction that does not provide an equivalent level of protection, we rely on appropriate safeguards, including contractual data protection terms and, where the GDPR applies, the European Commission's Standard Contractual Clauses under Articles 45 and 46, or the recipient's adherence to a recognised adequacy framework.
You may request further information about the safeguards we rely on by emailing support@criyo.ai.
15. Your Rights
15.1 Rights Under the DPDP Act, 2023
As a Data Principal, you have the right to:
- Access. Obtain a summary of the personal data we process about you, the processing activities undertaken, and the identities of any other Data Fiduciaries with whom it has been shared.
- Correction and erasure. Have inaccurate or misleading data corrected, incomplete data completed, and data erased where it is no longer needed for the purpose for which it was collected.
- Grievance redressal. Raise a grievance with us in the first instance, as set out in Section 19.
- Nomination. Nominate another individual to exercise your rights in the event of your death or incapacity.
- Withdrawal of consent. Withdraw your consent at any time, with the same ease with which it was given.
15.2 Rights Under the GDPR and UK GDPR
If you are located in the EEA, the United Kingdom, or Switzerland, you additionally have the right to:
- Access, Art. 15. Obtain confirmation of processing and a copy of your data.
- Rectification, Art. 16. Have inaccurate or incomplete data corrected.
- Erasure, Art. 17. Have your data deleted where the conditions apply.
- Restriction, Art. 18. Limit how we process your data in certain circumstances.
- Data portability, Art. 20. Receive your data in a structured, commonly used, machine readable format.
- Objection, Art. 21. Object to processing based on legitimate interests, including direct marketing.
- Withdrawal of consent, Art. 7(3). Withdraw consent at any time, without affecting prior lawful processing.
- Not to be subject to automated decision making, Art. 22, producing legal or similarly significant effects.
- Complaint, Art. 77. Lodge a complaint with your local supervisory authority.
15.3 Exercising Your Rights
Email support@criyo.ai from your registered address. We will verify your identity before acting on any request, in order to protect your data from unauthorised disclosure. We respond within 30 days under the DPDP Act, and within one month under the GDPR. Under the GDPR this period may be extended by a further two months where the request is complex, in which case we will tell you within the first month.
If your request concerns data held by one of our Users, for example if you are a follower whose messages were processed through a brand's Criyo AI account, please contact that brand directly, as they are the Data Fiduciary for that data. If you contact us instead, we will forward your request to the relevant User and assist them in responding.
16. Automated Processing
The Services execute automated actions such as sending replies, tagging contacts, routing conversations, and applying keyword triggers, based on rules that Users configure themselves. These are rule based workflows that operate on your instructions.
We do not make automated decisions that produce legal effects concerning you or that similarly significantly affect you.
17. Children's Privacy
The Services are intended for business use and are not directed at children. We do not knowingly collect personal data from any individual under the age of 18.
Under the DPDP Act, processing the personal data of a child requires verifiable consent from a parent or lawful guardian. We do not undertake tracking, behavioural monitoring, or targeted advertising directed at children. Where the GDPR applies, our Services are not directed to children under 16.
If you believe a child has provided us with personal data, contact support@criyo.ai and we will take steps to delete it.
18. Links to Third Party Sites
The Services may contain links to websites, platforms, and services that we do not operate or control. This Policy does not govern those. We encourage you to review the privacy policy of any third party before providing them with personal data. Providing a link does not imply endorsement.
19. Grievance Redressal
In accordance with the DPDP Act, 2023 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, we have appointed a Grievance Officer to address complaints regarding this Policy or our data practices.
Charin Paresh Shah
Criyo AI
Narayan Dabholkar Road, Mumbai, Maharashtra 400006, India
Email: support@criyo.ai
Please include your registered email address, a clear description of the grievance, and any supporting information. We acknowledge grievances within 24 hours and resolve them within 30 days.
If you are not satisfied with our resolution, you may escalate your complaint to the Data Protection Board of India as constituted under the DPDP Act. If the GDPR applies to you, you may lodge a complaint with your local supervisory authority.
20. Changes to This Policy
We may update this Policy to reflect changes in our practices, technology, legal requirements, or business operations. When we make material changes, we will update the Effective Date at the top of this Policy and notify you through the Website, by email, or through an in product notice, as appropriate.
Where a change materially expands how we use personal data collected under a prior version, we will obtain fresh consent where the law requires it. Your continued use of the Services after an update constitutes acknowledgement of the revised Policy.
21. Contact Us
Operated by Charin Paresh Shah (Sole Proprietorship)
Narayan Dabholkar Road, Mumbai, Maharashtra 400006, India
GSTIN: 27LANPS7535L1ZK (trade name CRIYO AI)
Email: support@criyo.ai
Website: criyo.ai
This Privacy Policy was last updated on 25 August 2026.
