Privacy Policy

Privacy Policy

Last updated: [LAST_UPDATED_DATE]

Who we are

XO Engine is a product operated by [COMPANY_LEGAL_NAME], registered in [COMPANY_JURISDICTION]. This policy explains what information we collect when you use XO Engine (“the Service”), why we collect it, and how you can control or delete it.

What data we collect

When you create an XO Engine account, we collect:

  • Your email address and a hashed password, for account login.
  • With your explicit authorization through Instagram's official login screen: your Instagram profile information, media, comments, insights, and messaging data as described in detail on our Instagram Integration page.
  • Automation configurations you create (trigger keywords, reply text, scheduling settings).
  • Basic technical data (IP address, browser type) for security and abuse prevention.

Why we collect it

  • To operate the automation, scheduling and analytics features you configure.
  • To display your Instagram performance data inside your dashboard.
  • To keep your account secure and prevent abuse.
  • To respond to support requests.

We do not use your Instagram data for advertising, and we do not sell it.

How your data is used

Your Instagram data is used only to power the features you actively configure — for example, a comment automation only reads comments on the posts you select, and a scheduled post is only published when you schedule it. Automations you create are not shared with or visible to other XO Engine customers.

Third-party services

We share data with the following categories of third parties, and only as needed to operate the Service:

  • Meta / Instagram — all Instagram data flows through Meta's official Graph API under the permissions described on our Instagram Integration page.
  • Hosting & infrastructure — [HOSTING_PROVIDER], to store account and application data.
  • Anthropic (Claude) — only if you explicitly connect the optional Claude / MCP integration in Settings. When connected, Claude can read your account analytics and draft automation suggestions on your behalf; publishing an automation always requires your manual confirmation inside the dashboard. This integration is off by default.

We never sell your personal data or your Instagram data to any third party.

Instagram data

Meta / Instagram data specifically

Data we receive from Instagram's Graph API (profile information, media, comments, messages, insights) is used exclusively to provide the automation, scheduling and analytics features described on this site, and is handled in accordance with Meta's Platform Terms and Developer Policies.

Data storage

Your data is stored on servers located in [DATA_STORAGE_REGION] and encrypted at rest and in transit.

Data retention

We retain your account and Instagram data for as long as your account is active. If you request deletion or disconnect your Instagram account, we delete the associated data within [RETENTION_WINDOW], as described on our Data Deletion page.

Your rights

You can request a copy of your data, or request deletion of your account and all associated data, at any time by contacting [SUPPORT_EMAIL]. See our Data Deletion Instructions for the full process.

Changes to this policy

We may update this policy from time to time. Material changes will be announced on this page with an updated “Last updated” date.

Contact

Questions about this policy can be sent to [SUPPORT_EMAIL].