Security & Privacy

Your account stays yours.

XO Engine uses Meta's official authentication flow, requests access based on enabled features and keeps your workflows visible to you.

Access

How XO Engine connects to Instagram

Connection happens through the official login flow. XO Engine works with an access grant scoped to enabled features, not with your credentials.

Official Meta login, never your password

Authentication happens through the supported platform login flow.

Only the permissions each feature needs

Features should request only the access required for their function.

You can revoke access

Disconnect the integration from XO Engine or through the relevant platform controls.

No scraping or browser automation

Supported Instagram functionality should run through official APIs.

See each permission and why it's needed

Data

What we store, and what we don't.

Instagram data is used only to provide the features described on this site. The full detail is in the Privacy Policy.

We store

  • Your XO Engine login: email address and a hashed password.
  • Account connection identifiers for the Instagram professional account you connect.
  • Profile and media information required by the features you enable.
  • Workflow configuration: triggers, reply text, scheduling settings.
  • Comments and messages handled by the workflows you run.
  • Analytics and insights data required by enabled features.

We don't store

  • Your Instagram password.
  • Data from accounts you have not connected.
  • Data not required by the features you enabled.
Read the Privacy Policy

Workflow safeguards

Automation with guardrails.

Product controls that help keep workflows measured, visible and within the settings you chose.

Spam-risk checks

Workflows are checked before they go live. Broad triggers, very short keywords and very long messages are flagged so you can adjust them first.

Randomized delays

A configurable minimum and maximum delay before the first action, so responses are not sent at identical intervals.

Messaging-window awareness

Follow-up messages are only sent inside the platform's supported messaging window.

Blocked word / URL checks

Message text is checked against your account's blocked-word list, and raw URLs are rejected in favor of tracked buttons.

Clear workflow status

Each workflow shows whether it is a draft, active or paused, and failed runs are listed so nothing happens silently.

These safeguards are product controls and do not guarantee that every workflow will remain permitted under future platform policy changes.

Optional integrations

Off by default. On only when you choose.

Optional AI connector

XO Engine offers an optional AI connector that is off by default. It runs only after you intentionally enable it in Settings, and anything it drafts still requires your manual confirmation before it is published. Disabling it stops the connection.

Deleting your data

You can request deletion of your XO Engine account and the associated Instagram data at any time. The Data Deletion page explains how to send the request and what happens next.

Data Deletion

Want to understand exactly how Instagram access works?

Each permission group, the feature it powers and how to disconnect are documented in plain language.