Official Meta login, never your password
Authentication happens through the supported platform login flow.
Security & Privacy
XO Engine uses Meta's official authentication flow, requests access based on enabled features and keeps your workflows visible to you.
Access
Connection happens through the official login flow. XO Engine works with an access grant scoped to enabled features, not with your credentials.
Authentication happens through the supported platform login flow.
Features should request only the access required for their function.
Disconnect the integration from XO Engine or through the relevant platform controls.
Supported Instagram functionality should run through official APIs.
Data
Instagram data is used only to provide the features described on this site. The full detail is in the Privacy Policy.
We store
We don't store
Workflow safeguards
Product controls that help keep workflows measured, visible and within the settings you chose.
Workflows are checked before they go live. Broad triggers, very short keywords and very long messages are flagged so you can adjust them first.
A configurable minimum and maximum delay before the first action, so responses are not sent at identical intervals.
Follow-up messages are only sent inside the platform's supported messaging window.
Message text is checked against your account's blocked-word list, and raw URLs are rejected in favor of tracked buttons.
Each workflow shows whether it is a draft, active or paused, and failed runs are listed so nothing happens silently.
These safeguards are product controls and do not guarantee that every workflow will remain permitted under future platform policy changes.
Optional integrations
XO Engine offers an optional AI connector that is off by default. It runs only after you intentionally enable it in Settings, and anything it drafts still requires your manual confirmation before it is published. Disabling it stops the connection.
You can request deletion of your XO Engine account and the associated Instagram data at any time. The Data Deletion page explains how to send the request and what happens next.
Data DeletionEach permission group, the feature it powers and how to disconnect are documented in plain language.