Privacy Policy

Last updated: March 30, 2026

1. Introduction

Welcome to Reelactive ("we", "our", "us"). Reelactive is a SaaS platform operated at reelactive.ai that generates Instagram carousel posts and auto-publishes them on behalf of users. We are committed to protecting your personal data and respecting your privacy in accordance with the General Data Protection Regulation (GDPR) and other applicable data protection laws. This Privacy Policy explains how we collect, use, store, and share your information when you use our services.

2. Data We Collect

We collect and process the following categories of personal data:

Account Information

Your name and email address, provided during account registration.

Business Profile Information

Business name, business description, and target audience details that you provide to help us generate relevant carousel content.

Instagram OAuth Tokens

When you connect your Instagram account, we receive and store OAuth access tokens from Instagram (via Meta). These tokens allow us to publish carousel posts to your Instagram account on your behalf. We do not receive or store your Instagram password.

Uploaded Images

Images you upload to be used in your carousel posts.

Payment Information

Payment processing is handled by Stripe. We do not store your credit card numbers or full payment details on our servers. We receive and store only a Stripe customer ID, subscription status, and transaction metadata needed to manage your subscription.

Usage Data

We may collect information about how you interact with our service, including pages visited, features used, timestamps, and device/browser information.

3. How We Use Your Data

We use the data we collect for the following purposes:

  • To create and manage your account.
  • To generate AI-powered Instagram carousel content tailored to your business profile.
  • To publish carousel posts to your Instagram account using your authorized OAuth tokens.
  • To process payments and manage subscriptions through Stripe.
  • To communicate with you about your account, service updates, and support requests.
  • To improve our services, diagnose technical issues, and perform analytics.
  • To comply with legal obligations.

4. Instagram Data Usage and OAuth Tokens

Reelactive integrates with the Instagram Graph API (via Meta) to publish content on your behalf. Here is how we handle your Instagram data:

  • We request only the permissions necessary to publish carousel posts to your Instagram account.
  • OAuth tokens are stored securely and encrypted at rest. We never share your tokens with third parties.
  • We periodically refresh tokens as required by Meta's API to maintain authorized access.
  • You may revoke access at any time by disconnecting your Instagram account from Reelactive or revoking access through your Instagram/Meta account settings. Upon revocation, we will delete your stored OAuth tokens.
  • We do not read, store, or analyze your Instagram direct messages, followers list, or any data beyond what is needed to publish your content.

5. Legal Basis for Processing (GDPR)

For users in the European Union, we process your personal data on the following legal bases:

  • Contract: Processing necessary to perform our contract with you (providing the Reelactive service).
  • Consent: Where you have given explicit consent, such as connecting your Instagram account via OAuth.
  • Legitimate interest: To improve our services, ensure security, and perform analytics, where these interests are not overridden by your rights.
  • Legal obligation: Where we are required to process data to comply with applicable law.

6. Data Sharing and Third Parties

We do not sell your personal data. We share data only with the following third parties, as necessary to provide our services:

  • Meta / Instagram: To publish content to your Instagram account using their API.
  • Stripe: To process payments and manage subscriptions. Stripe's privacy policy governs their handling of your payment data.
  • Cloud infrastructure providers: To host and store data securely.

7. Data Retention

We retain your data as follows:

  • Account data: Retained for as long as your account is active. Upon account deletion, we will erase your personal data within 30 days, except where retention is required by law.
  • Instagram OAuth tokens: Retained while your Instagram account is connected. Deleted promptly upon disconnection or account deletion.
  • Uploaded images: Retained while your account is active. Deleted within 30 days of account deletion.
  • Payment records: Retained as required for tax and legal compliance (typically up to 7 years).
  • Usage data: Retained in aggregated or anonymized form for analytics purposes.

8. Your Rights (GDPR)

If you are located in the European Economic Area (EEA), you have the following rights under GDPR:

  • Right of access: Request a copy of the personal data we hold about you.
  • Right to rectification: Request correction of inaccurate or incomplete data.
  • Right to erasure: Request deletion of your personal data ("right to be forgotten").
  • Right to restrict processing: Request that we limit how we use your data.
  • Right to data portability: Receive your data in a structured, machine-readable format.
  • Right to object: Object to our processing of your data based on legitimate interest.
  • Right to withdraw consent: Withdraw consent at any time where processing is based on consent (e.g., Instagram OAuth connection).

To exercise any of these rights, please contact us at support@reelactive.ai. We will respond to your request within 30 days.

9. Data Security

We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. This includes encryption of sensitive data at rest and in transit, secure storage of OAuth tokens, regular security reviews, and access controls limiting data access to authorized personnel only. However, no method of transmission over the internet or electronic storage is 100% secure, and we cannot guarantee absolute security.

10. Cookies

We use essential cookies required for the operation of our service, such as session cookies to keep you logged in. We may also use analytics cookies to understand how our service is used. You can manage your cookie preferences through your browser settings.

11. Children's Privacy

Reelactive is not intended for use by individuals under the age of 16. We do not knowingly collect personal data from children under 16. If we become aware that we have collected data from a child under 16, we will take steps to delete that data promptly.

12. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. We encourage you to review this policy periodically. If we make material changes, we will notify you via email or through a notice on our website.

13. Contact Us

If you have any questions about this Privacy Policy, your personal data, or wish to exercise your rights, please contact us:

Company: Reelactive

Website: reelactive.ai

Email: support@reelactive.ai