1. Who controls your data

Convert Run runs on infrastructure operated by the organisation that deployed it. That operator is the data controller. The software authors do not receive, host, or have access to any data processed by your installation.

2. What we collect and why

Account information

Your email address and a password hash, used solely to authenticate you. Passwords are never stored in readable form.

Provider API keys

Keys you enter for language, image, video, voice and stock media providers. They are stored encrypted at rest and are used only to make the requests you trigger. They are never transmitted anywhere except to the provider they belong to.

Content you create

Scripts, project settings, generated media files, rendered videos, thumbnails and publishing copy. These live on the deployment's own storage under your account and are visible only to you.

Connected social accounts

When you connect an Instagram professional account or a YouTube channel, we store the access and refresh tokens (encrypted), the account or channel identifier, the display name, and the permission scopes you granted. Tokens are used only to perform the actions you configured.

Instagram platform data

If you enable comment automation, the integration receives and processes:

  • Comments on your own posts — the comment text, its identifier, and the commenter's username and scoped identifier. Needed to match your keyword rules and to send the one private reply the platform permits per comment.
  • Direct messages sent to your account — the message text and identifier. Needed to decide whether a rule applies and whether the 24-hour reply window is open. Message contents are not stored. Only the timestamp and identifier of the most recent message are kept, and only to compute that window.
  • Follow status — whether the person messaging you follows your account, read from the platform's profile endpoint only after they message you. Needed for rules that require a follow before sending a file. Cached for six hours to avoid repeated calls.

This data is used only to run the automations you configured on your own account. It is never used to build advertising profiles, never sold, and never shared with any third party.

3. What we do not collect

  • We do not read direct messages sent to other accounts.
  • We do not collect your followers list or anyone's contact details.
  • We do not track you across other websites.
  • We do not use cookies for advertising or analytics — only the session cookie required to keep you signed in.
  • We do not store the body of conversations, only what the reply window requires.

4. Third parties

Convert Run sends data to a provider only when you have configured that provider and triggered an action that needs it:

  • Language model providers receive your script or the text of an incoming comment in order to generate a script, caption or reply.
  • Image, video and voice providers receive prompts and, where you enabled it, reference images.
  • Stock media providers receive search keywords.
  • Meta and Google receive the content you choose to publish and the messages your rules send.

Each provider processes that data under its own terms. Removing a key stops all traffic to that provider immediately.

5. How long data is kept

  • Account and content: until you delete the project or your account.
  • Provider keys and platform tokens: until you remove them or disconnect the account.
  • Webhook events: retained only as long as needed to process them and to prevent duplicate replies.
  • Generated media: subject to the retention window configured by the operator of your deployment.

6. Deleting your data

You can disconnect any social account from the settings screen at any time. Disconnecting immediately erases the stored tokens and stops all automation for that account.

To erase everything associated with a connected Meta account, follow the data deletion instructions. Removing the app from your Instagram or Facebook settings also triggers our deletion callback automatically.

7. Security

  • Provider keys and platform tokens are encrypted at rest.
  • Incoming platform callbacks are rejected unless their signature verifies against the app secret.
  • Media shared with platforms is exposed only through signed links that expire.
  • Each account's data is scoped to that account; no cross-account access exists in the application.

8. Your rights

Depending on where you live, you may have the right to access, correct, export or erase your data, and to object to processing. Because the software is self-hosted, exercise these rights with the operator of the deployment you use.

9. Children

Convert Run is a business tool and is not directed at children under 13. We do not knowingly collect their data.

10. Changes

Material changes to this policy will be reflected here with an updated date. Continued use after a change means you accept the revised policy.

11. Contact

For privacy questions or a data request, contact the operator of your deployment. If you reached this page through a Meta app review, the contact address is the one listed on the application record.

Beklenmedik bir hata oluştu. Sayfayı yenilemeyi deneyin. Yenile ×