Privacy Policy
Last updated 2026-08-15
What this service does
Social Relay connects your Instagram and Facebook accounts to a Telegram forum group. Each conversation on the connected platform becomes its own Telegram topic, and a reply posted in that topic is sent back out as a direct message over the platform the conversation started on.
This policy describes what information Social Relay collects and how it is used to provide that relay. It applies to the hosted version of the service. If you are using a self-hosted deployment, see the "Self-hosted deployments" section below.
Information collected
To create and operate your account, we collect the email address and credentials you sign up with. When you connect a social account, we store the platform account identifiers needed to route messages, such as the Instagram or Facebook page and user identifiers involved in a conversation.
To perform the relay itself, we process the content of the messages sent between your connected accounts and your Telegram group — message text, quoted-reply references, and supported attachments such as photos, video, audio, and documents — along with the Telegram group and topic identifiers used to route that content to the right topic.
We also store, for each conversation, the platform-issued identifier and, when the platform makes it available, the public username of the person messaging your connected account. Those individuals are not Social Relay account holders — they have not signed up and cannot access this service — but their identifier and username are necessary to route their messages to the correct Telegram topic and route replies back to them.
If billing is enabled for your account, Stripe processes and holds your payment details; we retain the billing and subscription identifiers Stripe issues, not your card number.
How message content is handled
Message content is relayed in both directions to deliver the service: inbound messages from Instagram or Facebook are posted into your Telegram topic, and replies you post in that topic are sent back out over the originating platform. This includes message text, quoted replies, and supported attachments.
Outbound attachments are staged temporarily on S3-compatible object storage under a private prefix, social-relay/outbound/, so that the sending platform can retrieve them. Those objects and their buckets are private, and access is granted only through short-lived signed links that are never stored in our database or written to logs.
We do not use the content of your conversations to train models, and we do not sell it.
Storage and security
Access tokens for your connected Instagram and Facebook accounts are encrypted at rest using AES-256-GCM before they are stored. They are decrypted only at the moment they are handed to the delivery worker process that sends or receives a message on your behalf, and are never returned to a browser or client application.
Account credentials are stored using the hashing built into our authentication system, not in plain text.
Third parties
Delivering the service necessarily involves sharing data with the platforms it connects: Meta (for Instagram and Facebook messaging), Telegram (for posting into your forum group), and, if billing is enabled, Stripe (for processing payments). Each of these third parties has its own privacy policy governing the data it processes on its own systems.
We also rely on infrastructure providers — such as our hosting and object-storage providers — to run the service. These providers process data only as needed to host and operate the application; they do not receive independent rights to use your conversation content.
We do not sell personal data, and we do not share message content with third parties except as described above, to deliver the service you have requested.
Retention and deletion
You can disconnect a connected Instagram or Facebook account from the Accounts page of your dashboard at any time; doing so stops further messages from being relayed for that account. To request deletion of your account and the data associated with it, contact the operator of this deployment through the channel that operator publishes for support requests, as described in the "Contact" section below.
Outbound media staged for delivery is held only long enough to complete delivery to the destination platform and is not kept indefinitely in the staging prefix.
Self-hosted deployments
Social Relay is also distributed as self-hostable, public-domain software. When an organization or individual runs their own deployment, that operator — not the authors of the software — controls the infrastructure, decides what data is collected, and is the data controller responsible for that deployment's compliance obligations.
If you are interacting with a self-hosted deployment, this policy describes the default behavior of the software; the operator of that specific deployment may supplement or modify it, and you should look to that operator for the policy that actually governs your data.
Contact
Questions about this policy, or requests to access, correct, or delete your data, should be directed to the operator of the deployment you are using, through whatever contact channel that operator publishes for support requests.