Your passwords stay yours, the network itself grants access.
GO & REPLY never asks for your social network password and never sees one time codes: you sign in on the network's own screen and it hands us a scoped access token. That token is stored encrypted, never shown in the interface and revoked with one button. Card details are handled by the payment provider and never reach our servers.
What we never receive and what we always do
Two sides of one rule: the product takes exactly the access it needs to answer, and not a drop more.
- Your social network password. The login form belongs to the network, we never see it and cannot store it.
- One time codes and two factor confirmations. They go to you and stay with you.
- Card number and security code. The payment provider processes the payment and only reports the subscription status to us.
- Anything you did not grant. The token is limited to a set of permissions: no rights to advertising, in network payments or account settings.
- Access is granted by the network on its own consent screen, not by us with your password.
- The token and the data are stored encrypted, and every connection runs over a secure channel.
- Disconnecting a network deletes its token at once and stops all reading and answering.
- Every automated action is written to the log: time, text, source and the rule it passed under.
How access is granted in each network
The mechanism differs per network, so here is exactly what happens and which permissions are requested.
- Instagram: A Meta consent screen for a professional account. Messages, comments, mentions, publishing
- Facebook: A Meta consent screen for a page, your personal profile is untouched. Page inbox, comments, reviews, publishing
- Telegram: A session of your own account over the MTProto protocol, confirmed by the code from the app. Private chats, groups, channel comments
- WhatsApp Business: A number registered in the WhatsApp Business Platform. Conversations inside the 24 hour window and approved templates after it
- TikTok: A login on the TikTok Login page. Comments, messages, video publishing
- YouTube: A Google consent screen for the chosen channel. Comments under videos, Shorts and live streams, statistics
- Threads: A Meta consent screen for the account linked to Instagram. Replies, mentions, publishing up to 500 characters
- X: An app authorisation in X, the access level depends on the X API tier. Mentions, replies, quotes, publishing; private messages on a paid tier
What happens to a message
The text of a message does pass through the product, otherwise it could not be answered. Here is the whole path and its boundaries.
- 1. It arrives through the network API: Only the streams you granted permission for, and only over a secure connection.
- 2. It lands in your workspace: Workspaces are isolated: another account or another agency client never sees your conversations.
- 3. It is processed to produce a reply: A model detects the intent, the buyer score and a draft reply. The model provider processes the text under contract and does not use it to train shared models.
- 4. It is kept as customer history: So that next time the operator and the autopilot see the context. Storage is encrypted, and the retention rules are described in the privacy policy.
- 5. It is deleted when you ask: A deletion request removes conversations, comments, drafts and generated creatives of the chosen workspace, and deleting the account removes everything at once.
- Connections only over a secure channel, plain HTTP is refused
- Social network tokens are encrypted and never shown in the interface
- Your GO & REPLY password is stored only as a hash and cannot be recovered
- Conversations are never sold or handed to third parties for advertising
Who inside can see it
Access belongs to people, not to the product: it is defined by workspace and role.
- Workspace isolation: A brand or an agency client is a separate workspace with its own accounts, team and limits. Data never crosses between workspaces.
- Roles and permissions: An operator replies, a manager sees reports and settings, a client sees only their own brand. Inviting and revoking access is a single action.
- Action log: You can see who sent what, by hand or by autopilot, with the exact text and time. The log cannot be rewritten from the interface.
- Our support team: Our staff do not read your conversations as part of normal work. If a support case needs access, we ask for permission, and the access itself stays in the log.
We play by the platform rules
Your account has to survive, so the product does not do the things networks ban accounts for.
- Official network APIs only, no page scraping and no bypassing of limits
- No bulk messages to people who did not write first: networks treat that as spam
- Rate discipline: the autopilot keeps pauses and daily caps so it does not look like a robot
- The data handling requirements of Meta, Google, TikTok and X are met to the extent they prescribe for developers
Questions and answers
- Can my account be blocked for automation?
- Accounts get blocked for breaking the rules: bulk messages to people who did not write, bypassing limits, scraping pages. The product does none of that: it works through official APIs, keeps pauses and daily caps and answers only people who wrote to you.
- What happens if I disconnect an account?
- The token is deleted at once and reading and answering stop the same second. The conversation history can stay for reports or be removed with a separate request. Access can also be revoked from the network's own settings, which stops the work just as instantly.
- Will my conversations go into AI training?
- No. The text is used to answer in that same conversation and to tune your brand voice inside your own workspace. It does not enter shared training sets and is not used for other accounts.
- Do you see my personal chats in Telegram?
- The inbox receives chats of the account you connected, because MTProto acts on your behalf. That is exactly why a work account is the right one to connect rather than a personal one, and chats you do not need can be hidden from the queue. The session is visible in Telegram settings and can be closed there.
- How do I check what exactly the autopilot sent?
- In the log every action opens in full: time, the exact text, the network and the source of the message, the moderation mode and the rule or limit it passed under. Reports additionally show the share of accepted and edited drafts.