Last updated August 7, 2026

Privacy Policy

This Privacy Policy explains how Ongevia (“we”, “us”, “our”) handles information when you use https://ongevia.com and related services that automate Instagram comment-to-DM workflows through Meta’s official APIs.

1. Who we are

Ongevia is operated by Nathaniel Mwaipopo. Contact for privacy requests: nathanielmwaipopo@gmail.com. Website: https://ongevia.com.

2. Data we collect

Depending on how you use Ongevia, we may collect:

  • Account data: phone number (for OTP login), optional name, admin email for platform operators, session identifiers.
  • Workspace data: workspace name, members, invitations, campaign settings (keywords, messages, links, post IDs).
  • Instagram / Meta data: Instagram professional account IDs and usernames, encrypted access tokens, webhook payloads (for example comments and messaging events needed to run campaigns), and delivery / status logs.
  • Payment data: mobile-money phone numbers, order IDs, amounts, payment status, and wallet credit balances. We do not store full card numbers.
  • Technical / security data: IP addresses (where logged for security or click tracking), timestamps, error diagnostics, and action audit logs.

3. How we use data

  • Authenticate users (phone OTP via SMS) and protect accounts.
  • Connect Instagram professional accounts and send private replies / public comment replies through Meta’s official APIs.
  • Match keywords, queue and rate-limit delivery, prevent duplicates, and show campaign analytics and logs.
  • Process wallet top-ups and credit usage for messaging features.
  • Operate, secure, debug, and improve the service; comply with law and Meta Platform Terms.

4. Instagram and Meta

Ongevia does not ask for Instagram passwords, does not scrape Instagram, and does not use browser automation. Access is granted via Meta Instagram Login / Business Login. Tokens are encrypted at rest and used only for actions you authorize (for example reading comments and sending private replies). You can disconnect Instagram at any time in Settings.

5. Legal bases (where applicable)

We process data to perform our contract with you, based on your consent (for example connecting Instagram), for legitimate interests such as security and fraud prevention, and where required by law.

6. Sharing and subprocessors

We share data only as needed to run Ongevia, including:

  • Meta / Instagram — to authenticate and send API requests you authorize.
  • SMS provider (Beem Africa) — to deliver login OTP codes.
  • Payment provider — to process mobile-money top-ups.
  • Hosting infrastructure — servers, PostgreSQL, and Redis used to run the application.

We do not sell personal data. We may disclose information if required by law or to protect rights, safety, and the integrity of the service.

7. Retention

We retain account, campaign, log, and payment records for as long as your account is active and as needed for security, billing disputes, and legal obligations. You may request deletion as described on our Data Deletion page.

8. Security

We use industry-standard measures including encrypted Instagram tokens at rest, HTTPS in transit, access controls, and operational logging. No method of transmission or storage is 100% secure.

9. Your rights

Depending on your location, you may have rights to access, correct, export, or delete personal data, or to withdraw consent where processing is consent-based. Contact nathanielmwaipopo@gmail.com to exercise these rights.

10. Children

Ongevia is intended for businesses and adults. We do not knowingly collect personal data from children under 13 (or the applicable age in your jurisdiction).

11. Changes

We may update this policy from time to time. The “Last updated” date at the top will change when we do. Continued use of Ongevia after updates means you accept the revised policy.

12. Contact

Privacy questions and requests: nathanielmwaipopo@gmail.com.