Reply
Get started

Privacy policy

This document explains what Reply does with your data and with that of the people who leave reviews on your listing, under Regulation (EU) 2016/679.

Last updated : August 10, 2026 · The French version of this document prevails.

Controller

For your account data, the publisher identified in the legal notice acts as controller.

For your customers’ reviews and the replies published, you are the controller and we act as processor, on your instructions and on your behalf alone.

Data processed

  • Account: email address, display name, language, creation date, passkeys (credential id and public key, never a password).
  • Sessions: hash of the session token, hash of the IP address, user agent. The IP address is never stored in clear.
  • Google connection: account id, associated email address, encrypted refresh token (AES-256-GCM).
  • Businesses: name, sector, address, time zone, publication settings, reply tone, menu and news you enter, staff first names you provide.
  • Reviews: rating, text, author name and photo as published by Google, date, detected language, extracted themes.
  • Replies: proposed text, published text, status, timestamps, model used and token volumes.
  • Telegram: chat id, username and first name, if you link a conversation.
  • Billing: Stripe identifiers, plan, status and renewal date. No card details.
  • Audit log: actions that change what is public or who has access to what.

Purposes and legal bases

  • Providing the service, generating and publishing replies: performance of the contract.
  • Invoicing and collection: performance of the contract and accounting obligations.
  • Securing accounts, limiting abuse, keeping an audit log: legitimate interest in protecting the service and its users.
  • Measuring site traffic with a self-hosted, cookie-free solution: legitimate interest in understanding use of the site.
  • Answering your requests: legitimate interest, or legal obligation depending on the request.

Traffic measurement

The site uses Matomo, hosted on our own infrastructure. Traffic data is shared with no third party and used for no advertising.

Measurement is configured so as not to require prior consent: no cross-site tracking, no resale, truncated IP addresses.

Automatic reply generation

Review text and the context you entered are sent to Anthropic to produce a proposed reply. That data is not used to train models.

Do not enter sensitive data in the context fields, nor information about people who would not expect to find themselves there. Staff first names you enter are used only to thank a member of staff named by a customer.

Recipients

We neither sell nor rent any data. The following providers act on our behalf under contract:

  • Anthropic (United States): reply generation. Receives review text and the context you entered. The data is not used to train models.
  • Stripe (Ireland, United States): payment and invoicing. Receives your email address and payment details. We never see your card number.
  • Google (Ireland, United States): reading your reviews and publishing your replies, through the Google Business Profile API and with your explicit authorisation.
  • Telegram (United Arab Emirates): delivery of reviews awaiting validation, if you enable that feature.
  • Hostinger International Ltd (Cyprus): hosting of the application and the database, in a European Union region.

Transfers outside the European Union

Some providers are established outside the European Union. Those transfers rely on the European Commission’s standard contractual clauses, supplemented by the technical measures described here, notably encryption of access tokens at rest.

Retention periods

  • Account and businesses: for the duration of the subscription, then erased when the account is deleted.
  • Reviews and replies: as long as the associated business exists. They are erased with it.
  • Sessions: thirty days at most, purged automatically on expiry.
  • Authentication challenges and link codes: a few minutes.
  • Audit log: three years, so an action can be accounted for after the fact.
  • Accounting records: ten years, as required by law.

Security

  • Passwordless authentication with a passkey bound to your device.
  • Google tokens encrypted at rest with AES-256-GCM.
  • Session tokens stored as hashes: a database leak yields no usable session.
  • Strict per-account scoping on every query and every action.
  • All communication encrypted with TLS.

Your rights

You have rights of access, rectification, erasure, restriction, objection and portability. Write to the contact address in the legal notice; we answer within thirty days.

Deleting your account erases all associated data, in cascade. This is immediate and irreversible.

You may lodge a complaint with the CNIL, 3 place de Fontenoy, 75007 Paris, or with your own country’s supervisory authority.

For people who left a review

If you posted a review on a Google listing managed with Reply, your review and the name Google displays are processed so that the business can respond. The controller is the business concerned, to whom any request should be addressed. You can also edit or delete your review directly from your Google account.

Changes

Any substantial change to this document is notified by email at least thirty days before it takes effect.