Privacy Policy
This document describes the behaviour of the software as built.
This policy has not been reviewed by a lawyer. Have qualified counsel review it before you launch.
What we collect
Account information: your name, email address and a bcrypt hash of your password. We never store your password itself.
Business information: everything you enter into your knowledge base — services, prices, policies, FAQs and instructions. This is used solely to generate replies for your workspace.
Email content: when you connect a mailbox, we read incoming messages so the assistant can answer them, and store the message text, sender and subject so the conversation stays coherent and so you can review what happened.
Billing information: handled entirely by Stripe. We store only a Stripe customer identifier and subscription status — never card numbers.
Google account access
We use Google's official OAuth flow. You authenticate at Google, not with us, and we never see or store your Google password.
We request the minimum scopes the product needs: read messages, send mail as you, and modify labels so a message is not handled twice. We do not request permission to delete anything, and we do not request Drive, Calendar or Contacts access.
Access and refresh tokens are encrypted with AES-256-GCM before being written to our database. You can revoke access at any time from your dashboard or from your Google account security settings.
Repliable AI's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
How your data is separated from other customers
Every record belongs to a workspace, and every database query is scoped to the workspace of the authenticated user. Your business information is never included in another customer's assistant, and their information is never included in yours.
A mailbox can be connected to exactly one workspace at a time.
AI processing
To generate a reply, we send your business knowledge and the relevant part of the conversation to an AI provider. We send only the current thread, bounded to recent messages — never your whole mailbox.
We do not use your data to train models.
What we log
We record account and system events — sign-ins, subscription changes, mailbox connections, messages processed and errors — so you can audit what happened and so we can support you.
Logs are automatically scrubbed of credentials. OAuth tokens, passwords, API keys and session tokens are never written to logs or to the activity trail.
IP addresses associated with sessions are stored as a one-way hash, not in the clear.
Retention and deletion
Your data is kept for as long as your account is active. Deleting your workspace removes its business information, email records and activity through database cascade rules.
Disconnecting Gmail deletes the stored credentials for that mailbox immediately and attempts to revoke the grant at Google.
Contact
For any privacy question or a data request, email repliableai@gmail.com.