Privacy Policy

Last updated: July 27, 2026  ·  Contact: lukoai1337@gmail.com

1. What is ReplyFlow?

ReplyFlow is a software-as-a-service platform that allows businesses ("Customers") to embed an AI-powered chat widget on their websites. Visitors to those websites can interact with the widget to get answers, submit contact information, and request support. This Privacy Policy explains how ReplyFlow collects, uses, and protects data in connection with the ReplyFlow platform, dashboard, and chat widget.

2. Data We Collect

Account Data — When a Customer registers for ReplyFlow, we collect the company name, email address, and a securely hashed password. We do not store plain-text passwords.

Chat Data — When a visitor uses a ReplyFlow-powered widget, we store the messages exchanged, timestamps, session identifiers, and associated metadata. This data is stored under the Customer's account and is only accessible to that Customer's authorised staff.

Lead Data — If a visitor submits their contact information through the pre-chat form (name, email address, phone number, and/or a message), that information is stored as a lead record linked to the Customer's account.

Technical Data — Our hosting infrastructure (Railway) may log IP addresses and user-agent strings as part of standard server operations. We do not use these for tracking or profiling beyond operational purposes.

3. Payment Data

Subscription payments are processed by Stripe. ReplyFlow does not store credit card numbers or full payment details on its own servers. Please review Stripe's Privacy Policy for information on how payment data is handled.

4. AI Processing

Visitor messages may be sent to a third-party AI provider to generate responses. Messages are used solely to produce a reply in context; they are not used to train external AI models on your behalf. The AI provider processes data in accordance with their own privacy policies and data processing agreements.

5. Connected Accounts (Google, Microsoft, WhatsApp)

ReplyFlow Pro Customers may optionally connect a Google Workspace account, a Microsoft 365 account, and/or a WhatsApp Business number so that the AI Employee can spot messages that need a follow-up and prepare replies. Connecting an account is always initiated by the Customer, requires explicit consent on the provider's own screen, and can be revoked at any time.

What we request — We ask only for the narrowest permissions the features need:

What we store — Access tokens are held encrypted at rest by our integration backend and are never displayed in the dashboard, never included in any report, and never shared with third parties. Email message bodies are not stored. When a mailbox is scanned we keep only derived signals — the sender's name and address, the subject line, a short summary, and a classification such as "sales inquiry" — which is what the dashboard shows you. WhatsApp conversations are an exception: because the channel has no inbox of its own to refer back to, message content is stored so the Customer can read the conversation history in ReplyFlow.

Nothing is sent without approval. Every reply, message, and calendar booking the AI prepares is queued as a pending action for the Customer to review. It is sent only after the Customer explicitly approves and then confirms it. ReplyFlow never sends mail or messages on its own initiative.

Google user data — ReplyFlow's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Data obtained from Google APIs is used solely to provide the features described above, is not used for advertising, is not sold, and is not used to train generalised AI models.

Disconnecting — A Customer can disconnect any account at any time from Connected accounts in the ReplyFlow dashboard, which deletes the stored credential. Access can also be withdrawn directly at the provider: Google account permissions, Microsoft account permissions, or the Business Settings of the connected Meta business portfolio.

6. How We Use Data

We do not sell personal data to third parties. We do not use visitor chat data for advertising.

7. Data Retention

Customer account data is retained for as long as the account is active. Chat sessions, leads, and associated data are retained to provide the service and may be deleted at the Customer's request. Technical log data is retained for a limited period for security and debugging purposes.

8. Customer Responsibility

Businesses that use the ReplyFlow widget on their own websites are responsible for informing their own visitors about data collection in accordance with applicable laws. ReplyFlow provides the technical platform; each Customer is the data controller for the personal data their widget collects from their visitors.

9. Data Deletion & Contact

To request deletion of your account data or the data collected through your widget, please email us at lukoai1337@gmail.com. We will process reasonable requests within a reasonable timeframe.

Data from a connected Google, Microsoft, or WhatsApp account can be removed without waiting for us: disconnecting the account in the ReplyFlow dashboard deletes the stored credential immediately, and any WhatsApp conversation history held for that account is deleted on request to the address above.

10. Security

We use industry-standard measures including password hashing (bcrypt), HTTPS, and access controls to protect stored data. No system is perfectly secure; we encourage Customers to use strong, unique passwords and to keep their login credentials confidential.

11. Changes to This Policy

We may update this policy from time to time. Continued use of the service after changes are posted constitutes acceptance of the updated policy. Material changes will be communicated via email to registered accounts.


Questions about this policy? Email lukoai1337@gmail.com.
See also: Terms of Service · Cookie Policy