← Back

Privacy Policy

Last updated: 8 August 2026

ReplyFlow ("ReplyFlow", "we", "us") provides an AI-assisted review-management tool for local businesses. This policy explains what data we collect, how we use it, and the specific commitments we make about Google user data.

1. Information We Collect

  • Account information — name, email address, and a hashed password you provide at sign-up.
  • Payment information — processed and stored by Stripe. ReplyFlow never receives or stores full card numbers.
  • Google Business Profile data — after you explicitly grant access, we retrieve the business locations you own or manage, and the reviews on those locations (reviewer display name, star rating, review text, review timestamp, and existing reply, if any). We also store the OAuth refresh token needed to keep this connection working.
  • Yelp data — reviews retrieved from the Yelp Fusion API for businesses you connect.
  • Usage data — counts and timestamps of AI replies generated, used for billing limits and product improvement.

2. How We Use Your Information

We use your information only to operate and improve ReplyFlow. Specifically, to: display your reviews in your dashboard; generate AI reply suggestions; post replies to Google Business Profile at your direction; send transactional email (account confirmations, weekly review digests); process subscription payments; and provide customer support.

3. Google User Data — Limited Use Disclosure

ReplyFlow's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Concretely, this means:

  • We use Google user data only to provide and improve the user-facing features described in this policy.
  • We do not sell Google user data, and we do not transfer it to data brokers, information resellers, or any other party for sale.
  • We do not use Google user data for advertising, ad targeting, ad personalisation, or retargeting of any kind.
  • We do not use Google user data to train, fine-tune, or otherwise improve generalised machine-learning or AI models. Review text sent to our AI provider is used solely to produce a reply for that specific review, in real time.
  • We allow humans to read Google user data only when: you give us explicit permission (for example, in a support ticket you open); it is necessary for security purposes such as investigating abuse; it is required to comply with applicable law; or the data has been aggregated and de-identified.
  • We request the narrowest set of permissions our features require, and you can revoke access at any time.

4. Scopes We Request and Why

ReplyFlow requests a single Google OAuth scope:

  • https://www.googleapis.com/auth/business.manage — required to list the Google Business Profile locations you manage, read the reviews on those locations, and publish your reply to a review. Google does not offer a read-only or reply-only alternative for the Business Profile APIs, so this scope is the minimum that makes the product work.

5. AI Processing

When you request a reply suggestion, the review text and your business's tone settings are sent to Anthropic's Claude API to generate a draft. Anthropic processes this data as our service provider and does not use it to train its models. By default you review and approve every reply before it is published; if you enable automatic posting for a business, replies for it are published without that review step.

6. Data Storage, Retention, and Security

Data is stored in Supabase (PostgreSQL, hosted on AWS in the United States) with row-level security enabled so each account can only access its own records. Data is encrypted in transit (TLS) and at rest. OAuth refresh tokens are stored encrypted and are used only to call Google APIs on your behalf.

We retain your data for as long as your account is active. If you disconnect your Google account, we delete the stored Google OAuth tokens and associated Google review data within 30 days.

You can delete your account yourself at any time from the Account tab of the ReplyFlow iOS app. Deletion is immediate and permanent: it erases your login, your businesses, your synced reviews, your generated replies, and your stored OAuth tokens. Deleted accounts cannot be recovered. Residual copies may persist in encrypted infrastructure backups for up to 30 days before being overwritten.

7. Third-Party Services

ReplyFlow shares data with the following service providers strictly as needed to operate: Google Business Profile API (reading and replying to reviews), Yelp Fusion API (reading reviews), Supabase (database and authentication), Vercel (application hosting), Stripe (payments), Resend (transactional email), and Anthropic (AI reply generation). We do not share your data with any party for advertising or resale.

8. Your Rights and Choices

You may disconnect your Google or Yelp integration at any time from your ReplyFlow dashboard settings. You may also revoke ReplyFlow's access directly at myaccount.google.com/permissions.

You can delete your account and all associated data yourself from the Account tab of the iOS app — see section 6. You may also request access to, correction of, or deletion of your data by emailing hello@replyflow.dev. Residents of the EU, UK, and California have additional rights under GDPR, UK GDPR, and the CCPA/CPRA, including the right to access, rectify, port, and erase personal data, and the right to opt out of sale — noting that ReplyFlow does not sell personal data.

9. Cookies

We use first-party cookies solely to maintain your authenticated session. We do not use advertising, tracking, or third-party analytics cookies.

10. Children's Privacy

ReplyFlow is a business tool and is not directed to anyone under 16. We do not knowingly collect data from children.

11. Changes to This Policy

We may update this policy from time to time. Material changes will be announced by email to account holders, and the "Last updated" date above will change.

12. Contact

Questions about this policy or your data? Email hello@replyflow.dev.

ReplyFlow  ·  Terms of Service  ·  Support  ·  Contact