Privacy
Replyloop is a private, single-operator build. This policy describes how your data is handled.
What we store
- Your Google account email, name, and profile image (for login).
- OAuth refresh tokens for any mailboxes you choose to connect — AES-256-GCM encrypted at rest with a key that lives only on the host.
- Lead contact data you upload, the emails you send and receive through connected mailboxes, and metadata about those messages.
- Audit log entries describing what the AI did on your behalf.
What we never log
- Refresh tokens or access tokens.
- API keys you supply (OpenRouter, OpenAI, etc.).
- Raw IP addresses — tracking events store a SHA-256 hash only.
Who we share with
Nobody except the AI provider you have configured (OpenRouter, OpenAI, Anthropic, or Gemini). Each prompt you dispatch is subject to that provider's own data policy.
Deletion
Disconnect any mailbox at any time to revoke OAuth access. You can request complete data wipe by contacting the operator.
This is a plain-English summary — not a lawyered-up privacy policy. If this product opens to the public we'll replace it with a real one.