PreviewReplyflow is in early access — new workspaces are invite-only. Have a code? Sign up.
Legal

Privacy policy

Last updated: August 29, 2026

Replyflow puts an AI assistant on business websites. That means we handle two kinds of data: yours (the business running Replyflow) and your visitors' (the people chatting with your assistant). This page covers both, in plain language.

What we collect

From account holders

  • Your email address and a password (stored as a salted hash).
  • The public pages of websites you connect — we crawl them to build your assistant's knowledge.
  • Settings you configure: widget branding, tone, languages, calendar and CRM connections, and any answer corrections or voice-training transcripts you provide.
  • Usage and billing records for your workspace (conversation counts, model usage).

From website visitors

  • Chat messages, and anything a visitor chooses to share in them — for example an email address when asking to be contacted, or details needed to book an appointment.
  • Conversation context: the page the chat started on, a random per-browser visitor identifier, and the browser's timezone (used to quote appointment times correctly).
  • With voice chat, the audio of each spoken turn is transcribed and then handled like a text message.

The widget stores its visitor identifier and conversation id in the browser's localStorage so returning visitors can continue their conversation. It sets no advertising cookies and does no cross-site tracking.

How we use it

  • To answer visitors from the connected website's content.
  • To provide the features the business enables: lead capture, appointment booking, human handoff, CRM sync.
  • To show the business its own conversations, leads and stats.
  • To meter usage, bill, and keep the service secure and working.

We do not sell personal data, and we do not use your content or your visitors' conversations to train AI models. Conversations are sent to AI providers only to generate the reply in that conversation.

Who processes it

Replyflow runs on established infrastructure providers acting as processors: AI responses (OpenAI; Anthropic; OpenRouter where selected), search embeddings (Voyage AI), hosting (DigitalOcean, Vercel), database (Neon), and transactional email (Resend). If the business enables them, conversations also touch: Twilio (phone calls), Meta/WhatsApp (human handoff notifications), the connected calendar provider (Cal.com, Calendly, Google, Microsoft), and HubSpot (lead sync). Each receives only what its function needs.

Retention and deletion

Conversations, leads and settings are kept while the workspace is active so the business can use them. Deleting a workspace deletes its sites, conversations, leads and settings. Businesses can also delete individual data from the dashboard, and visitors can ask the business that operates the website to remove their conversation data.

Your role and your visitors

For visitor conversations, the business running the widget decides what the assistant does and is the controller of that data; Replyflow processes it on their behalf. If you're a visitor with a question about a specific website's chat, the fastest route is the business itself — or ask the assistant to bring in a human.

Security

Traffic is encrypted in transit (TLS). Data is stored with managed providers that encrypt at rest. Credentials for connected services (calendars, integrations) are stored encrypted with a separate key.

Changes and contact

If this policy changes materially, we'll note the new date at the top. Questions or requests: email support@replyflow.chat, or open the chat on this page and ask for a human.