1. Scope
This Privacy Policy explains how AI Reply Solutions processes personal information through its website, dashboard, contact and lead forms, shared inbox, automation features, and optional integrations. It covers account users as well as people whose messages or appointment details are handled by a business using the service.
2. Our role and the business user’s role
For account registration, website operation, security, and direct support, AI Reply Solutions determines why and how information is processed and acts as the data controller where that concept applies.
When a business connects a mailbox, calendar, website assistant, Telegram profile, X account, lead form, or another customer channel, that business normally decides why its customer information is processed. The business is responsible for its privacy notice, legal basis, customer instructions, and any required consent. AI Reply Solutions processes that customer information to provide the service on the business’s instructions.
3. Information we process
- Account and workspace information: name, login email, hashed password, business profile, services, prices, opening hours, automation instructions, team roles, invitations, assignments, internal notifications, activity, and integration settings.
- Customer and lead information: names, email addresses, phone numbers or channel handles, company details, enquiry content, conversation history, lead stage, tags, notes, and estimated value.
- Appointment information: requested service, date and time, duration, customer contact information, booking status, cancellation or rescheduling timestamps, reminder status, and related calendar event information.
- Connected Google information: the Gmail and Google Calendar data described in Section 4 when the account owner grants access.
- Connected X information: the account profile, Direct Messages, mentions, and identifiers described in Section 5 when the account owner grants access.
- Connected Meta and WhatsApp information: business account and phone-number identifiers, access tokens, customer phone numbers or platform identifiers, profile names supplied by the channel, messages, message status events, timestamps, and provider message identifiers described in Section 6 when the account owner connects the channel.
- Website and support information: contact-form submissions, session information, approximate request source, security events, and technical logs needed to operate and protect the service.
Passwords are stored as password hashes. Email-verification, password-reset, and team-invitation secrets are stored only as one-way hashes and expire automatically. When optional authenticator protection is enabled, its setup secret is encrypted at rest and recovery codes are stored only as one-way hashes. Supported access and refresh tokens are encrypted at rest.
4. Gmail and Google Calendar data
Google access is optional and begins only after the Google account owner completes Google’s authorization screen. The requested permissions are used as follows:
- Gmail read-only: read new customer emails, including sender and recipient addresses, subject, message body, timestamps, and thread or message identifiers, so the service can display the enquiry, preserve its context, identify booking requests, and prepare a reply. The service does not use this permission to modify or delete Gmail messages.
- Gmail send: send a reply from the connected Gmail account when an automated or human-approved response or enabled appointment reminder is produced.
- Calendar free/busy: check whether a proposed appointment time is available without retrieving unrelated event content for that check.
- Calendar events: create, update, and delete appointment events requested through the service.
Relevant email content and identifiers may be copied into the workspace’s shared inbox so authorised workspace users can view the conversation, prevent duplicate processing, provide follow-up, and maintain the lead record. By enabling Gmail, the account owner directs and consents to this workspace processing. Calendar availability is queried when needed; appointment details and identifiers may be stored with the corresponding booking.
If the account owner enables both Gmail and AI-assisted replies, the service may transfer the minimum relevant email content and business instructions to the configured AI model provider solely to generate the user-facing reply. By enabling both features, the account owner requests and consents to that transfer. AI-assisted replies should be disabled before connecting Gmail if the account owner does not want email content processed by the AI provider.
Google information is used only to provide or improve the user-facing email and appointment features the account owner enables. It is not sold, used for advertising, used to determine creditworthiness, or used to build unrelated user profiles. AI Reply Solutions’ use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements.
The account owner can disconnect Google from the dashboard and can also revoke access through Google Account connections. Revocation stops new API access. Copies already stored in workspace conversations or appointments remain subject to the retention and deletion provisions below.
5. X account data
X access is optional and begins only after the X account owner approves the permissions shown on X’s authorization screen. The service uses basic account information to identify the connected profile; Direct Message access to receive customer messages and send replies; Post access to receive mentions and publish replies to those mentions; and offline access to keep the connection working until it is disconnected or revoked.
Relevant Direct Messages, mentions, sender details, timestamps, and provider identifiers may be copied into the workspace’s shared inbox so authorised workspace users can view the conversation, prevent duplicate processing, provide follow-up, and maintain the lead record. If AI-assisted replies are enabled, the minimum relevant conversation content and business instructions may be sent to the configured AI model provider to generate a response.
The account owner can disconnect X from the dashboard or revoke access from X’s connected-app settings. This stops future API access but does not automatically erase conversations, leads, or appointments already stored in the workspace. Use of X remains subject to X’s own terms and policies.
6. Meta and WhatsApp data
Meta and WhatsApp connections are optional. The official connection begins when a workspace owner supplies credentials for a business account. For an enabled official connection, the service receives customer messages and delivery-status events through Meta’s WhatsApp Business Platform, places relevant messages in the workspace’s shared inbox, and may send a reply when the business has enabled that automation.
The separately labelled, unofficial WhatsApp Desktop connection uses a companion extension in the account owner’s browser. When paired, that extension reads new one-to-one message text, customer names or handles, timestamps, and technical message identifiers visible in the owner’s open WhatsApp Web session; sends that information to the paired workspace; and delivers workspace replies through the same browser session. The service stores only a one-way hash of the companion device token. It does not request or store the owner’s WhatsApp password or WhatsApp Web QR code. Group automation and bulk campaigns are not supported by this connection.
We use this information only to provide, secure, support, and improve the customer-communication features the business enables. We do not sell Meta or WhatsApp data, use it for advertising, or disclose it to another business except as directed by the workspace owner or required to operate the service. Authorised workspace users can see the communications associated with their workspace. If AI-assisted replies are enabled, the minimum relevant conversation content and business instructions may be sent to the configured AI model provider solely to generate that reply.
The account owner can disconnect either WhatsApp connection from the dashboard to stop future access. This does not automatically erase messages, leads, or appointments already stored in the workspace. A person whose information was obtained through a Meta product can follow our User Data Deletion Instructions. Use of Meta and WhatsApp remains subject to Meta’s applicable terms and policies.
7. How we use information
- Provide, secure, maintain, and troubleshoot the service.
- Authenticate users and keep workspaces separated.
- Receive, organise, and display customer communications and lead information.
- Apply business-authored rules and generate AI-assisted replies.
- Send authorised replies and enabled appointment reminders through a connected channel or configured email transport.
- Check availability, prevent conflicting bookings, and create, reschedule, or cancel appointments.
- Respond to support enquiries and communicate about the service.
- Detect abuse, enforce limits, investigate errors, and comply with legal obligations.
8. AI processing
When AI replies are enabled, the service may send the business profile, relevant instructions, and a limited portion of the recent conversation to the configured AI model provider to generate a response. Customers should not include unnecessary sensitive information in messages. AI output can be inaccurate and should be subject to appropriate business oversight. AI Reply Solutions does not use Google user data to train a general-purpose AI model.
9. Legal bases
Where the GDPR or similar law applies, AI Reply Solutions relies on performance of a contract to provide requested account features; legitimate interests in operating, securing, and improving the service; consent for optional integrations where required; and compliance with legal obligations. A business using the service must determine and communicate the appropriate legal basis for its processing of customer messages, leads, and appointments.
10. Service providers and disclosures
We use infrastructure providers to operate the service, including Vercel for application hosting and Supabase for database services, and a configured SMTP mail server to deliver account verification, password-recovery, staff-invitation, eligible manual-booking reminder messages, and an account-deletion notice containing the reason supplied by the workspace owner. If enabled by the account owner, information may also be processed by Google for Gmail and Calendar functionality, Meta for WhatsApp Business Platform messaging, X for connected messaging, and the configured AI model provider for response generation. A connected communication channel processes messages under that channel’s own terms.
Providers receive only the information reasonably necessary for their function and are expected to process it under applicable contractual and security obligations. We may also disclose information when required by law, to protect users or the service, or as part of a business reorganisation subject to appropriate safeguards. We do not sell personal information.
11. International transfers
Some providers may process information outside the country where it was collected. Where required, transfers must rely on an applicable legal mechanism, such as an adequacy decision or approved contractual safeguards.
12. Retention and security
Account, workspace, conversation, lead, and appointment information is retained while needed to provide the workspace and until it is deleted, the account is closed, or a valid deletion request is completed, subject to legal, fraud-prevention, dispute, and backup requirements. OAuth tokens are retained only while the integration remains connected or until they are revoked or replaced. Expired or consumed account-verification and recovery records are removed. Contact and security records are kept only for as long as reasonably necessary for support, service integrity, and legal obligations.
We use safeguards including strong password hashing, optional authenticator-based multi-factor authentication, one-way-hashed recovery codes, email verification, revocable signed sessions, encrypted integration credentials, access controls, tenant separation, secure transport, and webhook verification. No online service can guarantee absolute security.
13. Your choices and rights
Depending on your location, you may have rights to access, correct, delete, restrict, or object to processing of your personal information and to receive a portable copy. You may withdraw consent without affecting earlier lawful processing and may complain to your local data-protection authority.
Account owners can disconnect integrations or permanently delete their workspace from Account Security in the dashboard. Permanent deletion requires re-authentication, removes the workspace and its stored operational data, signs out its team members, and sends AI Reply Solutions the reason entered by the owner. Existing events already created in an external Google Calendar are not deleted. To request access or another privacy action, use the contact details below. We may need to verify identity and authority. If the request concerns a conversation handled for a business using AI Reply Solutions, contact that business first because it normally controls the customer relationship and must instruct us where appropriate. People using a Meta product can also use our dedicated User Data Deletion Instructions.
14. Automated processing
The service can classify enquiries, suggest or send replies, and offer appointment times. These functions are not intended to make decisions that produce legal or similarly significant effects. Businesses must provide human review where the context, risk, or applicable law requires it.
16. Children
The service is intended for business users and is not directed to children. Businesses must not knowingly use it to collect children’s information without the notices, consent, and safeguards required by law.
17. Changes to this policy
We may update this policy when the service or legal requirements change. Material changes will be communicated through reasonable means where required. The date above identifies the current version.
18. Contact
AI Reply Solutions is the service contact for this policy. For privacy questions or requests, email aireplysolutions@gmail.com or use our contact form.