Privacy Policy
Effective date · July 28, 2026
Replyhand is a shared team inbox and lightweight CRM that helps a business bring its customer conversations — from a public web chat widget on its own website to WhatsApp, Instagram, Facebook Messenger, and a phone line — into one workspace, with an AI agent that can answer on the business's behalf. This Privacy Policy explains what personal information we handle, why, and the choices and rights you have. We've written it in plain English because we want you to actually understand it.
A note on our two roles. Replyhand serves two different groups of people, and our privacy responsibilities differ for each. For the businesses and the team members who hold a Replyhand account, we are the data controller. For a business's own customers and website visitors — the people whose details a business stores in Replyhand, or who contact a business through its chat widget, its connected messaging channels, or its phone line — the business is the data controller and we act only as a processor on the business's behalf. This distinction runs through the whole policy, so we explain it carefully in Section 2 and again wherever it matters.
1. Introduction & Who We Are
Replyhand is a software-as-a-service platform for customer communication. Through the Replyhand web application at replyhand.com and the Replyhand mobile app for iOS and Android, a business's owners, admins, and members can manage a shared inbox of customer conversations, keep a lightweight CRM of the people who contact them, connect communication channels (a public web chat widget on their own website, WhatsApp, Instagram, Facebook Messenger, and a phone line), and configure an AI agent that answers conversations on the business's behalf using knowledge the business provides. Replyhand is a multi-tenant platform: each business is an organization, and a person can belong to one or more organizations with a role of owner, admin, or member. The service and this policy are provided in English and Spanish.
Replyhand is operated by Braintu Inc., located at 251 Little Falls Drive, Wilmington, Delaware 19808, USA ("Replyhand", "we", "us", or "our"). Throughout this policy we refer to the businesses and team members who hold a Replyhand account as "you".
Scope. This policy primarily governs the personal information we handle as a controller — chiefly the account and organization information of the people who use Replyhand. It also explains, for transparency, the categories of personal information we process on a business's behalf when that business uses Replyhand to manage its own customer conversations. For that processor activity, the business's own privacy policy and the processor terms in our Terms & Conditions govern how the data is used, and an individual End Customer's rights run through the business. We say more about this in Sections 2, 5, and 13.
2. Who This Policy Covers
Replyhand touches the personal information of two distinct groups of people, and our responsibilities are different for each. Please find the group that applies to you.
Account Users (owners, admins, and members)
Account Users are the people who register for and use the Replyhand dashboard — a business's owners, admins, and members. For the personal information that relates to your Replyhand account and your use of the service, Replyhand is the data controller: we decide how and why that information is processed, and the rights described in Section 12 apply directly between you and us.
End Customers (a business's own customers and website visitors)
End Customers are a business's own customers — the people whose details a business stores in Replyhand and the people who contact a business through its public web chat widget, its connected messaging channels (WhatsApp, Instagram, Facebook Messenger), or its phone line. For this information, the business is the data controller and Replyhand acts only as a processor, handling the data on the business's behalf and under its documented instructions.
If you are an End Customer and want to exercise your privacy rights — to access, correct, or delete information held about you, for example — please contact the business you dealt with. For End Customers, the business is the controller and must respond to data-subject requests; Replyhand will support the business but will not respond to the individual directly without the business's instruction, because the data belongs to that business and is isolated to its workspace. See Section 13 for more.
3. Information We Collect
The information below reflects what Replyhand actually collects and stores. Almost all of it lives in our primary backend (Supabase). We do not collect more than we describe here — in particular, we use no advertising trackers. We do run first-party product analytics for Account Users (never for End Customers), described under Technical & Usage Data below.
Account Information
When you create or use a Replyhand account, we collect your full name, email address, your phone number (if you sign in by phone), your role within each organization you belong to, and (optionally) an avatar. Sign-in is passwordless: you sign in with your email address and a one-time code we send to it, with your phone number and a one-time SMS code (delivered through Twilio Verify), or — where it is enabled for the service — with "Sign in with Google" or "Sign in with Microsoft." If you sign in with Google or Microsoft, we receive basic OAuth profile data from that provider (such as your name, email address, and profile image). Replyhand accounts have no password — there is nothing for us to store, and authentication (including the one-time codes) is managed by Supabase Auth. See Section 6 for more on third-party sign-in.
Organization Data
For each organization, we store configuration such as the organization name, its slug / URL, your channel and chat-widget settings, and the membership and role information that controls who can access the workspace. When an owner or admin invites a teammate, we store the invitee's email address and the invitation's status so the invitation can be delivered and redeemed.
Your Contacts & Conversations
Replyhand is a shared inbox and CRM, which means you receive and store personal information about other people — your own customers and the people who contact you. This includes contact records (display name, email, phone, and any notes or metadata you choose to store), conversations (subject and message previews), the content of messages exchanged with your customers (free text, up to 8,000 characters per message), message attachments (photos, documents, and voice notes — voice notes are transcribed so your team and the AI agent can read them), AI agent replies sent on your behalf, internal team notes that you add to a conversation, and an activity timeline of conversation events.
Important: this is third-party personal data that you, the business, choose to collect or receive. For this data the business is the controller and Replyhand is the processor, and we process it only on your instructions to provide the service (see Sections 4 and 5). You are responsible for having a lawful basis to collect and store this information and for giving any notices your customers are owed. Please don't store more than you need, and don't enter special-category or other sensitive personal data into these fields.
Public Chat Widget Interactions
When a visitor messages a business through its public web chat widget, Replyhand captures, on the business's behalf, the content of the visitor's message and, optionally, a display name and email address that the visitor chooses to provide. Visitors are anonymous — they do not create an account or sign in. To let a visitor return to the same conversation, the widget generates a random token stored in the visitor's browser (in local storage); that token is the visitor's only identifier and credential. We explain the widget in more detail in Section 7.
Connected Messaging Channels
A business can connect messaging channels — WhatsApp, Instagram, and Facebook Messenger (via Meta) — so those conversations land in the same inbox. For each connected channel we store, on the business's behalf, the conversation content, the routing identifiers the platform provides (for example the customer's phone number or social handle and display name), and any attachments the customer sends.
Phone Calls (Voice)
A business can add a phone line answered by its AI agent. To do this, live call audio is processed in real time by our voice provider (ElevenLabs) for speech-to-text and text-to-speech, over telephony provided by Twilio. Calls are recorded and transcribed end to end — including any portion where the call is transferred to a member of the business's team — and Replyhand stores, on the business's behalf: the call recording (audio), a full transcript of the conversation, and a summary in the business's inbox. Callers hear a recording notice in the call greeting. Call audio and a person's voice are sensitive, and call recording is regulated differently across jurisdictions — including "two-party" and "all-party" consent rules. Because the business operates its phone line, the business is responsible for any additional call-recording and consent notices required for its callers in its jurisdiction.
Cookies & Session Data
When you sign in, we process your authentication and session information through the essential cookies described in Section 8. We do not use non-essential or tracking cookies.
Technical & Usage Data
Like any web service, your device's IP address and similar connection information are necessarily handled by our hosting and backend providers (Vercel and Supabase) to deliver and secure the application. Replyhand itself does not run geolocation or build advertising profiles, and it does not store IP addresses, device fingerprints, or browser/user-agent strings about End Customers at the application layer. We do not use advertising pixels or cross-site tracking.
Product Analytics, Session Replay & Error Reports (PostHog)
To understand where Account Users get stuck and what errors they hit, we run product analytics through PostHog (one analytics project per product, hosted in PostHog's US cloud). For Account Users only, this collects: usage events (screens opened and actions taken in the dashboard and the mobile app), device and connection metadata, client-side error reports (including native crash reports from the mobile app), and session replays — recordings of what your screen showed during a dashboard or mobile session. Replays capture screen content as you saw it, including text you type and images you view; passwords are always masked. Once you sign in, this data is linked to your account id and email so we can see a real session behind a real problem.
Scope and limits. Analytics covers Account Users only: the chat widget and every End Customer surface are never instrumented, so your customers are not tracked by us. On the web, analytics events are sent through our own domain (first-party); marketing pages set no analytics identifiers until you sign in. In the mobile app, analytics runs only in production builds and reports directly to PostHog. We use analytics to improve the product — never for advertising, and we never sell it.
4. How We Use Information
We use personal information only for the purposes below. For users in the EEA, UK, and similar regimes, we also note the lawful basis we rely on under Article 6 of the GDPR/UK GDPR.
- Provide and operate the service — to set up and run your organization, store your contacts, conversations, and messages, and deliver the features you use, including the shared inbox, the connected channels, and the public chat widget. Lawful basis: performance of our contract with you.
- Provide AI features — to generate the AI agent's replies on your connected channels and phone line, transcribe voice audio (voice notes and call recordings), and produce conversation summaries and insights for your inbox. Lawful basis: performance of our contract with you.
- Authenticate you and secure accounts — to sign you in, keep your session active, remember your active organization, and protect against unauthorized access. Lawful basis: performance of contract and our legitimate interests in security.
- Send transactional email — to deliver sign-in codes, team invitations, and service notifications. Lawful basis: performance of contract and our legitimate interests in operating the service.
- Maintain security and prevent abuse — to detect, investigate, and prevent fraud, abuse, and security incidents, and to keep the platform reliable. Lawful basis: our legitimate interests and, where applicable, legal obligation.
- Comply with law — to meet our legal and regulatory obligations and to establish, exercise, or defend legal claims. Lawful basis: legal obligation and legitimate interests.
Where we process a business's contacts, conversations, and messages, we do so only on the business's instructions as its processor, for the purpose of providing the service — not for our own purposes. We do not use your customer conversations to build advertising profiles, and neither we nor our AI providers use them to train artificial-intelligence models — AI providers process conversation content only to generate the requested output for your organization.
5. How We Share Information & Our Sub-processors
We do not sell your personal information, and we do not "share" it for cross-context behavioral advertising, as those terms are defined under California law (the CCPA/CPRA). We do not rent or trade personal information. We disclose personal information only to the service providers ("sub-processors") that help us run Replyhand, and in the limited other circumstances described below.
Our sub-processors
We rely on the following sub-processors, each engaged for a specific purpose and bound by terms that require them to protect personal information and to process it only as needed to provide their service to us:
- Supabase — our primary backend: the PostgreSQL database, authentication (Supabase Auth), and realtime infrastructure. Row-Level Security enforces strict per-organization data isolation. Supabase runs on Amazon Web Services (AWS) and stores essentially all application data.
- Vercel — application hosting and deployment, which serves the application and processes requests in transit.
- Resend — transactional email delivery: sign-in codes, team invitations, and service notifications, so it receives the recipient's email address and the message content.
- AI model providers via the Vercel AI Gateway (including Anthropic) — generate the AI agent's replies, summaries, and insights. Conversation content is sent to produce the requested output for the business and is not used to train the providers' models.
- ElevenLabs — the AI voice agent on phone calls (speech-to-text, text-to-speech, and turn-taking) and speech-to-text for voice notes and call recordings.
- Twilio — telephony: provisions each business's phone number, carries its calls, and produces the call recordings we store on the business's behalf; also delivers the one-time SMS sign-in codes (Twilio Verify).
- Meta Platforms — delivery of WhatsApp, Instagram, and Facebook Messenger messages for the channels a business connects; Meta processes those conversations under its own platform terms.
- Stripe — payments and billing for paid subscriptions. Stripe processes payment details directly; Replyhand stores no card numbers.
- Google (OAuth) — "Sign in with Google" single sign-on, used to authenticate Account Users who choose that method, where it is enabled for the service.
- Microsoft (Azure OAuth) — "Sign in with Microsoft" single sign-on, used to authenticate Account Users who choose that method, where it is enabled for the service.
- PostHog — product analytics, session replay, and error/crash reporting for Account Users of the dashboard and mobile app (one analytics project per product, hosted in PostHog's US cloud). See Technical & Usage Data in Section 3.
We do not use any third-party advertising network. Our product-analytics provider (PostHog) is listed above and described in Section 3.
Sub-processor changes
We maintain an up-to-date list of sub-processors and will provide businesses with reasonable advance notice of any new or replacement sub-processor, so that a business can object where it has grounds to do so.
Other disclosures
We may also disclose personal information: (a) to comply with law or a valid legal request, or to protect the rights, safety, and security of Replyhand, our users, and the public; (b) in connection with a business transfer such as a merger, acquisition, financing, or sale of assets (with continued protection of the information under this policy); and (c) with your consent or at your direction. Where we act as a processor, any disclosure of a business's customer data follows that business's instructions.
6. Third-Party Sign-In
You can sign in to Replyhand using your email address and a one-time code we send to it (sign-in is passwordless). Where it is enabled for the service, you can also sign in using your Google or Microsoft account. When you use single sign-on, we receive basic profile information from that provider (such as your name, email address, and profile image) to create and authenticate your account. See Section 3 (Account Information) for the data involved.
Google API Services User Data Policy (Limited Use). Replyhand's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We use Google data only to provide the sign-in feature you requested and do not use it for advertising or sell it. Likewise, when you use "Sign in with Microsoft," we use the Microsoft profile data we receive only to provide the sign-in feature you requested, and we do not use it for advertising or sell it.
7. The Public Chat Widget
A business can embed Replyhand's public chat widget on its own website using an inline frame (an iframe), so its website visitors can send the business a message without creating an account or signing in. As described in Section 3, the widget captures the visitor's message and, optionally, a display name and email the visitor provides for the business's reference.
To let a visitor return to the same conversation, the widget generates a random token in the visitor's browser and stores it in the browser's local storage (it does not use a cookie for this). That token is the visitor's only identifier and credential — anyone with access to that browser profile can resume the conversation, so the widget is best suited to non-sensitive, general enquiries. The widget does not set advertising or cross-site tracking cookies, and Replyhand does not log End Customer IP addresses or device fingerprints at the application layer.
Because a business embeds and presents the widget on its own website, that business is responsible for providing its visitors with a privacy notice, and for displaying any notice or obtaining any consent its jurisdiction requires for storing an identifier in a visitor's browser. If you are a website visitor and want to exercise privacy rights over a message you sent through a business's widget, please contact that business — it is the controller of that data (see Section 13).
8. Cookies & Tracking
Replyhand uses essential, strictly-necessary cookies — the minimum required to make the service work and keep it secure — plus, after you sign in, a first-party identifier for the product analytics described in Section 3. We do not use any advertising cookies.
- Supabase Auth session cookies (essential, httpOnly) — set by Supabase Auth to keep you signed in and to maintain and refresh your authenticated session as you use the dashboard.
- Active-organization cookie (`replyhand_active_org`; essential/functional, not httpOnly so it can be read by scripts in your browser, persists about 1 year) — remembers which organization you are currently viewing so the dashboard shows the right workspace. It is cleared when you sign out.
The public chat widget stores a visitor token and the current conversation id in the visitor's browser's local storage (not a cookie), so a returning visitor can resume their conversation on that device. These values stay on the visitor's device and are used only to identify the conversation.
We use no advertising pixels and no cross-site tracking. Our marketing pages set no analytics identifiers: before you sign in, any analytics run without cookies or persistent storage. After you sign in, our first-party product analytics keeps its identifier in your browser's storage on our own domain so your session can be associated with your account. Because we rely on strictly-necessary cookies plus this signed-in, first-party product analytics — and use no advertising or cross-site tracking — no cookie-consent banner is required under the applicable rules.
9. Data Security
We take security seriously and apply safeguards appropriate to the sensitivity of the data we handle:
- Encryption in transit — data is protected with TLS as it travels between you and Replyhand.
- Encryption at rest — data is encrypted at rest by our backend provider, Supabase (on AWS).
- Per-organization isolation — Row-Level Security (RLS), backed by composite foreign keys, enforces strict multi-tenant separation, so one organization's data is not accessible to another. This isolation is verified by automated database tests.
- Secure authentication — sign-in is passwordless (one-time email codes and OAuth, managed by Supabase Auth), and session cookies are httpOnly; there are no passwords for Replyhand to store or lose.
- Least-privilege access — we request least-privilege scopes for third-party sign-in, and the anonymous chat widget can reach data only through narrowly-scoped database functions, never the tables directly.
No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. We do not currently claim formal certifications such as SOC 2 or ISO 27001. Where we act as a processor and become aware of a personal-data breach affecting a business's data, we will notify the affected business without undue delay so it can meet its own obligations, and we will support any legally required notifications.
10. Data Retention
We keep personal information only for as long as we need it for the purposes described in this policy.
- Account & organization data (controller) — retained while your account and organization are active. When an organization is deleted, its data is removed from the active database as described below.
- Customer contacts, conversations, and messages (processor) — retained according to the business's instructions for as long as the business uses Replyhand, and deleted or returned on termination of the business's account, subject to short-term backup retention.
- Voice call recordings and transcripts — stored on the business's behalf alongside the conversation they belong to, and they follow the customer-data retention above (retained per the business's instructions, deleted or returned on termination).
- Team invitations — kept in their final state (pending, accepted, or revoked); invitation links expire after 7 days.
- Backups — residual copies may persist in routine, encrypted backups for a limited period and are cycled out in the ordinary course.
Replyhand does not currently offer a self-service data-export or account-deletion tool. If you need a copy of your data, or want your organization and its data deleted, contact us at privacy@replyhand.com or support@replyhand.com and we will assist you. When an organization is deleted, its associated contacts, conversations, and messages are permanently deleted from the active database (a hard delete), with residual copies removed from routine backups in the ordinary course. Where we cannot state an exact retention period, we determine retention based on the nature and sensitivity of the data, the purpose for which we hold it, applicable legal requirements, and the need to resolve disputes and enforce agreements.
11. International Data Transfers
Replyhand relies on infrastructure and sub-processors that are based in or operate from the United States, including our hosting and database providers (Supabase runs on AWS; Vercel), our email provider (Resend), our AI and voice providers (Anthropic via the Vercel AI Gateway, ElevenLabs, and Twilio), our messaging platform (Meta), our payment processor (Stripe), our product-analytics provider (PostHog, US cloud), and our sign-in providers (Google and Microsoft). If you or your customers are located outside the United States — for example, in Latin America, the EEA, or the UK — personal information may be transferred to and processed in the United States and other countries whose data-protection laws may differ from those where you are located.
Where the data-protection law that applies to you or your customers requires a specific safeguard for such a transfer, we will put an appropriate mechanism in place. Our primary hosting region is in the United States, and we rely on our sub-processors' own security and data-protection commitments, described above, to protect information wherever it is processed.
12. Your Privacy Rights
Depending on where you live, you may have rights over your personal information. This section describes the rights of Account Users, for whom Replyhand is the controller. If you are an End Customer of a business that uses Replyhand, please see Section 13 — your requests should go to that business.
EEA / UK (GDPR and UK GDPR)
If you are in the EEA or the UK, you have the right to: access the personal information we hold about you; request rectification of inaccurate data; request erasure ("right to be forgotten"); restrict processing; data portability; object to processing based on legitimate interests; and withdraw consent at any time where we rely on consent (withdrawing consent does not affect processing already carried out).
You also have the right to lodge a complaint with a supervisory authority — in the UK, the Information Commissioner's Office (ICO), and in the EEA, your local data protection authority. We'd appreciate the chance to address your concerns first, but you can contact them at any time.
California (CCPA / CPRA)
If you are a California resident, you have the right to: know and access the personal information we collect, use, and disclose; delete personal information; correct inaccurate personal information; obtain a portable copy; and opt out of the sale or sharing of personal information — though, as noted in Section 5, we do not sell or share personal information. You may also limit the use of sensitive personal information. We will not discriminate against you for exercising your rights, and you may use an authorized agent to submit a request on your behalf.
The categories of personal information we collect, the categories of sources, the business and commercial purposes for which we use them, and the categories of sub-processors to whom we disclose them are described in Sections 3, 4, and 5. In the preceding 12 months we have not sold or shared personal information for cross-context behavioral advertising.
How to exercise your rights
To make a request, email us at privacy@replyhand.com. To protect your information, we will take reasonable steps to verify your identity before acting, and we will respond within the timeframes required by applicable law (generally within one month under the GDPR/UK GDPR and within 45 days under the CCPA/CPRA, with extensions where permitted). For End Customers, the business is the controller and must respond to data-subject requests; Replyhand will support the business but will not respond to the individual directly without the business's instruction. Requests that concern an End Customer's data held on a business's behalf will therefore be routed to the relevant business, which is the controller of that data.
13. For the Customers of Businesses That Use Replyhand
If you are a customer or website visitor of a business that uses Replyhand — for example, you messaged a business through its chat widget, WhatsApp, Instagram, or Facebook Messenger, you called its phone line, or a business stored your contact details — please note that Replyhand processes your personal information on that business's behalf, as its processor, and only under its instructions. The business is the data controller for that information.
Because the business controls this data and it is isolated to its workspace, you should direct any privacy request — to access, correct, or delete your information, or to ask how it is used — to the business you dealt with. Replyhand will support that business and forward information as needed, but will not respond to the individual directly without the business's instruction. The business's own privacy policy, not this one, primarily governs how your information is used.
14. Children's Privacy
Replyhand is a business tool and is not directed to or intended for children. We do not knowingly collect personal information from anyone under 16 (or under 13 in the United States) as a controller. If you believe a child has provided personal information to us as a controller, please contact us and we will take appropriate steps to delete it.
Businesses that use Replyhand should not enter or collect the personal information of children through the service without a valid lawful basis and any required parental consent.
15. Changes to This Policy
We may update this Privacy Policy from time to time as Replyhand evolves or as legal requirements change. When we make changes, we will revise the effective date shown near the top of this policy. If the changes are material, we will provide more prominent notice — for example, by email to Account Users or an in-app notice — before the changes take effect. The version identified by the most recent effective date governs. We encourage you to review this policy periodically.
16. Contact Us
If you have any questions, concerns, or requests about this Privacy Policy or your personal information, we're here to help.
- Privacy inquiries: privacy@replyhand.com
- General & support: support@replyhand.com
- Entity: Braintu Inc.
- Address: 251 Little Falls Drive, Wilmington, Delaware 19808, USA
This Privacy Policy is governed by the laws of the State of Delaware, USA, without regard to its conflict-of-laws rules.
We're committed to handling your information carefully and transparently. If you have any questions about this policy, want to exercise a privacy right, or need help, please reach out to our privacy team — we read every message and aim to respond promptly. If you are a customer of a business that uses Replyhand, please contact that business directly for requests about your information; the business is the controller of that data and Replyhand supports it as the processor.
privacy@replyhand.com