ReplyProof
Start free trial
LAST UPDATED · SEPTEMBER 27, 2026

Privacy, in plain language.

ReplyProof is an early-access service for drafting customer questionnaire answers from documents you provide.

Information we process

We process your email address, authentication records, workspace name, uploaded documents and their extracted text, questions, answers, citations, approval history, usage totals, and feedback. Supabase handles passwords; ReplyProof does not store readable passwords. Essential, HTTP-only cookies keep you signed in. We do not add advertising trackers or sell customer content.

Why we use it

We use this information to provide the service, isolate workspaces, prepare and verify drafts, enforce trial and spending limits, troubleshoot errors, respond to support requests, and prevent abuse. Operational logs store routes, status codes, timing, and sanitized error categories rather than document contents or passwords.

Feedback and support

Feedback reports contain the message you submit, your verified account email when signed in (or an optional unverified reply address), and the page and workflow step if you choose to include them. We do not automatically attach documents, answers, screenshots, full URLs, or browser logs. The owner can assign priorities and add internal notes. Feedback does not trigger AI actions or automatic email replies. One-way, date-scoped IP hashes help rate-limit signed-out reports; raw IP addresses are not stored by this feedback feature.

Service providers

Cloudflare hosts the application and stores workspace data in D1 and R2. Supabase manages authentication in a US East project. OpenAI processes source passages for search embeddings and relevant passages with questions for drafting. Authentication emails are delivered through the configured email provider. These services may process information in the United States and other locations under their own infrastructure arrangements.

OpenAI API data is not used for model training by default. ReplyProof requests store: false for generated responses. That does not eliminate OpenAI’s separate abuse-monitoring retention, typically up to 30 days. Do not upload material requiring zero retention.

Security and access

Cloudflare provides encryption at rest, and HTTPS protects transit. Server-side account checks restrict workspace access. This is not end-to-end encryption. The owner dashboard shows account and usage metadata and submitted feedback. Infrastructure access is limited to authorized administration; it is not a promise that the operator can never access stored data.

Retention and deletion

Your workspace content remains available until you delete it. Removing a source deletes its active file and searchable chunks; quoted evidence already attached to an answer remains in that questionnaire until the questionnaire or workspace is deleted. Workspace deletion removes active uploaded files, extracted text, questions, answers, activity, and feedback. It does not immediately erase infrastructure backups or provider-retained records, which expire under provider retention settings.

Deidentified spending records remain to preserve budget accounting. A hashed account identifier supports a 90-day period to prevent repeated free-trial resets. Expired identifiers are removed during subsequent application cleanup. Application error records and aggregate request metrics are kept for approximately 30 days, with cleanup performed during subsequent application activity. Your Supabase sign-in account remains after workspace deletion; request its removal from Account & support. Identity verification may be required.

Signed-out feedback and its internal notes are removed after approximately 90 days during subsequent application cleanup. Signed-in feedback and related internal notes are removed with workspace deletion. Hosting providers may retain infrastructure logs under their own policies.

Your choices

Download workspace data from Account & support and original source files from Documents. You can delete questionnaires, remove sources, or delete the workspace. For access, correction, account removal, or privacy questions, use Account & support and select “Privacy or account removal.” Rights available to you depend on your location.

Changes to this notice

We will update this notice when our practices change. Material changes that affect your use of the beta will be communicated through the service.