In this policy, “we,” “us,” and “our” mean RepBot. “You” means the person or business using the service.
What we collect
We collect the information needed to operate your account and the review-management features you use. This includes:
- Account and Workspace information: account details, Workspace details, and team-member invitations.
- Billing and support information: billing status and requests you send to support.
- Review-management data: information you add to RepBot or connect through supported integrations.
- Team and activity information: membership, permissions, selected Profiles, credit usage, and records of account actions.
- Website inquiries: information you choose to send when you contact us through the marketing website.
Our website and app also process technical information needed to deliver pages and protect the service. Our Cookie Policy explains cookies, browser storage, and third-party resources in more detail.
When you connect Google Business Profile, RepBot stores the tokens and review data needed to sync reviews, generate responses, and publish approved replies.
Website visitors do not need an app account to read public pages. If you contact us through the website or by email, we process the details you choose to provide so we can handle your inquiry. Avoid including customer content or other sensitive information that is not needed for your request.
How we use information
We use your information to:
- Provide RepBot and maintain secure sign-in sessions.
- Process billing and send operational notifications.
- Import reviews and generate AI-assisted response drafts.
- Publish responses you have approved.
- Respond to inquiries sent through our website.
We may use aggregate, de-identified usage data to improve reliability, product quality, and abuse prevention.
Website and app analytics
Ordinary marketing pages. We do not use Google Analytics or third-party audience-tracking tools on these pages. The separate free tool uses device recognition for abuse control as described below. Delivering pages, receiving inquiries, and loading resources such as Google Fonts still involves processing information.
App. We use PostHog to understand usage and diagnose reliability problems. It is configured in cookieless mode, but can still process page visits, interactions, performance information, and errors. The configuration includes click and heatmap collection and masking settings for session replay, which can reproduce a sequence of on-screen interactions for troubleshooting. Text, element attributes, and form inputs are configured to be masked in recordings. These settings are designed to limit the content included in recordings.
Service messages and your daily digest
The app can send an optional daily digest when responses from Profiles you can access are waiting for approval. This preference is enabled by default and can be changed in your User Profile for the relevant Workspace.
Turning off the digest does not turn off required service messages. Billing, security, legal, invitation, account, and required service notices, including low-credit alerts, are sent according to their purpose and the recipient's responsibilities. The digest setting does not control marketing communications from the website.
AI processing
To generate response drafts or removal assessments, we may send review text, business context, and Brand Rules to the AI providers configured for the service.
The app's response-generation service uses OpenAI. Depending on the request, the information sent can include a review's rating and text, a screened reviewer name, Brand Rules, and the previous response and instructions when regenerating a draft. RepBot does not submit review-removal requests on your behalf.
For publishing decisions, RepBot uses the text you approve as the source of truth.
Sharing and subprocessors
We share information only with service providers needed to operate RepBot. These include providers of hosting, authentication, billing, communications, analytics, and AI infrastructure.
We do not sell customer data.
Providers used by the app
| Provider | Role in the service |
|---|---|
| Cloudflare | App hosting and request processing, email-code authentication, security checks, and outbound service email. |
| Neon | Storage of application records in the app's database. |
| OpenAI | AI-assisted response generation using the information described above. |
| Stripe | Hosted payment processing and subscription billing. |
| PostHog | App usage analytics, error diagnostics, and configured recording features. |
Google Business Profile is a connected service you authorize for eligible Profiles. Google Fonts is described separately below. These services have their own terms and privacy information. This table describes the app's provider roles; it does not establish that every provider processes every category of information.
Google Fonts
Our marketing website uses Google Fonts to display text. Where fonts load directly from Google, your browser sends Google the request information needed to deliver them, including your IP address. This is separate from Google Analytics. Fonts served from our own website do not require a font request to Google.
Security and retention
We use access controls, encrypted connections, secure cookies, and integration tokens limited to their intended scope to protect information handled by RepBot.
We retain customer data while an account is active and as needed for legal, security, billing, and backup purposes.
Different records have different purposes and retention periods:
- Reviews and account history: deactivating or archiving a Profile does not delete its history. Ending a paid plan is separate from an account-closure or personal-deletion request.
- Google Business Profile connection tokens: when a Profile's Google access ends, we stop Google calls and disable its token. The disabled token is kept for 30 days to support short reactivation, with a warning seven days before removal. After 30 days, we revoke Google access and remove the local token. Eligible reactivation can reuse a valid token only after your confirmation; after removal, you must connect again.
- Browser storage: session cookies and interface settings have the durations described in the Cookie Policy. Those durations do not determine how long server-side account records are retained.
- Privacy-request records: records needed to handle and demonstrate completion of a privacy request can outlast the deleted account data. The app sets a three-year retention period when a privacy case reaches a terminal state, preserving any longer retention already required for related records.
- Billing, security, and backup records: some information remains where needed for fraud prevention, tax, legal, security, or backup purposes.
Archiving a Profile does not start or restart the Google token retention period. A scheduled cancellation starts that period when the Profile's Google entitlement actually ends.
Your choices
You can update Workspace data, disconnect integrations, and manage team access. You can also contact support to request an export or deletion of your data.
These app controls depend on your role and permissions. Personal-data requests can be sent to our compliance email whether you are an app user or a website visitor. Describe the request and the relevant account or interaction so we can determine its scope and any identity verification needed.
Deleting your personal data, closing a Billing Account, leaving a Workspace, and canceling a subscription are different actions. A team member cannot use a personal-data request to assume ownership of another person's account or direct deletion of an entire Workspace. Workspace offboarding and related account-administration requests are handled by our support team.
Some records may need to be retained for fraud prevention, tax, legal, or security obligations.
Free review-response tool
Ordinary pages, the app, and the free tool
Ordinary marketing pages provide information about RepBot. The app provides signed-in review management and uses the account, billing, and PostHog processing described above. The free review-response tool is a separate feature: it processes your drafting inputs and additional device and network signals to help control abuse. Its device-identification flow does not run merely because you browse an ordinary marketing page.
Drafting inputs
The free tool processes the review text and star rating you submit, your selected tone, and any optional reviewer name or industry. These inputs are sent to OpenAI to generate response suggestions. Avoid including phone numbers, email addresses, links, or unnecessary personal information. Review and edit the suggestions before using them.
Additional data for abuse control
The tool uses Cloudflare Turnstile and device-recognition services to help prevent automated misuse and support free-usage controls. These checks begin when you interact with the response form and may run before you submit a review.
To prevent abuse and administer free-tool usage, RepBot and its service providers process device, browser, and network information. RepBot maintains pseudonymous records needed for these purposes and does not store raw device identifiers or IP addresses in its abuse-control records.
These extra signals support abuse prevention and free-tool usage controls, rather than advertising. They are separate from app analytics and account authentication.
Quality-review records
For quality assurance, we temporarily retain submitted content and generated suggestions for up to 10 days, after which they are deleted.
Retention and choices
The tool uses a visitor cookie as described in our Cookie Policy. Abuse-control records are retained only for as long as needed for abuse prevention and free-tool usage controls. Provider retention may be governed by their own policies.
You can choose not to interact with the tool, or clear its cookies and browser storage. Clearing storage does not necessarily prevent device recognition or remove provider-side records. For privacy requests, contact compliance and identify the tool and approximate time of use. Do not send device identifiers or sensitive review content in your initial message.