Skip to content
RepBot RepBot
Home Features Pricing Free Tools Blog
Log in Sign up
Home Features Pricing Free Tools Blog Log in Sign up
RepBot.ai / Policies

Privacy Policy

Last updated: September 15, 2026

This policy explains what information RepBot collects when you visit our website or use our app, how we use it, and the choices available to you.

In this policy, “we,” “us,” and “our” mean RepBot. “You” means the person or business using the service.

On this page

  • What we collect
  • How we use information
  • AI processing
  • Sharing and subprocessors
  • Security and retention
  • Your choices
  • Free review-response tool
  • Contact

What we collect

We collect the information needed to operate your account and the review-management features you use. This includes:

  • Account and Workspace information: account details, Workspace details, and team-member invitations.
  • Billing and support information: billing status and requests you send to support.
  • Review-management data: information you add to RepBot or connect through supported integrations.
  • Team and activity information: membership, permissions, selected Profiles, credit usage, and records of account actions.
  • Website inquiries: information you choose to send when you contact us through the marketing website.

Our website and app also process technical information needed to deliver pages and protect the service. Our Cookie Policy explains cookies, browser storage, and third-party resources in more detail.

When you connect Google Business Profile, RepBot stores the tokens and review data needed to sync reviews, generate responses, and publish approved replies.

Website visitors do not need an app account to read public pages. If you contact us through the website or by email, we process the details you choose to provide so we can handle your inquiry. Avoid including customer content or other sensitive information that is not needed for your request.

How we use information

We use your information to:

  • Provide RepBot and maintain secure sign-in sessions.
  • Process billing and send operational notifications.
  • Import reviews and generate AI-assisted response drafts.
  • Publish responses you have approved.
  • Respond to inquiries sent through our website.

We may use aggregate, de-identified usage data to improve reliability, product quality, and abuse prevention.

Website and app analytics

Ordinary marketing pages. We do not use Google Analytics or third-party audience-tracking tools on these pages. The separate free tool uses device recognition for abuse control as described below. Delivering pages, receiving inquiries, and loading resources such as Google Fonts still involves processing information.

App. We use PostHog to understand usage and diagnose reliability problems. It is configured in cookieless mode, but can still process page visits, interactions, performance information, and errors. The configuration includes click and heatmap collection and masking settings for session replay, which can reproduce a sequence of on-screen interactions for troubleshooting. Text, element attributes, and form inputs are configured to be masked in recordings. These settings are designed to limit the content included in recordings.

Service messages and your daily digest

The app can send an optional daily digest when responses from Profiles you can access are waiting for approval. This preference is enabled by default and can be changed in your User Profile for the relevant Workspace.

Turning off the digest does not turn off required service messages. Billing, security, legal, invitation, account, and required service notices, including low-credit alerts, are sent according to their purpose and the recipient's responsibilities. The digest setting does not control marketing communications from the website.

AI processing

To generate response drafts or removal assessments, we may send review text, business context, and Brand Rules to the AI providers configured for the service.

The app's response-generation service uses OpenAI. Depending on the request, the information sent can include a review's rating and text, a screened reviewer name, Brand Rules, and the previous response and instructions when regenerating a draft. RepBot does not submit review-removal requests on your behalf.

For publishing decisions, RepBot uses the text you approve as the source of truth.

Sharing and subprocessors

We share information only with service providers needed to operate RepBot. These include providers of hosting, authentication, billing, communications, analytics, and AI infrastructure.

We do not sell customer data.

Providers used by the app

Provider Role in the service
Cloudflare App hosting and request processing, email-code authentication, security checks, and outbound service email.
Neon Storage of application records in the app's database.
OpenAI AI-assisted response generation using the information described above.
Stripe Hosted payment processing and subscription billing.
PostHog App usage analytics, error diagnostics, and configured recording features.

Google Business Profile is a connected service you authorize for eligible Profiles. Google Fonts is described separately below. These services have their own terms and privacy information. This table describes the app's provider roles; it does not establish that every provider processes every category of information.

Google Fonts

Our marketing website uses Google Fonts to display text. Where fonts load directly from Google, your browser sends Google the request information needed to deliver them, including your IP address. This is separate from Google Analytics. Fonts served from our own website do not require a font request to Google.

Security and retention

We use access controls, encrypted connections, secure cookies, and integration tokens limited to their intended scope to protect information handled by RepBot.

We retain customer data while an account is active and as needed for legal, security, billing, and backup purposes.

Different records have different purposes and retention periods:

  • Reviews and account history: deactivating or archiving a Profile does not delete its history. Ending a paid plan is separate from an account-closure or personal-deletion request.
  • Google Business Profile connection tokens: when a Profile's Google access ends, we stop Google calls and disable its token. The disabled token is kept for 30 days to support short reactivation, with a warning seven days before removal. After 30 days, we revoke Google access and remove the local token. Eligible reactivation can reuse a valid token only after your confirmation; after removal, you must connect again.
  • Browser storage: session cookies and interface settings have the durations described in the Cookie Policy. Those durations do not determine how long server-side account records are retained.
  • Privacy-request records: records needed to handle and demonstrate completion of a privacy request can outlast the deleted account data. The app sets a three-year retention period when a privacy case reaches a terminal state, preserving any longer retention already required for related records.
  • Billing, security, and backup records: some information remains where needed for fraud prevention, tax, legal, security, or backup purposes.

Archiving a Profile does not start or restart the Google token retention period. A scheduled cancellation starts that period when the Profile's Google entitlement actually ends.

Your choices

You can update Workspace data, disconnect integrations, and manage team access. You can also contact support to request an export or deletion of your data.

These app controls depend on your role and permissions. Personal-data requests can be sent to our compliance email whether you are an app user or a website visitor. Describe the request and the relevant account or interaction so we can determine its scope and any identity verification needed.

Deleting your personal data, closing a Billing Account, leaving a Workspace, and canceling a subscription are different actions. A team member cannot use a personal-data request to assume ownership of another person's account or direct deletion of an entire Workspace. Workspace offboarding and related account-administration requests are handled by our support team.

Some records may need to be retained for fraud prevention, tax, legal, or security obligations.

Free review-response tool

Ordinary pages, the app, and the free tool

Ordinary marketing pages provide information about RepBot. The app provides signed-in review management and uses the account, billing, and PostHog processing described above. The free review-response tool is a separate feature: it processes your drafting inputs and additional device and network signals to help control abuse. Its device-identification flow does not run merely because you browse an ordinary marketing page.

Drafting inputs

The free tool processes the review text and star rating you submit, your selected tone, and any optional reviewer name or industry. These inputs are sent to OpenAI to generate response suggestions. Avoid including phone numbers, email addresses, links, or unnecessary personal information. Review and edit the suggestions before using them.

Additional data for abuse control

The tool uses Cloudflare Turnstile and device-recognition services to help prevent automated misuse and support free-usage controls. These checks begin when you interact with the response form and may run before you submit a review.

To prevent abuse and administer free-tool usage, RepBot and its service providers process device, browser, and network information. RepBot maintains pseudonymous records needed for these purposes and does not store raw device identifiers or IP addresses in its abuse-control records.

These extra signals support abuse prevention and free-tool usage controls, rather than advertising. They are separate from app analytics and account authentication.

Quality-review records

For quality assurance, we temporarily retain submitted content and generated suggestions for up to 10 days, after which they are deleted.

Retention and choices

The tool uses a visitor cookie as described in our Cookie Policy. Abuse-control records are retained only for as long as needed for abuse prevention and free-tool usage controls. Provider retention may be governed by their own policies.

You can choose not to interact with the tool, or clear its cookies and browser storage. Clearing storage does not necessarily prevent device recognition or remove provider-side records. For privacy requests, contact compliance and identify the tool and approximate time of use. Do not send device identifiers or sensitive review content in your initial message.

Contact us

For questions about this policy or to request a data export or deletion, contact us at the compliance email below.

Compliance email: [email protected]

Mailing Address:

RepBot.ai
584 Castro St Suite #4238
San Francisco, CA 94114

Related policies

Terms and Conditions Cookie Policy Security Policy
RepBot RepBot

RepBot provides Google review management, AI-assisted response drafts, and approval tools for businesses.

Explore Home Features Pricing
Resources Free Tools Blog
Your account Log in Sign up
© 2026 RepBot.ai.
Terms Privacy Cookie Policy Security