Privacy Policy

Last updated: 2026-07-21

1. Data controller and processor

For data you provide to us directly (contact form, website chat), the controller is FT1 (Szczecińska 48a, 80-392 Gdańsk, NIP 7582229163). Contact: [email protected].

For personal data contained in a serviced inbox, the customer is the controller and Replavo acts as a processor on their behalf. The data-processing agreement is concluded automatically upon accepting the Terms (section 8); details also on Trust & Security.

2. What data we collect

3. Google user data access (Gmail / Google Workspace)

When a customer connects Gmail or Google Workspace via OAuth, Replavo requests only the scopes needed to run the inbox assistant:

These two are the minimum scopes for this product. Replavo never modifies message state, never changes labels and never deletes mail, so gmail.modify is deliberately not requested. We no longer request the full https://mail.google.com/ scope: the product moved from IMAP/SMTP to the Gmail API precisely to run on least privilege.

Raw Google user data accessed: mailbox address; message metadata (from, to, subject, date, message IDs); full body of incoming messages that reach the connected inbox (to decide whether to reply); content of replies we send; OAuth tokens (refresh/access) stored encrypted for ongoing access.

Aggregated / operational data: minimal operational logs needed to run the service (e.g. sender address hashes or metadata for the “one auto-reply per sender” rule, reply timestamps, delivery status shown to the owner).

We do not request Drive, Contacts, Calendar, Docs, or other non-mail Google scopes. Access is limited to the single mailbox the customer chooses to connect.

4. How we use Google user data

We use Google user data only to provide or improve these user-facing features of Replavo. We do not use it for advertising, credit decisions, profiling for ads, or sale to data brokers.

5. Purpose and legal basis (GDPR)

6. Data transfer and recipients

We use trusted infrastructure providers:

Some data may be processed outside the European Economic Area (incl. the USA) under an adequacy decision (EU–US Data Privacy Framework) and standard contractual clauses (SCC). We do not sell Google user data. We do not transfer it to third parties for advertising or data-broker purposes. Transfers to Anthropic are solely to generate the reply for the connected customer’s business.

7. Data protection

8. Retention and deletion

Data from the contact form and website chat: for the time needed to handle the enquiry, no longer than 12 months. Data from a serviced inbox: enquiry content is processed on an ongoing basis to generate the reply; we store only the minimum needed to run the service (e.g. sender metadata for the “one reply per sender” rule and the reply log shown to the owner). Revoking inbox access stops processing immediately; after the contract ends we delete the customer’s service data within 30 days, unless the law requires longer retention (e.g. billing records). Step-by-step deletion instructions: How to delete your data.

9. Google Limited Use and AI/ML restrictions

The use of raw or derived user data received from Workspace APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

More detail: Trust & Security.

10. Your rights

You have the right to access, rectify, erase or restrict the processing of your data, to object, to data portability, and to lodge a complaint with a supervisory authority. For data matters write to [email protected].

11. Cookies

The site does not use cookies for tracking or analytics. We only use essential browser storage (e.g. remembering the demo access code).

Back to the homepage · Trust & Security · Data deletion