Legal
Privacy Policy
Reply Pilots (“Reply Pilots”, “we”, “us”) provides a Chrome extension and a web app (app.reply-pilots.com) that help you draft replies, DMs and posts in your own voice on social platforms. This policy explains what we collect, where it goes, and how long we keep it. It covers both the extension and the web app.
1. What the extension reads — and when
The extension does nothing until you open it on a post or message and ask for a draft. At that moment it reads:
- the text of the post or message you’re replying to, and
- the comments or message turns already visible on your screen,
so the AI can write a reply that fits the conversation. That content is sent to our web app for that single request and passed to the AI provider that generates the draft. The reply assistant runs only on the platforms we support — Facebook, Instagram, Threads, LinkedIn, X, Reddit, and Gmail for email replies.
On every other site, the only part of the extension that runs is the highlight tool: select some text, click Summary or Explain, and that selection is sent for that one request. Nothing is read or sent from a page you haven’t acted on.
One feature works without a click, and we want to be straight about it. When you are viewing a Facebook or LinkedIn group or page that you follow, the extension reads the posts already rendered on your screen — their text, the author name, and the public like, comment and share counts — and sends them to your account so the planner can rank which of your sources actually perform. It runs only on group and page addresses, never on your home feed, on profiles, or in your inbox. It reads only what is already on your screen and never scrolls or fetches to load more. It stops the moment you switch Reply Pilots off for that site, or sign out.
Beyond that, the extension does not crawl or fetch pages you haven’t opened, log into accounts, or read anything in the background. You can switch it off on any site at any time, and it never posts anything — every message is sent by you, by hand.
2. Information you give us
- Account — your email address and, optionally, your name; a hashed password; your sign-in sessions.
- Business context — the details you choose to add about your business, and links to social accounts or pages you follow. These are stored as text you enter; we do not fetch or crawl them.
- Your content — the prompts you run and the drafts the AI returns (your history / library), saved prompts, and planner posts.
- Settings — platform, model and notification preferences, and, if you add one, your own AI provider key. Provider keys are encrypted at rest, are never returned by any endpoint, and are never shipped in the extension.
- Billing — records of credits and any payment an administrator records on your account. We do not process card payments and store no card numbers.
3. Information collected automatically
- Technical data needed to run and secure the service: IP address and browser / user-agent (for your sessions and abuse prevention), and a periodic “the extension is connected” heartbeat.
- Posts from groups and pages you follow, as described in section 1 — captured on Facebook and LinkedIn to rank sources for your planner.
- Stored in your browser, not sent to us — the extension keeps your sign-in token, your reply preferences and your per-site off switches in Chrome’s local extension storage. Uninstalling the extension removes them.
- Website analytics — our marketing site (reply-pilots.com) uses Google Tag Manager / Google Analytics cookies to understand traffic. The web app itself is not an advertising surface.
4. Where your data goes
We share data only with the providers needed to run the service:
- AI provider — to generate your drafts. By default this is OpenRouter, which routes your request to the underlying model. If you add your own key (OpenAI, Anthropic, Google or OpenRouter), your requests go to that provider instead and are billed to you. No provider key is ever included in the extension.
- Hosting & infrastructure — our self-hosted servers and databases (PostgreSQL, Redis, Neo4j).
- Email — an SMTP provider, for transactional email such as address verification and password resets.
- Analytics — Google, for the marketing site as described above.
We do not sell your personal information, and we do not share it for advertising. We do not use the content you send us to train our own models; any handling by the AI provider is governed by that provider’s terms.
5. How long we keep it
- Account data — until you delete your account.
- Your history, drafts and planner posts — until you delete them, or until your workspace’s retention window elapses. Your workspace owner can set how long generations and planner posts are kept, and a daily job removes anything past that window.
- Content read for a draft — processed for that request and stored only as part of your history above; its handling by the AI provider follows that provider’s retention terms.
- Posts captured for the planner — kept with your planner data and removed on the same retention schedule, when you delete them, or when you delete your account.
- Security logs and sessions — kept for a limited period, then expired.
6. Your choices and rights
- View and export your history (CSV export is built in) and delete individual items.
- Remove your own AI provider key at any time; deletion takes effect on your next run.
- Request access to, or deletion of, your account data by contacting us. Depending on where you live you may have additional rights (access, correction, deletion, portability, objection); we honour these requests.
- Turn the extension off per site, or uninstall it, at any time.
7. Cookies
The web app uses a strictly-necessary session cookie to keep you signed in. The marketing site uses analytics cookies as described in section 3.
8. Children
Reply Pilots is a business tool and is not directed to children. Do not use it if you are under 18.
9. Changes to this policy
We’ll post any changes on this page and update the date above. Significant changes will be highlighted.
10. Contact
Questions about privacy, or a data request? Reach us through our contact page, or email [email protected].