1. Scope and our roles
This Privacy Policy applies to the ReplyRoot website, dashboard, embeddable website widget, backend services, document-processing pipeline, Agent Inbox, authenticated Support workspace, analytics, notifications, and related support activities.
For account registration, website operation, product administration, security, and direct business communications, ReplyRoot generally decides why and how personal data is processed. For end-customer conversations and business content uploaded by a customer organization, the organization generally decides what information is collected and how the service is used, while ReplyRoot processes that information to provide the service. The exact legal roles may depend on the customer agreement and applicable law.
Customer organizations are responsible for providing any notices and obtaining any permissions required for the people whose information they submit to ReplyRoot.
2. Data we collect
Account and profile data
- First and last name.
- Email address.
- Password, which is stored as a one-way password hash rather than readable plain text.
- Account status, authentication tokens, session records, account timestamps, and the date and version of Terms acceptance and Privacy acknowledgement.
- Two-factor authentication configuration, recovery-code records, and related security events when these protections are enabled.
Organization and workspace data
- Organization name, workspace slug, and optional industry.
- Organization memberships and roles.
- Widget settings, including welcome text, brand color, active status, public widget key, and allowed website origins.
- Subscription status, plan information, usage counters, storage totals, and configured limits.
- Workspace analytics derived from conversations, messages, handoffs, resolutions, and response timing.
Uploaded knowledge and processing data
- Uploaded files and file metadata, including filename, type, size, status, and processing timestamps.
- Text extracted from documents.
- Document chunks and vector embeddings created to support semantic retrieval.
- Processing attempts and error details when a document cannot be processed.
Widget visitor and conversation data
- A browser-generated customer identifier and signed widget-session token.
- Messages sent by customers, AI responses, and agent replies.
- Conversation channel, creation and activity times, AI or human control state, handoff reason, closure time, closure reason, and the agent who closed a case.
- IP address used temporarily as part of public-widget abuse and rate-limit controls.
Technical and support data
- Request metadata, server logs, timestamps, error details, and security events.
- Authenticated support requests, categories, priorities, replies, status changes, and the account and organization connected to the request.
- Contact requests, including name, business name, work email, optional phone or website, and the message submitted through the public form.
- Operational and in-app notification records, delivery status, and recipient information.
Please do not upload secrets, passwords, payment-card details, health information, government identifiers, or other highly sensitive personal data unless the use is lawful, necessary, and expressly supported by a written agreement with appropriate safeguards.
3. How we use data
We use data to:
- Create, authenticate, and administer accounts and organizations, including two-factor authentication, session security, and recording policy acceptance versions.
- Receive and respond to founding-customer walkthrough and contact requests.
- Store, validate, extract, process, chunk, embed, retrieve, and delete uploaded knowledge.
- Operate website widgets and preserve visitor sessions and conversation history.
- Generate knowledge-grounded AI responses and route conversations to human agents.
- Provide Agent Inbox controls, human takeover, AI resumption, and conversation closure.
- Measure workspace performance, administer subscriptions, enforce organization limits, prevent abuse, and protect system reliability.
- Receive and manage authenticated support requests and send related email or in-app notifications.
- Diagnose errors, investigate security incidents, improve the service, and provide support.
- Comply with legal obligations and enforce our Terms and Acceptable Use Policy.
We do not use customer-uploaded knowledge or private conversations for public advertising. We do not sell personal data.
4. AI processing and service providers
ReplyRoot uses configured AI and infrastructure providers to deliver parts of the service. Relevant conversation text, recent chat history, system instructions, and selected excerpts from uploaded business knowledge may be sent to an external language-model provider to generate or classify a response. Infrastructure providers may process data for hosting, database, file storage, queues, monitoring, email, or similar operational services when those services are configured.
Embeddings are generated using the configured embedding model. Depending on deployment configuration, models may be downloaded from a model provider and then run within ReplyRoot infrastructure. Customers should review the applicable customer agreement and deployment details before submitting regulated or confidential information.
AI output can be incomplete, inaccurate, or inappropriate. Customer organizations remain responsible for reviewing their business knowledge, configuring escalation behavior, supervising agents, and deciding whether an AI-generated response is suitable for their customers.
5. Browser storage, tokens, and logs
The dashboard stores an access token in browser local storage so the user can remain authenticated during a session. The website widget stores a signed widget-session token and browser-generated customer identifier in local storage so a visitor can continue the same support case after refreshing or returning to the page.
These values are necessary for current product functionality. Users can remove them by signing out, clearing browser storage, or using the widget's reset or new-conversation behavior where available.
The current public website does not intentionally use advertising cookies or third-party advertising trackers. Hosting, reverse-proxy, security, or monitoring providers may still create ordinary technical logs when those services are deployed.
6. Legal bases where applicable
Where data-protection law requires a legal basis, processing may rely on one or more of the following:
- Performance of a contract or steps requested before entering a contract.
- Legitimate interests in operating, securing, improving, and supporting ReplyRoot, balanced against individual rights.
- Consent, where consent is requested and can be withdrawn.
- Compliance with legal obligations or protection of legal rights.
Customer organizations are responsible for identifying an appropriate legal basis for the end-customer and employee data they submit or cause ReplyRoot to process.
8. Retention and deletion
ReplyRoot keeps personal data for as long as reasonably necessary to provide the service, maintain security and audit history, resolve disputes, enforce agreements, and meet legal obligations.
- Uploaded documents remain until an authorized workspace user deletes them or the organization is deleted.
- Deleting a document removes its active stored file and associated processed content from the product database, subject to any temporary operational copies or backups used in production.
- Conversation history remains available to the customer organization after a case is closed so the organization can review support history.
- Usage records may be retained to maintain monthly accounting, limits, security, and audit integrity.
- Temporary rate-limit records expire automatically after the configured rate-limit window.
The current pre-launch product does not provide self-service deletion of a complete user account or organization. Requests for access, correction, export, or deletion must be handled manually through the legal contact. A formal production retention schedule, backup-retention period, and account-deletion procedure must be finalized before launch.
9. Security
ReplyRoot uses safeguards including password hashing, signed authentication tokens, organization-scoped authorization, origin restrictions, input and upload validation, transaction controls, rate limiting, generated storage names, and tenant-isolation tests. No system can be guaranteed completely secure or continuously available.
Customers must protect account credentials, enable available account protections, limit access to trusted personnel, configure allowed widget origins, review uploaded content, and promptly report suspected compromise. ReplyRoot has completed dedicated authentication, authorization, API, upload, AI, dependency, monitoring, backup, restore, and production-simulation hardening. Security review continues through deployment and release gates.
10. Privacy rights and choices
Depending on location and applicable law, individuals may have rights to request access, correction, deletion, restriction, objection, portability, or withdrawal of consent, and may have the right to complain to a data-protection authority.
End customers who used a widget should normally contact the organization whose website displayed the widget, because that organization controls the customer relationship and can identify the relevant conversation. ReplyRoot will assist customer organizations with appropriate requests as required by the applicable agreement and law.
We may need to verify identity and authority before completing a request. Some data may be retained where required for security, legal compliance, fraud prevention, or establishment and defense of legal claims.
11. Children
ReplyRoot is a business service and is not directed to children. Customer organizations must not knowingly use the service to collect children's personal data unless they have a lawful basis, appropriate notices and permissions, and a written agreement that expressly supports that use.
12. Changes to this policy
We may update this policy when the product, providers, legal requirements, or business practices change. The page will show the updated date. Material changes may also be communicated through the dashboard, email, or customer agreement where appropriate.
Contact
Questions, legal notices, and privacy requests should be sent to ReplyRoot.
Email: support@replyroot.com
Business address: Benghazi, Libya