Privacy Policy

Last Updated: August 16, 2026

Effective Date: August 16, 2026

Table of Contents

1. Introduction

ReplyPilot is self-hosted email and review reply-management software provided by Waldok Solutions LLC ("Waldok Solutions," "we," "our," or "us"). This Privacy Policy explains how information is handled by this ReplyPilot installation. The organization operating a self-hosted installation controls its server, database, connected services, users, and retention settings.

By using ReplyPilot, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies and practices, please do not use our service.

2. Information We Collect

2.1 Information You Provide

We collect information that you directly provide to us:

  • Account Information: Name, email address, password hash, role, and tenant membership created or managed by an authorized administrator
  • Connected Account Credentials: Encrypted Google OAuth tokens and encrypted SMTP/IMAP credentials when those connections are configured
  • Business Information: Organization name, business knowledge, reply preferences, and workflow settings
  • Communication Data: Messages, feedback, and correspondence with our support team

2.2 Information Collected Automatically

  • Operational Data: Ingestion attempts, queue and agent status, audit events, and feature settings
  • Request Information: IP address, browser information, and timestamps may be processed by the web server or security middleware
  • Error Data: Sanitized error details and performance information needed to diagnose and secure the installation

2.3 Email and Review Data

When you connect your email accounts or Google Business Profile, we collect:

  • Email Content: Subject lines, message bodies, and metadata for AI processing
  • Review Data: Google Business Profile locations, customer reviews, ratings, and reviewer information made available by Google
  • Draft and Response History: AI-assisted drafts, edits, approvals, and sent or posted status

3. How We Use Your Information

We use the information we collect for the following purposes:

3.1 Service Provision

  • Generate AI-assisted email and review reply drafts
  • Manage and respond to customer reviews
  • Fetch and organize your email inbox
  • Provide analytics and insights on communications
  • Send or post replies only after an authorized user approves the final content

3.2 Service Improvement

  • Analyze usage patterns to improve features
  • Develop new features and functionality
  • Improve user-facing prompts and drafting workflows without training generalized AI models on Google user data
  • Fix bugs and technical issues

3.3 Communication

  • Send service updates and notifications
  • Respond to your inquiries and support requests
  • Send important security alerts

4. Email Data Usage

ReplyPilot connects to your email accounts to provide AI-powered response management. Here's how we handle your email data:

4.1 What We Access

  • Email Content: To display conversations, classify messages, and generate draft replies
  • Email Metadata: Sender, recipient, subject, and timestamps
  • Attachment Information: File names, types, sizes, and available text context when supplied by the connected provider

4.2 What We Don't Do

  • We do NOT sell your email data to third parties
  • We do NOT use your emails for advertising purposes
  • We do NOT disclose email content except to operate requested features, the configured AI provider, infrastructure selected by the operator, or as legally required
  • We do NOT write full email or review bodies to application logs

4.3 Data Storage

Google OAuth tokens and SMTP/IMAP passwords are encrypted by the application before database storage. Email and review records are stored in the installation's database so authorized users can manage the workflow. Database, disk, backup, and hosting security remain the responsibility of the installation operator.

4.4 Google API Data

ReplyPilot uses Google API data only to provide and secure the user-facing Gmail and Google Business Profile features you authorize. We do not sell Google user data, use it for advertising, or use it to train or improve generalized AI models.

ReplyPilot's use of information received from Google Workspace APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

5. AI Service Providers

ReplyPilot sends relevant content to the AI provider selected and configured by the installation operator when an AI feature runs. Supported providers include:

  • OpenAI: Optional AI provider
  • Google Gemini: Optional AI provider
  • Anthropic: Optional AI provider

These providers process your content generation requests according to their own privacy policies. We recommend reviewing:

6. Data Sharing and Disclosure

ReplyPilot does not sell personal information. The installation operator determines and controls the service providers used with its deployment. Information may be disclosed only in the following circumstances:

6.1 Service Providers

  • The AI provider selected by the installation operator
  • Hosting, backup, security, and infrastructure providers selected by the installation operator
  • Google, Gmail, SMTP/IMAP, and notification-email providers used for requested features

6.2 Legal Requirements

We may disclose your information if required by law or in response to:

  • Valid legal processes (subpoenas, court orders)
  • Government or regulatory requests
  • Protection of our rights, privacy, safety, or property
  • Emergency situations involving safety risks

6.3 Business Transfers

In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity.

7. Data Security

ReplyPilot provides application-level safeguards, while the installation operator is responsible for secure hosting, deployment, backups, and administrator access:

7.1 Technical Safeguards

  • Transport Security: HTTPS/TLS when correctly configured by the installation operator
  • Credential Protection: Application encryption for OAuth tokens and mailbox passwords
  • Password Security: One-way password hashing
  • Access Control: Role-based access restrictions
  • Tenant Isolation: Application scopes and authorization checks separate tenant data

7.2 Operational Safeguards

  • Regular security audits and updates
  • Monitoring for suspicious activity
  • Secure development practices
  • Administrator-controlled access to personal data

Note: While we implement robust security measures, no method of transmission over the internet is 100% secure. We cannot guarantee absolute security of your information.

8. Data Retention

Retention is controlled by the installation operator and its ReplyPilot settings:

  • Account Data: Retained until an authorized administrator removes the account, subject to recovery and legal requirements
  • Email Data: Subject to the configurable email-retention period, which defaults to 24 hours
  • Reviews, Drafts, and Agent Records: Retained until removed through administrator cleanup settings or applicable scheduled cleanup
  • Soft-Deleted Records: Subject to the configured purge window, which defaults to 30 days
  • Server Logs and Backups: Controlled by the installation operator and hosting provider

Disconnecting Google or a mailbox stops future provider access but does not by itself remove records already stored locally. Contact the installation administrator to request local deletion.

9. Your Rights

You have the following rights regarding your personal information:

9.1 Access and Portability

  • Request access to personal data held by the installation operator
  • Request a copy where required by applicable law and technically available

9.2 Correction and Deletion

  • Update or correct your account information
  • Request deletion of eligible local records
  • Request account deletion, subject to administrator authority and legal retention obligations

9.3 Control and Objection

  • Disconnect email accounts at any time
  • Choose your preferred AI provider
  • Opt-out of non-essential communications

To exercise these rights, please contact us at support@waldoksolutions.com.

10. Cookies and Tracking

ReplyPilot uses essential first-party cookies needed for:

  • Essential Cookies: Authentication, security, and session management
  • Functional Cookies: Remember your preferences and settings

ReplyPilot does not include advertising cookies or third-party behavioral analytics by default. An installation operator that adds separate analytics is responsible for providing any additional notice or consent required.

You can control cookies through your browser settings. However, disabling essential cookies may affect service functionality.

11. Children's Privacy

ReplyPilot is not intended for users under the age of 13. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected information from a child under 13, please contact us immediately at support@waldoksolutions.com.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of any material changes by:

  • Posting the updated policy on this page
  • Updating the "Last Updated" date at the top
  • Sending you an email notification (for significant changes)

Your continued use of ReplyPilot after changes indicates your acceptance of the updated Privacy Policy.

13. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

ReplyPilot Privacy Team

Email: support@waldoksolutions.com

Response times vary based on the nature and complexity of the request.

Your Privacy Matters

ReplyPilot is committed to transparency and protecting your privacy. We believe in:

  • Collecting only necessary data
  • Using your data solely for providing our service
  • Never selling your personal information
  • Implementing strong security measures
  • Respecting your rights and choices
Back to Top