Privacy Policy
Effective September 1, 2026
1reply is the AI front desk for app businesses. Running it means handling personal information — our customers’, and their customers’. This policy explains what we collect, what we do with it, who we share it with, and the choices you have. We have tried to write it the way we write everything else: plainly, and without claiming more than we do.
Every numbered section opens with an “IN SHORT” summary. The summaries are aids to comprehension only — the full text of each section governs.
01 / 14
Who We Are & What This Covers
In short
We are Reev Tech Inc., an Ontario, Canada company operating as 1reply. This policy covers 1reply.app, app.1reply.app, and the 1reply service.
1reply is operated by Reev Tech Inc., a corporation formed in Ontario, Canada (“Reev Tech,” “we,” “us,” “our”). When we say “1reply” or “the service,” we mean the AI front desk we provide to app businesses: App Store and Google Play review ingestion with AI-drafted replies, daily digests, and — as they become available — the voice agent and verified billing actions described below.
This policy applies to our websites at 1reply.app and app.1reply.app and to the service itself. It takes effect on the date at the top. If we change it in a way that matters, section 14 explains how you will hear about it first.
02 / 14
The Two Roles We Play
In short
For the account, billing, and usage data of the businesses that sign up, we decide how and why processing happens — we are the controller. For the data those businesses run through the service (their reviews and, when enabled, their calls), we act only on their instructions — we are a processor. If you are a customer of a business that uses 1reply, that business’s privacy notice is the one that governs.
We handle personal information in two different capacities, and what we may do with it — and who answers to you for it — depends on which one applies.
As a controller. For the businesses that sign up for 1reply (“tenants”), we decide how and why to process account, billing, and usage information. Section 4 describes that data, and most of the rest of this policy applies to it.
As a processor. For the people who interact with a tenant — someone who reviewed the tenant’s app or, where the tenant enables the voice agent, someone who calls its support line (“end users”) — we process personal information only on the tenant’s documented instructions, to operate the service for it. We take no decisions of our own about that data and use it for no purpose of our own.
If you are an end user, the app business you dealt with is responsible for your personal information, and its privacy notice — not this one — tells you how it is used. If you send us a request about your data, we will direct it to the relevant tenant and assist the tenant in answering it.
03 / 14
Privacy Officer
In short
Our privacy officer is reachable at hello@1reply.app. Questions, requests, and complaints about personal information all go there.
The person in charge of the protection of personal information at our company is: Privacy Officer, Reev Tech Inc. — hello@1reply.app.
Write to that address for anything in this policy: questions, access or deletion requests, complaints. We aim to acknowledge within a few business days and to respond substantively within 30 days. If our response does not resolve a complaint, section 13 lists the regulators you can escalate to.
04 / 14
What We Collect as a Controller
In short
Your name and email from Google or Apple sign-in, your workspace configuration, billing records through Stripe (we never see card numbers), and technical logs of how the service is used.
When you create and use a 1reply account, we collect:
- Account information. Your name and email address, passed to us by Google or Apple when you sign in (sign-in runs on Google Firebase). We do not operate our own password system.
- Workspace configuration. The apps you connect, the caps, rules, and digest settings you choose, and the teammates you add.
- Billing information. Subscriptions are billed through Stripe, our payment processor. We receive subscription status, invoices, and card metadata such as brand and last four digits; the integration is designed so cardholder data — full card numbers, CVV — never reaches us.
- Usage and technical data. Logs of actions taken in the product, browser and device information, IP addresses, and diagnostic events.
We use this information to provide, bill for, secure, and improve the service, to communicate with you about it, and to meet legal obligations. We do not use it for third-party advertising.
05 / 14
What We Process for Tenants
In short
On a tenant’s instructions we process its app-store reviews, the knowledge base it uploads, and — where it enables the voice agent — call recordings, transcripts, and limited Stripe billing details. We use this data to run the service for that tenant, and for nothing else.
Acting as a processor on a tenant’s instructions, we handle:
- App-store review content. The text, rating, author display name, and metadata of reviews from the App Store and Google Play. Reviews are public, but public does not mean unprotected: review content can identify a person, and we treat it as personal information.
- Knowledge-base content. Documents, policies, and answers the tenant uploads so that replies are accurate.
- Call audio, recordings, and transcripts — only where the tenant enables the voice agent, a designed feature that is not yet live. Until a tenant enables it, no call data exists in the service.
- Limited Stripe metadata. Where the tenant connects its Stripe account: an end user’s email address, card last four digits, and charge amounts, read to verify a caller and to execute actions the tenant has authorized.
We process this data strictly to: draft and post review replies, answer calls, execute the billing actions a tenant has authorized (refunds and cancellations within tenant-set caps), produce digests, and maintain the audit log. Nothing else — no advertising, no profiling for our own purposes, no resale.
06 / 14
AI Processing
In short
Drafting runs on Anthropic’s Claude models. We send review text, knowledge-base snippets, and — when live — call transcripts for inference. Neither we nor Anthropic trains models on this data, and Anthropic retains API inputs for about 30 days for abuse prevention.
The service’s drafting and conversational abilities run on Claude models from Anthropic, via Anthropic’s commercial API. To draft a reply or hold a conversation, we send the relevant review text, snippets of the tenant’s knowledge base, and — once the voice agent is live — call transcripts to Anthropic for inference.
We do not use tenant or end-user personal information to train AI models. Under the commercial terms we use, Anthropic does not train its models on our API inputs or outputs either. Anthropic retains API inputs and outputs for approximately 30 days to detect and prevent abuse, and longer only where content has been flagged for abuse. We deliberately do not claim “zero retention,” because that is not how the provider works.
What the AI produces is reviewed according to each tenant’s configuration: by default, every drafted reply waits in an approval queue for a human decision, and tenants may enable narrow rules — for example, auto-sending thank-yous for five-star reviews.
07 / 14
Calls & the Voice Agent
In short
The voice agent is not live yet. Where a tenant enables it, every call will open with a notice that the line is recorded and answered by AI — a notice the tenant cannot turn off. A human path is always available, and we never use voice biometrics.
This section applies where a tenant enables the voice agent. The voice agent is a designed feature that is not yet live: today, 1reply answers no calls and records none.
Where a tenant enables it: every call will open with a standardized disclosure that the line is recorded and that the caller is speaking with an AI agent. Tenants cannot remove or weaken this disclosure. A path to a human is always available — a caller can ask for a person at any point, and the agent will escalate.
Where a caller asks for a billing action, verification uses the email address on the Stripe customer record, the card’s last four digits, and a one-time code. We do not use voice biometrics. No one is identified by voiceprint or any other biometric characteristic, and we do not build voice profiles.
If a caller does not want to be recorded, they can end the call and use the alternative contact channel the tenant provides — our terms require every tenant that enables the voice agent to offer one.
08 / 14
Automated Actions
In short
The service can execute refunds and subscription cancellations, but only inside caps the tenant sets, and every action lands in the audit log. Anyone affected by an automated action can get a human review of it through the tenant.
Where a tenant authorizes it, the service executes billing actions — refunds to the original payment method and subscription cancellations — through the tenant’s connected Stripe account. These actions run only within the caps and rules the tenant configures. Anything outside them is not executed; it is escalated to a human at the tenant.
Every executed action is recorded in the audit log: what was done, when, for whom, and under which policy. The log is kept for 24 months, and the tenant can export it at any time (section 11).
If you are an end user affected by an automated action — a refund decision, a cancellation — you can ask for a human review. Contact the app business you dealt with: the action ran on its configuration and on its behalf, and it is responsible for reviewing the decision. We assist the tenant with that review, including by providing the relevant audit-log entries.
09 / 14
Sharing & Subprocessors
In short
We do not sell personal information and do not share it for advertising. Seven providers run parts of 1reply — the table below lists each one, what it does, and where it processes data. Existing tenants get 30 days’ email notice before we add one.
We do not sell personal information, and we do not share it for cross-context behavioural advertising. Personal information leaves our hands in exactly three cases: the service providers below, a legal demand we are required to comply with, or a corporate transaction (such as a merger or acquisition) in which the data remains protected by this policy.
These are our subprocessors — the providers that host and power the service. Each processes personal information only to provide its function to us, under a data processing agreement:
| Subprocessor | Function | Region |
|---|---|---|
| Cloudflare | Edge compute, queues, object storage | Global / US |
| Amazon Web Services | Postgres database | US (us-east-1) |
| Vercel | Web hosting | US |
| Google Firebase | Sign-in via Google or Apple | US |
| Stripe | Our billing, and actions on tenant-connected Stripe accounts | US |
| Anthropic | AI inference (Claude API) | US |
| Resend | Email delivery | US |
We give existing tenants at least 30 days’ notice by email before adding a subprocessor.
10 / 14
International Transfers
In short
We operate from Canada, but the service runs on infrastructure in the United States. Personal information handled by 1reply is processed outside Quebec and outside Canada, under contracts with each provider.
We operate from Ontario, Canada. The service’s infrastructure — including our database, hosted with AWS in the US (us-east-1) — and the subprocessors in section 9 are located in the United States. Personal information handled by the service is therefore communicated outside Quebec and outside Canada, and while it is there it is subject to the laws of those jurisdictions, which may allow access by courts and authorities under conditions that differ from Canadian law.
Before adopting each provider, we considered the sensitivity of the data involved and the protections available. Each provider processes personal information under a data processing agreement with confidentiality and security obligations. For tenants with users in Europe: Canada holds a European Commission adequacy decision for organizations subject to PIPEDA, reconfirmed in 2024, and our subprocessors’ data processing agreements incorporate standard contractual clauses for their onward transfers. We will not dress this up further than it deserves: your data is processed in the United States by well-known providers, under contract.
11 / 14
Retention & Deletion
In short
Account data lives as long as the account. The audit log is kept 24 months and is exportable. Deletion is by verified email request — there is no self-serve deletion yet — completed within 30 days, plus up to 7 more days for encrypted backups to expire.
We keep personal information only as long as the purpose it serves:
| Data | How long |
|---|---|
| Account and workspace data | Life of the account |
| Tenant content we process (reviews, knowledge bases, and — when live — call recordings and transcripts) | Life of the account, or earlier on the tenant’s instruction |
| Audit log | 24 months; exportable by the tenant at any time |
| Billing records | As long as tax and accounting law requires |
| Copies at our AI provider | About 30 days at Anthropic, for abuse prevention (longer only if flagged) |
There is no self-serve deletion in the product yet — we would rather say that plainly than imply a button that does not exist. To delete your account or your data, email a request to hello@1reply.app. We verify it (normally by confirming you control the account’s email address) and complete deletion within 30 days; residual copies in encrypted backups expire within a further 7 days.
12 / 14
Security
In short
Encryption in transit and at rest, tenant-scoped access controls, least-privilege infrastructure access, and secrets kept out of logs. If a breach creates a real risk of significant harm, we notify you and the regulator.
We protect personal information with measures we actually run, and we will not pad this list:
- Encryption in transit (TLS) and encryption at rest.
- Tenant-scoped access controls in the application layer, so one tenant’s data is not reachable from another’s workspace.
- Secrets kept out of logs and error messages.
- Principle-of-least-privilege access to infrastructure for the people who operate the service.
We do not claim any security certification, because we hold none. If a breach of our safeguards creates a real risk of significant harm, we will report it to the Office of the Privacy Commissioner of Canada, notify the affected individuals and tenants without undue delay — so tenants can meet their own obligations — and keep the records of the breach that the law requires.
13 / 14
Your Rights
In short
You can request access, correction, a portable copy, or deletion, withdraw consent, and complain — to us first, then to the federal or Quebec regulator. If you are a customer of a business that uses 1reply, start with that business; we will help it respond.
Under PIPEDA and Quebec’s Law 25, you can:
- Access the personal information we hold about you, and learn how it has been used and to whom it has been disclosed.
- Correct information that is inaccurate or incomplete.
- Receive a copy of computerized personal information you provided to us, in a structured, commonly used technological format.
- Withdraw consent to processing, subject to legal and contractual limits — withdrawing consent essential to running the service may mean closing the account.
- Complain — first to our privacy officer (section 3), and if we do not resolve it, to the Office of the Privacy Commissioner of Canada or, in Quebec, the Commission d’accès à l’information.
To exercise any of these, email hello@1reply.app. We verify requests — normally by confirming you control the relevant email address — and respond within 30 days.
In the United States. We are honest about where we stand: we are not currently a “business” covered by the California Consumer Privacy Act. Where we process personal information for a tenant that is covered, we act as that tenant’s service provider and support its compliance.
In Europe. Where a tenant has end users in the EU or UK, their GDPR rights run through the tenant, which is the controller of their data; we support the tenant as its processor. Requests we receive directly from end users are passed to the tenant, as section 2 describes.
14 / 14
Children, Changes & Contact
In short
1reply is business software and not directed to children. Material changes to this policy are announced to existing tenants at least 30 days before they take effect. Contact: hello@1reply.app.
The service is built for businesses and is not directed to children. We do not knowingly collect children’s personal information, and our terms prohibit using the service for child-directed apps or phone lines. If we learn we have collected a child’s personal information, we will delete it.
We will update this policy as the service evolves. Material changes are announced to existing tenants by email at least 30 days before they take effect; the effective date at the top always tells you which version you are reading.
Questions, requests, and complaints: Privacy Officer, Reev Tech Inc. — hello@1reply.app. Reev Tech Inc. operates as 1reply from Ontario, Canada.