Privacy Policy
Last updated: September 2026 · Applies to Replai for Android
1. Who We Are (Data Controller)
Replai is operated by Elena Marinescu, an independent developer based in Romania, who is the data controller responsible for your personal data. For all privacy matters, contact us at replaiengl@gmail.com. We operate under EU law, including the General Data Protection Regulation (GDPR) (EU) 2016/679.
2. Age Requirement
Replai is not intended for users under 16 years of age in the European Economic Area, or under 13 elsewhere. If you are below the applicable minimum age, do not use this app. If we become aware that a child below the minimum age has provided data, we will delete it immediately.
3. What We Collect, Why, and Our Legal Basis
GDPR Article 6 requires us to have a legal basis for processing your data. The table below sets out each type of data we collect, its purpose, and the legal basis we rely on.
| Data | Purpose | Legal Basis (Art. 6 GDPR) | Stored Where |
|---|---|---|---|
| Google account email and user ID — your Google email address and Google account sub-identifier, obtained during Google Sign-In | Create and identify your Replai account; tie your subscription, Style DNA, and contacts to a stable, cross-device identity | Contract performance Art. 6(1)(b) | Stored by Supabase Auth (EU, Ireland) as part of your account record. Deleted when you delete your account. |
| Style DNA — writing style traits derived from your onboarding answers | Personalise reply suggestions to sound like you | Contract performance Art. 6(1)(b) | On-device only — cloud sync is not currently offered. |
| Contact profiles — contact names, relationship labels, persona settings, style notes, and previous name aliases you assign | Contextualise replies per contact; remember preferences across sessions | Contract performance Art. 6(1)(b) | On-device only — cloud sync is not currently offered. Removed when you uninstall or use Delete Account; individual contacts can be deleted in-app. |
| Conversation snippets — the visible portion of a conversation, including messages you received from the other person. The other person's name is included only if you have explicitly saved that contact in Replai; otherwise a relationship label (e.g. "Friend") is used so the AI can match tone without receiving the third party's real name. | Generate reply suggestions via AI. The other person's messages are necessary context — without them the AI cannot suggest a relevant reply. | Contract performance Art. 6(1)(b) for your own data; Legitimate interest Art. 6(1)(f) for the other party's messages — used solely to generate your reply, never for profiling or any other purpose. | Transmitted to Supabase edge function, forwarded to AI provider (OpenAI or Groq), then immediately discarded. Never logged or stored by Replai. Neither AI provider retains API input data for training under their API terms. |
| Sent message samples — up to 40 of your own sent messages, extracted from scanned conversations (Pro/Max only) | Analyse your writing style to generate a personalised Style DNA automatically | Contract performance Art. 6(1)(b) | Transmitted to Supabase edge function for analysis, then immediately discarded. The resulting Style DNA string (not the messages themselves) is saved on-device only. |
| Reply history — generated reply suggestions, associated contact name, app name, and persona | Display your history of generated replies in the app's History tab | Contract performance Art. 6(1)(b) | On-device only. Capped at 100 entries. Cleared via Settings → Clear History or Settings → Delete Account. Never uploaded. |
| Saved conversation context — recent messages with a saved contact, kept as relationship background | Give the AI the background of your relationship with that contact so replies stay consistent over time; a short excerpt is included with your next reply requests as context | Contract performance Art. 6(1)(b) | On-device only, automatically deleted after 30 days (or when you uninstall or use Delete Account). The excerpt sent with a request is discarded server-side immediately after generation. |
| Sent reply samples — the app keeps up to 10 recent replies you chose to send, per contact; up to 6 are included with a request | Match the voice you actually use with that specific person | Contract performance Art. 6(1)(b) | On-device; transiently included in AI requests and discarded server-side after generation — never stored by our servers. |
| Notification content — sender name, app, and the incoming message text | Detect who you are replying to without manual input | Consent Art. 6(1)(a) — you explicitly grant Notification Access in Android Settings | Sender/app data processed on-device; in Live mode (Max) the incoming message text is sent to the AI to draft a reply, then discarded — never stored by Replai. |
| Screen content (OCR) — a screenshot you trigger, read via OCR | Read chat messages without copy-paste (Pro/Max feature) | Consent Art. 6(1)(a) — you explicitly grant Screen Capture permission | The screenshot is processed on-device by ML Kit and the image never leaves your device; the extracted text becomes the conversation snippet above and is sent to the AI to generate your reply, then discarded. The screenshot image is never stored or transmitted. |
| Anonymous device identifier — a random UUID generated at first launch (Supabase anonymous auth) | Server-side enforcement of usage limits; spam and abuse prevention | Legitimate interest Art. 6(1)(f) — necessary to run a fair, sustainable service | Supabase (EU, Ireland). Not linked to your name, email, or any personal identifier. |
| Daily reply count — number of AI replies generated per calendar day, per user | Enforce usage limits server-side to prevent abuse; ensure fair access for all users across all subscription tiers | Legitimate interest Art. 6(1)(f) | Supabase database (EU, Ireland). Automatically deleted after 365 days (data minimisation, Art. 5(1)(e) GDPR). |
| Rate-limit window counters — request counts per user per endpoint per minute/hour | Prevent spam and denial-of-service abuse of AI endpoints; protect service availability for all users | Legitimate interest Art. 6(1)(f) | Supabase database (EU, Ireland). Automatically deleted after 2 hours — kept only as long as necessary for the rate-limit window. |
| Queue position data — pseudonymous user ID and timestamps while you wait in line during periods of high demand | Fair, first-come-first-served access to AI reply generation when the service is at capacity (free tier) | Legitimate interest Art. 6(1)(f) | Supabase database (EU, Ireland). Deleted the moment your request is served, or within minutes if you stop waiting — never kept longer than ~10 minutes. |
| Verified subscription record — Google Play purchase token (hashed), product ID, tier, and expiry date | Server-side verification of subscription status with Google; prevent unauthorised access to paid features | Contract performance Art. 6(1)(b) | Supabase database (EU, Ireland). The raw purchase token is used solely to verify with Google and is not stored in plaintext beyond the verification request. Subscription record is deleted when you delete your account. |
| Location data — approximate GPS location | Find nearby venues (Date Night feature, optional) | Consent Art. 6(1)(a) — you explicitly grant Location permission | Passed to Google Places API in real time. Never stored by us. |
| Foreground app identity — package name of the most recently used app (from the past 5 minutes) | Detect which chat app you are using so Replai can display the correct app name in reply suggestions | Legitimate interest Art. 6(1)(f) — necessary to identify the correct app context | Processed on-device only; never transmitted or stored. Requires PACKAGE_USAGE_STATS permission, granted during setup. |
| Subscription tier — Free, Pro, or Max | Unlock paid features; enforce tier-based limits server-side | Contract performance Art. 6(1)(b) | Supabase (EU). Payment card details are handled entirely by Google Play — we never receive or store them. |
| Reply & app feedback — an optional thumbs up/down, a reason category, or a free-text comment you choose to type, plus the generation context (mode, persona, language, source app, tier). Never the conversation or the reply text. Please avoid including sensitive personal details. | Measure and improve reply quality | Legitimate interest Art. 6(1)(f) | Supabase (EU). Auto-deleted after 180 days. |
| Reminders (Pro/Max) — reminder titles and times you choose to set | Notify you at the chosen time; let reply suggestions propose meeting times that fit around your schedule | Contract Art. 6(1)(b) | Stored on your device only; a short summary of upcoming reminders is transiently included with reply requests, then immediately discarded — never stored server-side. |
3a. Special-Category (Sensitive) Data — Art. 9 GDPR
Conversations can reveal sensitive information — for example health, religious or political views, or data about your sex life or sexual orientation (including when you use Replai on dating apps). Replai does not seek out such data, but a chat you choose to scan may contain it. When you tap to scan a conversation or request a reply, you give your explicit consent under Art. 9(2)(a) GDPR for Replai to process that content — including any special-category data within it — for the sole purpose of generating your reply. It is processed transiently, never stored by Replai, and never used to profile you. If a conversation is especially sensitive, you can choose not to scan it — type the context manually instead, or skip the feature.
4. International Data Transfers
Most of your data never leaves the EU — Supabase stores data in Ireland (eu-west-1). However, when you request a reply, the conversation snippet is forwarded by our Supabase edge function to one of the following AI providers, both headquartered in the United States:
- OpenAI, LLC (US) — processes conversation snippets to generate replies. Transfer safeguard: Standard Contractual Clauses (SCCs) adopted by the European Commission under Art. 46(2)(c) GDPR. OpenAI Privacy Policy
- Groq, Inc. (US) — alternative AI provider. Same safeguard: Standard Contractual Clauses under Art. 46(2)(c) GDPR. Groq Privacy Policy
Under our API terms, neither provider uses your content to train their models; any transient retention (for example brief abuse-monitoring) is governed by the provider terms linked above, and Replai itself never stores the content. You can request copies of the relevant SCCs by contacting replaiengl@gmail.com.
5. Third-Party Processors
- Supabase — authentication, AI edge functions. EU (Ireland). Privacy Policy · Data Processing Agreement
- Google Play — subscription billing. Privacy Policy
- Google Places API — venue search (Date Night, optional). Privacy Policy
- OpenAI / Groq — AI reply generation (see Section 4).
6. Data Retention
- On-device data (Style DNA, contacts, reply history) — retained until you uninstall the app or use Settings → Delete Account; individual items can be cleared in-app.
- Server-side account data (subscription record, usage counters, anonymous ID) — retained until you tap Settings → Delete Account, which triggers immediate deletion.
- Conversation snippets — never retained. Discarded immediately after the AI response is generated. Not logged.
- Anonymous identifier — retained for as long as your account exists, then deleted with it.
- Daily reply counters — retained for 365 days from the date of creation, then automatically purged. Legal basis for this retention period: we need up to 12 months of usage data to detect sustained abuse patterns.
- Rate-limit window counters — retained for 2 hours only, then automatically purged. These contain no personal content — only a user ID, endpoint name, and request count.
- Saved conversation context — retained on-device for 30 days per contact, then automatically purged. Never stored server-side.
- Sent reply samples — retained on-device until you delete the contact or your data. Never stored server-side.
- Queue position entries — deleted immediately when your request is served, or automatically within ~10 minutes at most. They contain only a pseudonymous user ID and timestamps.
- Subscription / purchase verification records — retained while your subscription is active and for 90 days after expiry, to handle any billing disputes. Deleted when you delete your account.
7. Your Rights Under GDPR
As a data subject under GDPR, you have the following rights. You can exercise most of them directly within the app at any time:
- Right of access (Art. 15) — request a copy of the personal data we hold about you. Your data is visible in the app under Settings.
- Right to rectification (Art. 16) — correct inaccurate data. You can edit your Style DNA and contact labels directly in the app.
- Right to erasure / "right to be forgotten" (Art. 17) — delete all your data. Tap Settings → Delete Account. This is immediate and permanent.
- Right to restriction of processing (Art. 18) — request that we limit how we use your data while a dispute is resolved. Contact us at replaiengl@gmail.com.
- Right to data portability (Art. 20) — receive your data in a machine-readable format. Your Style DNA is stored as plain text and visible in Settings. Contact us for a full export.
- Right to object (Art. 21) — object to processing based on legitimate interest (your anonymous identifier). Contact us and we will assess your request.
- Right not to be subject to automated decision-making (Art. 22) — we do not make any automated decisions that produce legal or similarly significant effects about you.
- Right to withdraw consent — where processing is based on consent (notification access, screen capture, location), you can withdraw consent at any time by revoking the permission in Android Settings. Withdrawal does not affect the lawfulness of processing before withdrawal.
To exercise any right not available directly in the app, email replaiengl@gmail.com. We will respond within 30 days as required by GDPR.
8. Right to Lodge a Complaint
If you believe we have not handled your data lawfully, you have the right to lodge a complaint with a supervisory authority. The lead supervisory authority for our country of registration is:
ANSPDCP — Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal
Website: dataprotection.ro
Email: anspdcp@dataprotection.ro
Phone: +40 318 059 211
You may also lodge a complaint with the supervisory authority in the EU member state where you live or work.
9. Security
All data transmitted between the app and Supabase is encrypted in transit using TLS 1.2 or higher. Your anonymous identifier contains no personally identifiable information and cannot be reverse-engineered to identify you. Access to our Supabase database is restricted by Row Level Security (RLS) policies — each user can only read their own data, and sensitive tables (daily usage counters, rate-limit windows, subscription records) are write-protected from the client entirely. All writes to those tables are performed exclusively by our server-side edge functions using a service-role key that is never included in the app binary. AI API keys and other secrets are stored as Supabase environment secrets and are never present in the distributed APK.
10. Changes to This Policy
We may update this policy. When we do, we will update the "Last updated" date at the top and notify you within the app for material changes. Continued use of the app after changes constitutes acceptance.
11. Contact
Data controller: Elena Marinescu (independent developer, Romania)
Email: replaiengl@gmail.com
Country: Romania