Effective Date: 6/6/2026
Last Updated: 6/6/2026
ReplyWorth helps local businesses respond to Google reviews using AI. We collect only what we need to deliver the service. We do not sell your personal data. We use industry-standard security practices. You have the right to access, correct, and delete your data at any time.
1. Who We Are
ReplyWorth (“ReplyWorth,” “we,” “us,” or “our”) is a software-as-a-service platform that automatically generates and posts SEO-optimized replies to Google Business Profile reviews on behalf of local businesses. Our services are accessible at https://replyworth.com.
This Privacy Policy explains how we collect, use, disclose, and safeguard personal information when you use our website (https://replyworth.com), our web application, or any related services (collectively, the “Service”).
By accessing or using the Service you agree to the practices described in this Policy. If you do not agree, please do not use the Service.
Legal entity: ReplyWorth · California · Los Angeles
2. Information We Collect
Information You Provide
– Account registration: name, email address, and password when you create an account.
– Business profile: business name, phone number, website URL, business category, services offered, service area ZIP codes, and other information you enter into your profile settings.
– Billing information: billing name, billing email, and payment card details. Card data is processed and stored directly by Stripe, Inc. We do not store full card numbers or CVV codes.
– Communications: messages you send us via email, support channels, or contact forms.
– Voice & tone preferences: writing style, tone, and custom phrases you configure for AI reply generation.
– Phone number: if you opt in to SMS notifications, the mobile number you provide.
Information from Third-Party Integrations
– Google Business Profile (GBP): when you connect your GBP account via OAuth 2.0, we access your business listing data, location information, customer reviews, and (once available) performance metrics such as profile views, search impressions, direction requests, and call data. See Section 5 for details.
– Google account identity: name and email address returned by the Google OAuth flow at connection time.
Information Collected Automatically
– Usage data: pages visited, features used, button clicks, timestamps, and session duration.
– Log data: IP address, browser type, operating system, referring URL, and error logs.
– Device data: device type, screen resolution, and time zone.
– Cookies and similar technologies: see Section 9.
Information About Your Customers (Review Data)
Through the GBP integration, we receive the text and metadata of reviews left by your customers on Google. This content is provided by Google and is already publicly visible. We process it solely to generate reply suggestions on your behalf. We do not independently collect or store personal data about your customers beyond what is contained in review text.
3. How We Use Your Information
We use your information for the following purposes:
– Provide and operate the Service: account info, GBP data, review text, voice/tone settings.
– Generate AI review replies: review text, business profile, voice/tone settings.
– Process payments and manage subscriptions: billing email, Stripe customer/subscription IDs.
– Send transactional emails: email address, notification preferences.
– Send SMS notifications (opt-in only): phone number, notification preferences.
– Provide customer support: account info, communications history.
– Improve and develop the Service: usage data, log data, aggregated analytics.
– Track local search rankings: business location data, GBP listing ID.
– Detect fraud and ensure security: IP address, log data, device data.
– Comply with legal obligations: any data required by law.
– Send product updates and marketing (opt-in only): email address.
We do not use your data to train public AI models. Review content and business data you provide are used only to operate the Service for your account.
4. Sharing & Disclosure
We do not sell, rent, or trade your personal information to third parties for their marketing purposes. We share data only as described below.
Service Providers (Sub-processors)
We share data with trusted vendors who process it on our behalf and are contractually obligated to protect it:
– Anthropic, PBC — AI reply generation (Claude API). Data shared: review text, business name, voice/tone settings.
– Supabase, Inc. — Database and authentication hosting. Data shared: all account and service data.
– Vercel, Inc. — Application hosting and deployment. Data shared: log data, IP addresses.
– Stripe, Inc. — Payment processing and subscription management. Data shared: billing name, email, payment card data.
– Resend, Inc. — Transactional email delivery. Data shared: email address, notification content.
– Google LLC — Business Profile API, OAuth authentication. Data shared: OAuth tokens, GBP location IDs.
– Cloudflare, Inc. — CAPTCHA (Turnstile), DDoS protection, DNS. Data shared: IP address, browser/device signals.
– DataForSEO — Local search rank tracking. Data shared: business name, location, target keywords.
– Zipcodebase — ZIP code radius lookup for service areas. Data shared: ZIP codes entered by user.
Legal Requirements
We may disclose your information if required to do so by law or in good-faith belief that such action is necessary to: (a) comply with a legal obligation, subpoena, or court order; (b) protect and defend our rights or property; (c) prevent or investigate possible wrongdoing in connection with the Service; or (d) protect the personal safety of users or the public.
Business Transfers
If ReplyWorth is involved in a merger, acquisition, asset sale, or bankruptcy, your information may be transferred as part of that transaction. We will provide notice before your personal data is transferred and becomes subject to a different privacy policy.
Aggregate / De-Identified Data
We may share aggregated, anonymized, or de-identified information that cannot reasonably be used to identify you — for example, aggregate platform usage statistics — without restriction.
5. Google Business Profile Integration
ReplyWorth integrates with the Google Business Profile API via OAuth 2.0. When you authorize the connection, you grant us the ability to:
– Read your GBP locations, business details, and customer reviews.
– Post reply responses to reviews on your behalf.
– Access performance metrics (profile views, impressions, direction requests, calls) once the Business Profile Performance API is enabled.
We request only the minimum permissions necessary to operate the Service. We do not access your Google Search history, Google Ads data, Gmail, Google Drive, or any other Google services outside of Google Business Profile.
Your GBP OAuth token is stored securely and is used only for operations you explicitly authorize within ReplyWorth. You may revoke our access at any time by visiting your Google Account permissions at myaccount.google.com/permissions or by disconnecting within the ReplyWorth Settings page.
Use of Google APIs by ReplyWorth complies with the Google API Services User Data Policy, including the Limited Use requirements.
6. AI-Generated Content
ReplyWorth uses the Anthropic Claude API to generate suggested replies to your customer reviews. When we submit a request to Anthropic, we send the review text and relevant business context (your business name, services, and configured tone preferences). We do not send payment data, passwords, or other sensitive credentials to any AI provider.
AI-generated replies are suggestions only. You are solely responsible for reviewing, editing, and approving any reply before it is posted — or for configuring the auto-reply feature with appropriate settings. ReplyWorth does not warrant that AI-generated content is accurate, appropriate, or legally compliant for your specific situation.
Anthropic’s handling of data submitted via their API is governed by Anthropic’s Privacy Policy and API usage policies. Per Anthropic’s terms, API inputs and outputs are not used to train their models without your consent.
7. SMS Communications
ReplyWorth may send you text messages (SMS) to the mobile phone number you provide, subject to your explicit consent. Our SMS program is governed by the Telephone Consumer Protection Act (TCPA) and applicable state laws.
Consent and Opt-In
By providing your mobile phone number and enabling SMS notifications in your account settings, you expressly consent to receive text messages from ReplyWorth at the number provided. Standard message and data rates may apply. Message frequency varies based on your account activity and notification preferences.
You are not required to consent to SMS as a condition of purchasing or using the Service. SMS notifications are optional and may be disabled at any time.
Types of Messages
ReplyWorth sends the following categories of SMS messages:
– Transactional alerts: new review received, reply posted, reply failed, urgent review flagged.
– Account notifications: billing alerts, password reset confirmation.
We do not send promotional or marketing SMS messages without your separate express written consent.
SMS Commands
– Reply STOP to immediately opt out of all SMS messages from ReplyWorth. You will receive one confirmation message, then no further texts.
– Reply HELP to receive our support contact information and a reminder of how to manage your notification preferences.
– Reply START to re-enroll in SMS notifications after previously opting out.
Opt-Out
To stop receiving SMS messages at any time, reply STOP to any message we send. You may also disable SMS notifications at any time in Settings → Notifications within the ReplyWorth app. After opting out, you will receive a single confirmation message and will not receive further SMS from us unless you re-enroll.
Standard Disclosures
Message and data rates may apply. Message frequency varies. Supported carriers are not liable for delayed or undelivered messages. For help, reply HELP or email hello@replyworth.com. For carrier privacy policy, please visit your carrier’s website.
SMS Data
We collect and store your mobile phone number, message delivery status, and opt-in/opt-out history to manage your SMS preferences and comply with TCPA recordkeeping requirements. We do not share mobile phone numbers with third parties for marketing purposes.
8. Email Communications
We send the following types of email:
– Transactional emails: account creation confirmation, password reset, receipt and invoice notifications, billing alerts, and service notifications. These are necessary to operate the Service and cannot be opted out of while you hold an active subscription.
– Product notifications: new review alerts, reply confirmations, and weekly performance reports. These can be managed in Settings → Notifications.
– Marketing and announcements: product updates, feature announcements, and promotional offers. You may opt out at any time by clicking “Unsubscribe” in any such email or by contacting us at hello@replyworth.com.
All marketing emails comply with the CAN-SPAM Act and include a physical mailing address, a clear identification of the sender, and an easy unsubscribe mechanism.
Email delivery is handled by Resend, Inc. from the address hello@replyworth.com.
9. Cookies & Tracking
We use cookies and similar tracking technologies to operate and improve the Service.
Types of Cookies We Use
– Strictly necessary: session management, authentication tokens, CSRF protection. Required for the Service to function. Cannot be disabled.
– Functional: remembering your preferences (e.g., notification settings, date range filters). Can be disabled, though this may affect some features.
– Analytics: aggregate, anonymized data about how users interact with the Service to improve performance. We do not use third-party behavioral advertising trackers.
– Security (Cloudflare Turnstile): challenge tokens used to verify that form submissions are human. No persistent tracking.
Managing Cookies
You can control cookies through your browser settings. Disabling strictly necessary cookies will prevent you from logging in or using the Service. Most browsers allow you to refuse new cookies, delete existing cookies, or alert you when cookies are set.
Do Not Track
Some browsers transmit a “Do Not Track” (DNT) signal. We honor DNT signals by not enabling cross-site behavioral tracking. Note that the Service still uses necessary cookies regardless of DNT setting.
10. Data Security
We implement industry-standard safeguards to protect your information:
– Encryption in transit: all data transmitted between your browser and our servers is encrypted using TLS 1.2 or higher (HTTPS).
– Encryption at rest: sensitive data fields are encrypted in our Supabase-hosted database.
– Row-level security (RLS): our database enforces access controls so that each user can only access their own data.
– Authentication: password hashing using industry-standard algorithms; optional multi-factor authentication.
– Payment security: we do not store credit card numbers. All payment data is processed by Stripe, which is PCI-DSS Level 1 compliant.
– Access controls: access to production systems is limited to authorized personnel on a need-to-know basis.
– Vendor agreements: all sub-processors are contractually obligated to maintain appropriate security standards.
No method of transmission over the internet or electronic storage is 100% secure. While we use commercially reasonable measures to protect your information, we cannot guarantee absolute security. If you believe your account has been compromised, contact us immediately at hello@replyworth.com.
11. Data Retention
We retain your personal information for as long as necessary to provide the Service and comply with our legal obligations:
– Active account data: retained for the life of your subscription plus 90 days after termination to allow for account reactivation and to resolve any disputes.
– Review and reply data: retained while your account is active. Upon account deletion, review data is deleted within 30 days except where required for compliance.
– Billing records: invoices, payment history, and subscription records are retained for 7 years as required by tax and accounting laws.
– Log data: system and access logs are retained for up to 90 days for security and debugging purposes.
– SMS opt-in/opt-out records: TCPA compliance requires us to retain records of your SMS consent and opt-out requests for a minimum of 4 years.
– Deleted accounts: upon confirmed account deletion, personal data is purged from active systems within 30 days. Some anonymized or aggregated data may remain in backups for up to 90 days before being overwritten.
12. Your Privacy Rights
Regardless of where you are located, you may exercise the following rights by contacting us at hello@replyworth.com:
– Right to Access: request a copy of the personal information we hold about you.
– Right to Correction: request correction of inaccurate or incomplete personal data. Many fields can be updated directly in Settings.
– Right to Deletion: request deletion of your personal data. Available directly in Settings → Security → Delete Account. We may retain certain data as required by law.
– Right to Data Portability: request a machine-readable export of your personal data.
– Right to Object / Restrict Processing: object to or request restriction of processing of your data in certain circumstances.
– Right to Withdraw Consent: where processing is based on consent (e.g., SMS, marketing email), withdraw at any time without affecting the lawfulness of prior processing.
We respond to verified requests within 30 days. We may need to verify your identity before processing your request. We will not discriminate against you for exercising any of these rights.
13. California Residents — CCPA / CPRA
If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), grants you specific rights regarding your personal information.
Categories of Personal Information Collected
In the past 12 months, we have collected the following categories as defined by the CCPA:
– Identifiers: name, email address, IP address, account ID.
– Commercial information: subscription history, payment records.
– Internet or other electronic network activity: usage data, log data, cookies.
– Geolocation data: general location inferred from IP address; ZIP codes you provide.
– Professional or employment-related information: business name and type.
– Inferences: derived preferences based on your usage and settings.
Do Not Sell or Share My Personal Information
We do not sell or share your personal information for cross-context behavioral advertising as defined under the CCPA/CPRA. If this changes, we will update this Policy and provide the required opt-out mechanism.
Sensitive Personal Information
We do not collect, use, or disclose sensitive personal information (as defined by CPRA) beyond what is necessary to provide the Service, and we do not use it to infer characteristics about you.
Your California Rights
California residents have the right to: know what personal information is collected; delete personal information; correct inaccurate personal information; opt out of sale or sharing; limit use of sensitive personal information; and non-discrimination for exercising these rights. To submit a California privacy request, email hello@replyworth.com with the subject line “California Privacy Request.” We will verify your identity and respond within 45 days (with one possible 45-day extension).
Shine the Light
Under California Civil Code Section 1798.83, California residents may request information about personal information disclosed to third parties for direct marketing purposes in the prior calendar year. We do not disclose personal information to third parties for their direct marketing purposes.
14. EEA, UK & Swiss Residents — GDPR
If you access the Service from the European Economic Area (EEA), the United Kingdom, or Switzerland, the General Data Protection Regulation (GDPR) or UK GDPR applies to our processing of your personal data.
Data Controller
ReplyWorth is the data controller for personal data collected through the Service.
Legal Bases for Processing
We rely on the following legal bases: contract performance (Article 6(1)(b)), legitimate interests (Article 6(1)(f)), legal obligation (Article 6(1)(c)), and consent (Article 6(1)(a)) where specifically noted.
Data Transfers Outside the EEA
Your data may be transferred to and processed in countries outside the EEA, including the United States. We use the European Commission’s Standard Contractual Clauses (SCCs) and other appropriate safeguards to ensure adequate protection. See Section 17 for details.
GDPR Rights
In addition to the rights in Section 12, EEA/UK residents have the right to lodge a complaint with your local supervisory authority. For EEA residents, the relevant authority is the data protection authority in your country of residence. For UK residents, it is the Information Commissioner’s Office (ICO) at ico.org.uk.
Data Protection Officer
As a small-scale processor that does not conduct large-scale systematic monitoring of individuals, we are not currently required to designate a formal DPO. Privacy inquiries may be directed to hello@replyworth.com.
15. Children’s Privacy
The Service is intended solely for use by business owners and their authorized representatives who are at least 18 years of age. ReplyWorth does not knowingly collect personal information from individuals under the age of 18.
If you are a parent or guardian and believe that your child has provided us with personal information without your consent, please contact us immediately at hello@replyworth.com. If we discover that we have collected personal information from a minor, we will delete it promptly.
Our Service is not directed at children and does not include any features, content, or marketing intended for children. This Policy and our practices comply with the Children’s Online Privacy Protection Act (COPPA).
16. Accessibility
ReplyWorth is committed to ensuring digital accessibility for all users, including people with disabilities. We continually work to improve the user experience for everyone and strive to meet the standards of the Web Content Accessibility Guidelines (WCAG) 2.1 Level AA.
Accessibility Features
We implement the following measures to support accessibility:
– Semantic HTML markup and ARIA attributes where appropriate.
– Sufficient color contrast ratios meeting WCAG 2.1 Level AA requirements.
– Keyboard navigability throughout the application.
– Descriptive alt text on informational images.
– Focus indicators on interactive elements.
– Text that can be resized up to 200% without loss of content or functionality.
Known Limitations
While we strive for full accessibility, some features of the Service may not yet fully meet WCAG 2.1 Level AA standards. We are actively working to address known gaps and welcome feedback to help us prioritize improvements.
Requesting Accommodations
If you experience difficulty accessing any part of the Service due to a disability, or if you need the content in an alternative format, please contact us at hello@replyworth.com with the subject “Accessibility Request.” We will make reasonable efforts to provide the information, service, or accommodation you need within a reasonable timeframe.
ADA Compliance
ReplyWorth is committed to compliance with Title III of the Americans with Disabilities Act (ADA) and Section 508 of the Rehabilitation Act as applicable to web-based services. We treat accessibility as an ongoing responsibility and regularly test our interfaces with assistive technologies including screen readers.
Feedback
We welcome feedback on the accessibility of ReplyWorth. If you encounter barriers or have suggestions for improvement, please notify us at hello@replyworth.com. We take all accessibility feedback seriously and will respond within 2 business days.
17. International Data Transfers
ReplyWorth is operated from the United States. If you access the Service from outside the United States, your information will be transferred to, stored, and processed in the United States and other countries where our service providers operate. These countries may have data protection laws that differ from those in your country.
For transfers from the EEA, UK, or Switzerland to the United States and other non-adequate countries, we rely on:
– Standard Contractual Clauses (SCCs) adopted by the European Commission, incorporated into our data processing agreements with sub-processors.
– Adequacy decisions by the European Commission where applicable.
– Your explicit consent where required and where you have been informed of the transfer risks.
Our primary sub-processors (Supabase, Vercel, Stripe, Anthropic, Resend) maintain their own international transfer mechanisms. Upon request, we can provide copies of applicable SCCs.
18. Data Breach Notification
In the event of a security breach that compromises the confidentiality, integrity, or availability of your personal information, we will:
– Assess the scope and nature of the breach promptly upon discovery.
– Notify affected users by email to the address on file within 72 hours of determining the breach poses a risk to your rights and freedoms (consistent with GDPR Article 33 timelines), or as required by applicable state law — whichever is sooner.
– Notify applicable supervisory authorities within legally required timeframes.
– Provide a clear description of what data was affected, how the breach occurred, and the steps we are taking to remediate it.
– Take reasonable steps to mitigate harm and prevent further unauthorized access.
If you suspect unauthorized access to your ReplyWorth account, please contact us immediately at hello@replyworth.com and change your password using the Security settings page.
19. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or the Service. When we make material changes, we will:
– Update the “Last Updated” date at the top of this page.
– Send an email notification to your registered email address for material changes.
– Display a prominent notice within the application for a period of at least 30 days.
Your continued use of the Service after the effective date of the updated Policy constitutes your acceptance of the changes. If you do not agree to the updated Policy, you must discontinue use of the Service and may request deletion of your account.
The current version will always be available at https://replyworth.com/privacy.
20. Contact Us
For privacy-related questions, data requests, accessibility accommodations, or to report a concern:
Email: hello@replyworth.com
Website: https://replyworth.com
Response time: within 2 business days for general inquiries; within 30 days for formal data requests.
Disclaimer: This Privacy Policy is provided for informational purposes. While we have made every effort to ensure its accuracy and completeness, it should not be construed as legal advice. Laws vary by jurisdiction and change over time. We recommend consulting a qualified attorney to ensure your specific legal compliance needs are met.