Last Updated: January 8, 2025
ReplyBoss ("we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.
Data Controller: ReplyBoss
Contact: support@replyboss.ai
Jurisdiction: Switzerland
This Privacy Policy complies with the Swiss Federal Act on Data Protection (FADP), the EU General Data Protection Regulation (GDPR), and other applicable data protection laws.
When you connect your Twitter/X account via OAuth, we collect:
Important: We only access data you explicitly authorize. We do not access your direct messages, private information, or perform actions without your consent.
We process your personal data based on the following legal grounds:
Contract Performance (Art. 6(1)(b) GDPR)
Processing necessary to provide the Service you subscribed to (account management, Twitter/X integration, AI generation, billing).
Legitimate Interest (Art. 6(1)(f) GDPR)
Analytics, security, fraud prevention, service improvement, and business operations.
Consent (Art. 6(1)(a) GDPR)
Marketing communications, non-essential cookies, and optional features (you can withdraw consent anytime).
Legal Obligation (Art. 6(1)(c) GDPR)
Compliance with tax laws, accounting requirements, and legal requests from authorities.
We use collected information for the following purposes:
We do not sell your personal data. We only share data in the following limited circumstances:
Supabase (Database Hosting)
Stores user data, settings, and content. Data location: EU/US (depending on configuration).
Privacy PolicyStripe (Payment Processing)
Processes payments, stores billing information. GDPR and PCI-DSS compliant.
Privacy PolicyAI Providers (OpenAI, Groq)
Process AI generation requests. Tweet content and prompts are sent for processing but not stored by providers beyond required processing time.
OpenAI Privacy | Groq PrivacyTwitterAPI.io (Third-Party Twitter API)
Accesses public Twitter/X data on your behalf. No personal identification data shared beyond API tokens.
Privacy PolicyWe may disclose your information if required by law, court order, or government request, or to:
In the event of a merger, acquisition, or sale of assets, your information may be transferred. We will notify you via email and/or prominent notice on our website before your data is transferred and becomes subject to a different privacy policy.
We may share aggregated, anonymized data that cannot identify you (e.g., "80% of users use feature X") for analytics, research, or marketing purposes.
ReplyBoss is based in Switzerland. Some of our service providers are located in the United States and other countries. When we transfer your data outside Switzerland/EEA, we ensure adequate protection through:
By using the Service, you consent to the transfer of your data to these countries. You can request information about specific safeguards by contacting support@replyboss.ai.
We retain your personal data only as long as necessary for the purposes outlined in this Privacy Policy:
Active Accounts
Duration of subscription plus 90 days (for billing disputes and account reactivation).
Deleted Accounts
30 days grace period for account recovery, then permanent deletion. OAuth tokens deleted immediately.
Billing Records
7 years (tax and accounting legal requirements).
Analytics Data
Aggregated data retained indefinitely. Individual activity logs retained for 12 months.
Backups
Automated backups retained for 30 days. Deleted data removed from backups after 30 days.
Under GDPR and Swiss data protection law, you have the following rights:
Right to Access (Art. 15 GDPR)
Request a copy of your personal data we hold. Available via account settings or by emailing support@replyboss.ai.
Right to Rectification (Art. 16 GDPR)
Correct inaccurate or incomplete data directly in your account settings.
Right to Erasure / "Right to be Forgotten" (Art. 17 GDPR)
Delete your account and all associated data. Available in account settings or contact support@replyboss.ai.
Right to Data Portability (Art. 20 GDPR)
Export your data in machine-readable format (JSON). Available in account settings.
Right to Object (Art. 21 GDPR)
Object to processing based on legitimate interest (e.g., marketing emails). Unsubscribe links provided in all marketing emails.
Right to Restriction (Art. 18 GDPR)
Request temporary restriction of processing while we verify accuracy or resolve disputes.
Right to Withdraw Consent
Withdraw consent for marketing, analytics, or optional features anytime without affecting lawfulness of prior processing.
Right to Lodge a Complaint
File a complaint with your local data protection authority if you believe we have violated your rights.
How to Exercise Your Rights:
We implement industry-standard security measures to protect your data:
Data Breach Notification: In the event of a data breach affecting your personal data, we will notify you and relevant authorities within 72 hours as required by GDPR.
Important Security Notice
While we implement robust security measures, no system is 100% secure. You are responsible for maintaining the confidentiality of your account credentials and should enable two-factor authentication where available.
ReplyBoss is not intended for individuals under 18 years of age. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child under 18, contact us immediately at support@replyboss.ai and we will delete it promptly.
We use cookies and similar technologies to provide and improve the Service. For detailed information about our use of cookies, including types of cookies, purposes, and how to manage them, please see our Cookie Policy.
Quick Summary:
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or service features. Material changes will be notified via:
Changes take effect 30 days after notification (or immediately if required by law). Continued use of the Service after changes constitutes acceptance of the updated Privacy Policy.
Previous versions of this Privacy Policy are available upon request by emailing support@replyboss.ai.
For questions, concerns, or requests regarding this Privacy Policy or our data practices, contact us at:
Email: support@replyboss.ai
Subject Line: Privacy Inquiry / Data Request / GDPR Request
Website: replyboss.ai
We will respond to all requests within 30 days as required by GDPR.
If you believe we have not adequately addressed your privacy concerns, you have the right to lodge a complaint with a supervisory authority:
Switzerland:
Federal Data Protection and Information Commissioner (FDPIC)
Website: www.edoeb.admin.ch
EU/EEA: Contact your national data protection authority. List available at: EDPB Members
ACKNOWLEDGMENT
BY USING THE SERVICE, YOU ACKNOWLEDGE THAT YOU HAVE READ AND UNDERSTOOD THIS PRIVACY POLICY AND CONSENT TO OUR DATA PRACTICES AS DESCRIBED HEREIN.