# Privacy Policy

**Last updated:** August 5, 2026

This Privacy Policy explains what information Repliqo ("we," "us," "Repliqo") collects when you use our service, how we use it, and how you can control it.

## What we access

When you connect your Gmail account to Repliqo, we access:

- **Your incoming email messages** — so we can read them and draft replies.
- **The ability to send email on your behalf** — used to send AI-drafted replies, either after your approval (Review mode) or automatically (Auto-send mode), depending on how you've configured your rules.
- **Basic account information** — your email address and a hashed (encrypted, not plain-text) version of your password if you signed up directly with us.

We only request the Gmail permissions needed to read messages and send replies. We don't access your contacts, calendar, Drive, or any other Google service.

## How we use your data

Your Gmail data is used **only** to provide the auto-reply service you signed up for — matching incoming messages against the rules you set up, drafting replies, and sending them when you tell us to.

We do **not**:

- Sell your data to anyone.
- Use your email content to train AI models (ours or anyone else's).
- Use your email content for advertising or marketing purposes.
- Share your email content with third parties except as described below.

## How replies are generated

To draft a reply, the relevant email content is sent to Google's Gemini API, which generates the suggested response text. This is a processing step, not a data-sharing arrangement for Google's benefit — Google's own terms for how it handles data sent to its AI/API products apply to that processing. You can review those terms here: [Google APIs Terms of Service](https://developers.google.com/terms) and [Generative AI Prohibited Use Policy](https://policies.google.com/terms/generative-ai/use-policy).

## How we protect your data

- OAuth tokens that let Repliqo access your Gmail account are **encrypted at rest**. We never store your Gmail password — Google's OAuth flow means we never see it in the first place.
- Access to production systems and data is limited to what's needed to operate and support the service.

## How long we keep your data

- **Email logs and drafts** are retained for as long as your account is active, so you can review your reply history.
- **OAuth tokens** are retained until you disconnect your Gmail account or delete your account.
- If you disconnect Gmail, we stop accessing your inbox immediately and delete the associated tokens.
- If you delete your account, we delete your account data, including stored email logs and OAuth tokens, within 30 days.

## Your controls

You can, at any time:

- **Disconnect your Gmail account** from your dashboard, which immediately revokes our access.
- **Delete your account**, which removes your account data as described above.
- **Request a copy or deletion of your data** by contacting us (see below), even outside the normal account-deletion flow.

## Google API Services User Data Policy

Repliqo's use and transfer of information received from Google APIs adheres to the [Google API Services User Data Policy](https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.

## Contact us

For privacy questions, or to request that we delete your data, email us at **privacy@repliqo.app**.

## Changes to this policy

If we make material changes to this policy, we'll notify users by email or through a notice on the site before the changes take effect.
