Privacy Policy
Last updated: 22 August 2026 Effective date: 23 April 2026
1. About this policy
This policy explains how Bhupendra Singh, sole proprietor trading as ReplySmooth ("we", "us", "our") collects, uses, and protects your personal data when you use ReplySmooth ("the Service").
For the purposes of India's Digital Personal Data Protection Act, 2023 (the "DPDP Act"), we are the Data Fiduciary and you are the Data Principal.
2. Who we are
- Legal name: Bhupendra Singh, sole proprietor trading as ReplySmooth
- Registered office: Labitha Enclave, Devarachikkanahalli Main Rd, Maruthi Layout, Royal Shelters, Bommanahalli, Bengaluru, Karnataka 560114
- Primary contact: support@replysmooth.com
- Grievance Officer (DPDP Sec. 8(9)): Bhupendra Singh (Proprietor), reachable at support@replysmooth.com
3. Data we collect
3.1 When you sign in with Google
- Email address (from your Google account)
- Full name (if your Google profile includes it)
- Profile picture URL (if your Google profile includes it)
- Opaque Google identifier (to authenticate you on return visits)
3.2 When you use the Service
- Messages you paste in — the text of messages you received, your drafts, and context you provide. Required for the AI to generate reply suggestions, openers, polished drafts, and profile critiques.
- AI-generated suggestions returned to you and stored against your account.
- AI Wingman conversation history — retained so the AI can maintain context across a session.
- Profile descriptions you enter into the Profile Review feature. This is text only — we do not accept photo uploads.
- Credit usage records — an append-only ledger of when you used a feature, for fairness, billing, and audit.
3.3 Automatic
- Device signals processed by Cloudflare Turnstile during sign-in. We receive only a success/failure verification token from Cloudflare; we do not receive raw device identifiers.
- IP address — used for rate limiting, fraud prevention, and abuse mitigation.
- Traffic measurement — which pages were viewed, and standard browser and device information, through Google Analytics. This sets two cookies on your device. In the European Economic Area, the United Kingdom and Switzerland we ask before any of it happens, and nothing is loaded or stored unless you accept. Full detail, including the cookie names and how to remove them, is in the Cookie Policy, section 3.8.
3.4 What we do not collect
- No access to your dating-app accounts. We never plug into Tinder, Bumble, Hinge, Aisle, or any other platform.
- No photo uploads. The Profile Review feature accepts text descriptions of photos only.
- No payment card data stored by us directly. When paid plans launch, card data will be handled by our payment processor (details will be added here before that feature ships).
- We never sell or rent your personal data for money. See section 6 for how advertising works on the Service.
4. How we use your data
| Purpose | Data used | Legal basis under DPDP Act |
|---|---|---|
| Authenticate you | Email, Google identifier | Performance of our contract with you (Sec. 7(a)) |
| Provide AI reply suggestions, openers, polished drafts, profile review | Messages/drafts/profile text you submit | Performance of contract |
| Maintain Wingman conversation context | Messages within the session | Performance of contract |
| Enforce fair-use limits (credits) | Credit ledger, user ID | Performance of contract |
| Prevent abuse, spam, and fraud | IP address, Turnstile verification signal | Legitimate use (Sec. 7(i)) |
| Notify you of important service updates | Email address | Consent (Sec. 6) |
| Measure traffic to our free public pages, so an advertising network can verify our visitor numbers | Pages viewed, IP address, browser and device information | Legitimate use (Sec. 7(i)). In the EEA/UK/Switzerland we ask for consent first and collect nothing without it. |
We do not use the content you submit — your messages, drafts, or profile text — for advertising, marketing profiles, or any purpose beyond those listed above. Advertising on the Service is described in section 6.
5. Third-party processors
We share the minimum necessary data with these third parties. Each is contractually bound to confidentiality and DPDP-aligned security standards.
| Processor | Role | Data shared | Where it's hosted |
|---|---|---|---|
| Supabase | Database + authentication hosting | Account info, chat history, credit ledger | ap-south-1 (Mumbai, India) |
| Google (OAuth) | Identity provider for sign-in | Standard OAuth handshake | Global |
| Google Cloud — Gemini API | AI inference for reply generation | Text you submit for that request. Not retained by Google for model training per the Gemini API Additional Terms. | Global |
| Cloudflare Turnstile | Bot protection on sign-in | Session-level verification signals | Global |
| Cloudflare (Pages, Workers, Web Analytics) | Hosting, content delivery, and privacy-friendly traffic measurement | IP address and standard request data (browser, device type, referring page, country). Cloudflare Web Analytics sets no cookies and does not track you across sites. | Global edge network |
| PostHog | Product analytics and session replay, so we can see which features are used and where the Service is confusing or broken | Pages viewed, buttons tapped, and a replay of your interactions with our pages. Everything you type is masked and is not recorded. No cookies. Outside the EEA, UK and Switzerland we keep one anonymous random identifier in your browser's local storage so we can recognise a returning visitor and count real people rather than repeat visits — it does not identify you personally. For EEA/UK/Switzerland visitors, nothing is stored on your device for this. | United States |
| Google Analytics 4 | Traffic measurement — counting visits and pages viewed, so an advertising network can verify our visitor numbers. Advertising networks do not accept these figures from any other source, which is the only reason we run it. | Pages viewed, IP address, and standard browser and device information. Nothing you type is sent to it. It sets two cookies on your device (_ga and _ga_…) holding a random number, not anything about you. For EEA/UK/Switzerland visitors it is not loaded at all unless you accept it first, and nothing is stored if you decline. |
Global |
| Grow by Mediavine | Traffic measurement, so an ad network can verify our visitor numbers | Pages viewed, and standard browser and device information. It keeps a random visitor number in your browser's local storage so a returning visitor is not counted twice. It shows no ads, but it does add a small "Grow Account Page" link at the very bottom of each page. It also loads an advertising identity tool (UID2) that can recognise the same person across different websites — we do not give it your email address, and we have not seen it store an identifier; it does not load at all if you use an ad blocker. Full detail in the Cookie Policy, section 3.5. | Global |
| Journey by Mediavine | Advertising on our free public pages — see section 6 | IP address, operating system type and version, device type, site language, browser type, and email in hashed form. Mediavine and its partners may use first- and third-party cookies and similar technologies for interest-based advertising. Nothing you type is sent to it. Full detail, including how to opt out, is in section 6. | Global |
We never sell your personal data for money, and we do not pass the content you submit — your messages, drafts, or profile text — to advertisers. Note that under some United States state privacy laws, showing personalised advertising is itself classed as "sharing" personal information. Section 6 explains what our advertising partner collects and how to opt out.
6. Advertising
Our free public pages carry advertising, supplied by Journey by Mediavine. That is how we keep those pages free to use. The section below is Mediavine's own required disclosure and describes what their advertising code does.
What we never share with advertisers. Nothing you type. Your messages, drafts, profile text, and Wingman conversations are never passed to Mediavine, to its partners, or to any advertiser. Those go only to the AI service that generates your reply, as described in section 5. Advertising code runs only on our free public pages — never inside the signed-in app.
If you are in the EEA, UK or Switzerland, Mediavine shows its own consent notice covering advertising, separately from the traffic-measurement notice described in section 5. Your choice there controls what advertising partners may do on this site, and you can change it at any time from the preferences link Mediavine places in the page footer.
Our own app is ad-free. The signed-in workspace at /app carries no advertising, and we do not intend to place ads there.
Mediavine Programmatic Advertising (Ver 1.1)
The Website works with Mediavine to manage third-party interest-based advertising appearing on the Website. Mediavine serves content and advertisements when you visit the Website, which may use first and third-party cookies. A cookie is a small text file which is sent to your computer or mobile device (referred to in this policy as a “device”) by the web server so that a website can remember some information about your browsing activity on the Website.
First party cookies are created by the website that you are visiting. A third-party cookie is frequently used in behavioral advertising and analytics and is created by a domain other than the website you are visiting. Third-party cookies, tags, pixels, beacons and other similar technologies (collectively, “Tags”) may be placed on the Website to monitor interaction with advertising content and to target and optimize advertising. Each internet browser has functionality so that you can block both first and third-party cookies and clear your browser’s cache. The "help" feature of the menu bar on most browsers will tell you how to stop accepting new cookies, how to receive notification of new cookies, how to disable existing cookies and how to clear your browser’s cache. For more information about cookies and how to disable them, you can consult the information at All About Cookies.
Without cookies you may not be able to take full advantage of the Website content and features. Please note that rejecting cookies does not mean that you will no longer see ads when you visit our Site. In the event you opt-out, you will still see non-personalized advertisements on the Website.
The Website collects the following data using a cookie when serving personalized ads:
- IP Address
- Operating System type
- Operating System version
- Device Type
- Language of the website
- Web browser type
- Email (in hashed form)
Mediavine Partners (companies listed below with whom Mediavine shares data) may also use this data to link to other end user information the partner has independently collected to deliver targeted advertisements. Mediavine Partners may also separately collect data about end users from other sources, such as advertising IDs or pixels, and link that data to data collected from Mediavine publishers in order to provide interest-based advertising across your online experience, including devices, browsers and apps. This data includes usage data, cookie information, device information, information about interactions between users and advertisements and websites, geolocation data, traffic data, and information about a visitor’s referral source to a particular website. Mediavine Partners may also create unique IDs to create audience segments, which are used to provide targeted advertising.
If you would like more information about this practice and to know your choices to opt-in or opt-out of this data collection, please visit National Advertising Initiative opt out page. You may also visit Digital Advertising Alliance website and Network Advertising Initiative website to learn more information about interest-based advertising. You may download the AppChoices app at Digital Advertising Alliance’s AppChoices app to opt out in connection with mobile apps, or use the platform controls on your mobile device to opt out.
For specific information about Mediavine Partners, the data each collects and their data collection and privacy policies, please visit Mediavine Partners.
7. Where your data lives
Your account data, chat history, and credit records are hosted in Supabase's Mumbai region (ap-south-1), inside India.
Data transmitted to the Gemini API for AI inference is processed transiently and is not retained by Google for model training, per Google's Generative AI API Additional Terms.
8. How long we keep your data
| Category | Retention |
|---|---|
| Account record (name, email, avatar) | Until you delete your account |
| AI Wingman chat history (Free tier) | Until you clear the conversation, or 7 days of inactivity |
| AI Wingman chat history (Monthly tier) | Until you clear the conversation or delete your account |
| Credit ledger transactions | 7 years (financial-audit retention allowed under DPDP Sec. 17) |
| Server logs (IP, request metadata) | 30 days |
When you request account deletion, we hard-delete all data within 30 days except the credit ledger, which is retained with personally identifying fields removed so individual transactions cannot be traced back to you.
9. Your rights under the DPDP Act
As a Data Principal, you have the right to:
- Access — request a copy of the personal data we hold about you (Sec. 11)
- Correction and erasure — have inaccurate data corrected or your data deleted (Sec. 12)
- Nominate — designate another person to exercise your rights in case of your death or incapacity (Sec. 13)
- Withdraw consent — at any time, for any processing based on consent
- Grievance redressal — complain to our Grievance Officer, and escalate to the Data Protection Board of India if unresolved (Sec. 13(3))
How to exercise these rights
Email the Grievance Officer at support@replysmooth.com with the subject line "Data Rights Request" and describe what you need. We respond within 30 days, as required by the DPDP Act.
10. How we protect your data
- In transit: TLS 1.2 or higher on all connections between your device and our servers.
- At rest: AES-256 encryption applied by Supabase to the Postgres database.
- Access control: Row-Level Security enforced at the database layer so each user can only read their own records.
- Bot protection: Cloudflare Turnstile on sign-in.
- Rate limiting: per-user quotas at the API layer to deter abuse.
- Principle of least privilege: only the services listed in section 5 have any access to your data, and each only to the minimum required fields.
If a personal-data breach occurs and is likely to cause harm to you, we will notify you and the Data Protection Board of India within 72 hours of becoming aware, as required by DPDP Sec. 8(6).
11. Children's data
The Service is only for users aged 18 years and above. At sign-in, you confirm you are 18 or older. If we discover that we have collected data from a person under 18, we will delete it immediately. If you believe a minor is using the Service, please email support@replysmooth.com.
12. International transfers
Your data is primarily stored in India. Some processors listed in section 5 (Google, Cloudflare) operate globally and may process data outside India in transit. Each such transfer is covered by the processor's own cross-border data-protection commitments (SCCs, DPAs) and is limited to what section 4 describes.
The Government of India, under DPDP Sec. 16, may designate restricted countries for cross-border transfer; we comply with all such designations as and when issued.
13. Changes to this policy
We may update this policy from time to time. If changes are material (e.g., new processors, new data types, new purposes), we will notify you by email and via an in-app notice at least 14 days before the changes take effect. Continued use of the Service after the effective date means you accept the updated policy.
The current effective date is shown at the top.
14. Contact
- General enquiries: support@replysmooth.com
- Grievance Officer (DPDP Sec. 8(9)): Bhupendra Singh (Proprietor), support@replysmooth.com
- Registered entity: Bhupendra Singh, sole proprietor trading as ReplySmooth
- Registered office: Labitha Enclave, Devarachikkanahalli Main Rd, Maruthi Layout, Royal Shelters, Bommanahalli, Bengaluru, Karnataka 560114