Skip to content
R Replim
How it works Product Use cases Build status Pricing FAQ
Sign in Start free
How it works Product Use cases Build status Pricing FAQ Sign in Start free

Legal

Privacy Policy

Last updated 5 August 2026

This policy covers two different groups of people, and the difference matters: the customers who sign up for Replim, and the people whose comments a customer brings into Replim. We hold far more of the first kind of data than the second, and our role is different for each.

The two roles we play

For your account data — your name, email, workspace, billing status — we are the controller. We decide why we hold it, and this policy explains that.

For the comments you bring in — written by people who never signed up for Replim — you are the controller and we are your processor. We only act on your instruction. The terms of that relationship are in the Data Processing Addendum, and you are responsible for having a lawful basis to collect those comments in the first place.

What we collect about you

  • Account: name, email address, hashed password, and the times you verified your email and last signed in.
  • Workspace: workspace name, time zone, members and their roles.
  • Sign-in security: six digit codes are stored only as a hash, with the IP address that requested them, and expire in ten minutes.
  • Billing: plan, subscription status and invoice records. We do not hold card numbers; Dodo Payments handles payment as merchant of record and never passes them to us.
  • Connections: which platforms you connected and the tokens needed to read from them, held so Replim can fetch comments on your instruction.
  • Server logs: ordinary web server records, including IP address, kept for security and debugging.

We do not sell personal data. We do not run advertising trackers on the product.

What we process on your behalf

When you connect an account, Replim fetches comments from it. Those comments contain the commenter's display name, handle, the text they wrote and when they wrote it. We hold that because you asked us to, and only for as long as you keep it.

Comment text is sent to our AI provider to classify sentiment and intent and to draft a suggested reply. If that is not acceptable for your use case, do not connect accounts whose comments you cannot share with a processor.

Why we are allowed to hold it

  • To perform our contract with you — running the service, your account, and billing.
  • Legitimate interests — keeping the service secure, preventing abuse, and understanding aggregate usage. We balance this against your interests and keep the data minimal.
  • Legal obligation — tax and accounting records.
  • Consent — where we ask for it, such as optional product email. You can withdraw it at any time.

Who we share it with

Only the providers needed to run the product. Every one of them is named, with what it receives and where it sits, on the subprocessors page.

We may also disclose data where we are legally required to, or to protect our rights or the safety of others. If Replim is ever sold or merged, data may transfer as part of that, and we will say so before it takes effect.

How long we keep it

  • Account data: while your account is open, then deleted or de-identified within 30 days of closure.
  • Comments and replies: until you delete them or close the workspace.
  • Sign-in codes: ten minutes, then they are dead whether used or not.
  • Invoices and tax records: as long as tax law requires, typically six to seven years.
  • Server logs: a short rolling window for security purposes.

Your rights

Depending on where you live, you may have the right to access, correct, delete, port or restrict your personal data, to object to processing based on legitimate interests, and to complain to a data protection authority.

Write to [email protected] and we will respond within one month. We will not charge you for a reasonable request.

If you are a commenter whose comment was collected by one of our customers, that customer controls it, and your request is best directed to them. Tell us anyway and we will pass it on and help them act on it.

Where data is processed

Our providers operate internationally, so personal data may be processed outside your country. Where data leaves the UK or EEA we rely on the appropriate safeguards, usually Standard Contractual Clauses, in our agreements with those providers.

Security

Passwords are hashed. Sign-in codes are hashed, expire in ten minutes and die after five wrong attempts. Sessions are cookie based with CSRF protection on every state changing request. Traffic is served over HTTPS. Access to production is limited.

We hold no security certification and we do not claim one. No system is perfectly secure, and we will tell you promptly if a breach affects your data.

Children

Replim is not for anyone under 16 and we do not knowingly collect their data. If you believe a child has an account, tell us and we will remove it.

Changes

We will post any update here and change the date at the top. If a change materially affects how we use your personal data, we will tell you directly before it takes effect.

Contact

Questions about this document go to [email protected]. Anything about personal data goes to [email protected].

Legal

Terms of Service Privacy Policy Data Processing Addendum Subprocessors Acceptable Use Refunds and Cancellation Cookies

On this page

The two roles we play What we collect about you What we process on your behalf Why we are allowed to hold it Who we share it with How long we keep it Your rights Where data is processed Security Children Changes
R Replim

One inbox for Instagram, Facebook, LinkedIn and YouTube comments.

Product

How it works One queue Use cases Pricing

Company

Build status FAQ Contact

Legal

Terms of Service Privacy Policy Data Processing Addendum Subprocessors Acceptable Use Refunds and Cancellation Cookies

Account

Sign in Start free
© 2026 Replim Comment examples on this page are sample data.