Back to Home

Privacy Policy

Last updated: 31 July 2026

1. Introduction

Replien ("we", "our", or "us"), operated by Bernardo Pereira (Empresário em Nome Individual), is committed to protecting the personal data of our users. This Privacy Policy explains how we collect, use, store, and protect information when you use our platform, available at replien.com. By using Replien, you agree to the collection and use of information in accordance with this policy.

2. Who We Are

Replien is an AI-powered quote automation platform for service businesses. We process email data on behalf of our customers to help them respond to quote requests faster.

For the purposes of the General Data Protection Regulation (GDPR), the data controller is:

Bernardo Pereira
Rua Tenente Coronel Ribeiro, dos Reis 14, Lisboa, 1500-588, Portugal
Contact: privacy@replien.com

When processing email data on behalf of our customers, Replien acts as a Data Processor. Our customers (service businesses) are the Data Controllers of their clients' personal data.

3. Data We Collect

3.1 Account Data

When you create an account, we collect:

3.2 Email Data

When you connect your email account (Gmail or Microsoft Outlook), the OAuth permissions you grant allow Replien to read messages in your mailbox and to send messages on your behalf. We use this access for the following purposes only:

Although the underlying OAuth permissions are broad (this is how Gmail and Microsoft Graph expose mailbox access), we only further process messages identified as quote-related. Messages classified as unrelated are handled in one of two ways: bulk and automated mail (newsletters, notifications, no-reply senders, auto-replies) is discarded after classification and is not stored; a message that starts a new conversation and is not recognised as bulk is stored and shown to you as a “needs review” item, so that a genuine customer enquiry we misclassified is never silently discarded. Both are subject to the retention periods in section 5.

Email body content is sent to a third-party AI processing service to extract quote-relevant information (such as service type, dimensions, location, and scheduling details). This provider does not use your data to train or improve their AI models. The provider may temporarily retain data for up to 30 days for safety and compliance monitoring purposes, after which it is deleted, in accordance with their data processing terms. A Data Processing Agreement (DPA) with appropriate safeguards, including EU Standard Contractual Clauses, is in place with this provider.

All incoming emails are briefly processed by a third-party AI service to determine whether they are related to a quote request. Bulk and automated email (newsletters, notifications, no-reply senders, auto-replies) is discarded after classification and is not stored. Other email that is not related to a quote request, but which starts a new conversation, is stored and surfaced to the account holder for review rather than discarded — this is deliberate, so that a genuine enquiry our classifier gets wrong is not lost. Emails that are part of an existing quote request conversation (such as follow-ups, confirmations, or additional information) are stored alongside the original request to maintain a complete conversation history. Access is limited to the minimum required to provide the service.

3.3 Usage Data

We automatically collect certain technical data including IP address, browser type, pages visited, and feature usage. This is used solely for product improvement and security purposes.

3.4 Legal Basis for Processing

Under Article 6 of the GDPR, we process your data based on the following legal grounds:

4. How We Use Your Data

We use your data to:

We do not sell your data to third parties. We do not use your data for advertising purposes.

5. Email Provider Integrations

5.1 Gmail Integration

Replien's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

5.2 Microsoft Outlook Integration

Replien's use of data obtained through the Microsoft Graph API complies with the Microsoft APIs Terms of Use. Specifically:

6. Data Storage and Security

We implement the following security measures:

Users can disconnect their email account at any time from the Settings page. Upon disconnection, we immediately stop accessing email data and revoke stored OAuth tokens.

7. International Data Transfers

Your data is primarily stored and processed within the European Economic Area (EEA) or the United Kingdom. Transfers between the EEA and the United Kingdom are protected by the European Commission's adequacy decision for the UK, which recognises the UK's data protection framework as providing essentially equivalent protection to the GDPR. Some of our service providers operate outside this region; in those cases, we ensure appropriate safeguards are in place, including:

We only transfer the minimum data necessary to provide the service.

8. Data Retention

We retain your data for as long as your account is active. Upon account deletion:

9. Your Rights (GDPR)

If you are located in the European Economic Area, you have the following rights:

You also have the right to lodge a complaint with the Portuguese supervisory authority:

Comissão Nacional de Proteção de Dados (CNPD)
Website: www.cnpd.pt

To exercise any of these rights, contact us at privacy@replien.com.

10. Cookies and Tracking

Replien runs no advertising of its own — we do not sell your data, and we do not operate advertising or retargeting cookies. Analytics cookies are used only if you accept them, and nothing is set before you choose. One of the analytics providers we use, Microsoft Clarity, does receive data as an independent controller and may use it for its own purposes including advertising — that is disclosed in section 11 rather than buried, because it is the one thing here that is not purely on our behalf.

In summary, we use three kinds of storage:

Every individual cookie — its name, who sets it, what it is for and how long it lasts — is listed in our Cookie Policy. That page is the authoritative list; this section is a summary of it. The button below changes or withdraws your choice at any time.

11. Sub-processors

This is the complete list of third parties that process personal data on our behalf, what reaches each one, where it is processed, and — where that is outside the EEA — what makes the transfer lawful.

ProviderWhat reaches itWhereTransfer basis
NeonDatabase Everything you and your clients put into Replien: requests, messages, quotes, clients, bookings, payments. AWS Europe (London), United Kingdom UK adequacy decision. We name the region plainly rather than saying “EU-hosted”, because London is not in the EU.
CloudflareProcessing, uploads Email content in transit through the processing pipeline; uploaded logos and avatars. Edge network, EU entry points Standard Contractual Clauses
OpenAIAI processing The body text of incoming emails, to classify them and extract quote details. Not used to train models; retained by the provider up to 30 days for safety monitoring, then deleted. United States Standard Contractual Clauses, under a data processing agreement
Google / MicrosoftMailbox & calendar Read and send access to the mailbox you connect, and to the calendar if you enable scheduling. United States EU–US Data Privacy Framework and Standard Contractual Clauses
StripePayments Your subscription billing, and — where you enable it — deposits and payments collected from your clients. Ireland / United States Standard Contractual Clauses
ResendOur own email Transactional email we send you (sign-in links, notifications). Never your clients’ email — that goes through your own mailbox. United States Standard Contractual Clauses
PostHogProduct analytics — consent only Which pages and features are used. Session recording is off everywhere and the text of what you click is not captured, so your clients’ details never reach it. European Union (Frankfurt) None needed — stays in the EU
Microsoft (Clarity)Independent controller — consent only Behaviour and session replay on our public marketing pages only. Never inside the application, and never on the pages your clients see. United States EU–US Data Privacy Framework and Standard Contractual Clauses. See the note below — Microsoft is not acting solely for us here.
VercelHosting & speed metrics Serves this website. Its speed and traffic measurement is cookieless and identifies no one. Edge network Standard Contractual Clauses

Two things worth stating plainly rather than leaving in a table.

First, the body text of incoming emails is sent to an AI provider in the United States. That is central to how Replien works and there is no version of the product without it, so we would rather you read it here than discover it later. It is covered by a data processing agreement with Standard Contractual Clauses, the provider does not train on it, and messages classified as unrelated to quoting are discarded rather than stored.

Second, Microsoft receives Clarity data as an independent controller, not as a supplier acting on our instructions, and may use it for its own purposes including advertising — see the Microsoft Privacy Statement. Every other provider in this table acts only for us. This is why Clarity is confined to anonymous marketing pages, why we send it an explicit “no advertising storage” signal, and why refusing analytics cookies stops it entirely.

For our customers specifically: no session recording ever runs inside the application. The screens where your clients’ names, addresses and email bodies appear are not recorded by any third party, with or without consent. That is enforced in our code, not just promised here.

Each provider is bound by a data processing agreement and is required to handle data in accordance with applicable data protection law. Our own Data Processing Agreement, covering the data you entrust to us about your clients, is available on request at privacy@replien.com. We will tell you before adding a new sub-processor that handles your clients’ data.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes via email or an in-app notification. Material changes will be communicated at least 30 days before they take effect. The date at the top of this document reflects the most recent revision.

13. Contact

If you have questions about this Privacy Policy or our data practices, please contact:
Bernardo Pereira
Email: privacy@replien.com
Website: replien.com