Privacy

Your reviews and replies stay yours.

How we handle data in HappyReplies. Last updated 5 July 2026.

The short version

We collect the minimum data needed to run HappyReplies, we don't sell it, and we don't use your reviews to train shared AI models. You can export or delete everything from Settings at any time. The rest of this page is the detail.

Who we are

HappyReplies is operated by Rhys Morgan, trading as HappyReplies, a sole trader with business address at HappyReplies, 447 Broadway, 2nd Fl #793, New York, NY 10013, United States. For any privacy questions, email team@happyreplies.com.

What we collect

We collect four categories of data:

  • Account data — your email address, hashed password (if you use email sign-in), and the OAuth identifier your provider returns if you sign in with Google.
  • Business content you create — the brand voice description, business name and logo, teammates you invite, reviews you paste or sync, and the replies we draft and you save.
  • Billing data — if you subscribe to a paid plan, Paddle (our Merchant of Record) processes your card and billing details on our behalf. We store your Paddle customer ID, plan, billing period, and invoice history. We never see or store your full card number.
  • Usage and diagnostics — pages visited, features used, error traces, IP address, and browser type. This is limited to what we need to keep the product working and to spot abuse.

How we use your data

We use your data to provide the service you signed up for: drafting replies, storing your history, enforcing plan limits, sending transactional email (sign-in codes, receipts, product notices), and keeping the product secure. We do not sell personal data, we do not share it with data brokers, and we do not use your reviews or replies to train shared or third-party AI models. Anonymised, aggregated usage patterns may be used to improve HappyReplies itself.

How AI drafting works

When you generate a reply, the review text and your brand voice description are sent to large language models via the Lovable AI Gateway, which routes to model providers including Google (Gemini) and OpenAI. Under our provider agreements, prompts and completions are processed to return your draft and are not used to train the underlying foundation models. Providers may retain requests for a short window for abuse monitoring; see each provider's policy for the current retention period. Do not paste anything into HappyReplies that you would not send to a third-party AI service.

Subprocessors

We use a small number of trusted providers to run HappyReplies. Each processes data only on our instructions and under a data-processing agreement.

  • Lovable Cloud (Supabase) — application hosting, authentication, and database. Data is stored in the EU.
  • Lovable AI Gateway — routes prompts to model providers (currently Google Gemini and OpenAI) to generate reply drafts.
  • Paddle (Paddle.com Market Ltd) — our Merchant of Record for all purchases. Paddle processes payment card details, billing address, tax data, and subscription lifecycle events, and acts as an independent data controller for that payment data. See paddle.com/legal/privacy.
  • Resend — delivery of transactional email (sign-in links, receipts, product notices).
If we add or replace a subprocessor, we will update this page before the change takes effect. If you need a current subprocessor list for procurement, email team@happyreplies.com.

International transfers

Our primary hosting and database are in the EU. Some subprocessors (notably certain AI model providers and Paddle) may process data in the United States or other countries. In those cases we rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum, where UK data is involved) to safeguard the transfer.

Security

Data is encrypted in transit (TLS 1.2+) and at rest on the database platform. Access to production data is restricted to a small number of team members using audited, role-based controls; database row-level security isolates each workspace from every other workspace. Passwords are hashed with an industry-standard algorithm — we never see or store the plaintext. We keep our dependencies patched and monitor for suspicious activity. No system is perfect: if you find a security issue, please email team@happyreplies.com and we will respond promptly.

Who can see your data

Reviews, replies, and brand voice are visible only to you and teammates you invite to your workspace. Our hosting platform provides the underlying infrastructure but does not access your content in the ordinary course of business. A very small number of HappyReplies staff may access your data only when strictly necessary — for example, to investigate a support ticket you've raised or a suspected security incident. We do not disclose your data to third parties except as described in this policy or as required by law.

Cookies and analytics

We use strictly-necessary cookies to keep you signed in and to remember your workspace. We use lightweight, privacy-respecting analytics to understand which features get used and where the product breaks. We do not use advertising cookies, cross-site tracking pixels, or third-party retargeting. You can disable non-essential cookies in your browser without breaking sign-in.

Retention and deletion

We keep your data for as long as your account is active. You can delete your account at any time from Settings → Danger zone → Delete account. Deletion removes your reviews, replies, brand voice, and account login immediately; encrypted database backups age out within 30 days. Operational logs (error traces, audit trail) are retained for up to 90 days for security and debugging. Billing records (invoices, tax records) are retained for the period required by applicable tax and accounting law, typically six years.

Legal basis (GDPR)

If you are in the EEA or UK, we process your data on three lawful bases: (1) contract — to provide the service you signed up for and to bill you for it; (2) legitimate interest — to keep the product secure, prevent abuse, and improve reliability; (3) legal obligation — to keep tax and accounting records and to respond to lawful requests from authorities. You can object to processing based on legitimate interest at any time by emailing us. We do not carry out automated decision-making with legal or similarly significant effects on you.

California residents (CCPA / CPRA)

If you are a California resident, you have the right to know what personal information we collect, use, disclose, and retain; the right to delete personal information we hold about you; the right to correct inaccurate personal information; the right to opt out of the sale or sharing of personal information; and the right not to be discriminated against for exercising these rights. HappyReplies does not sell or share personal information as defined under the CCPA/CPRA, and we do not use it for cross-context behavioral advertising. To exercise any right, email team@happyreplies.com from the address on your account or use the in-app delete flow; we verify requests by matching the account email and respond within 45 days. You may designate an authorized agent to submit a request on your behalf with written permission.

Children

HappyReplies is a tool for businesses and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has created an account, email us and we will delete it.

Your rights

If you are in the EEA, UK, or another jurisdiction with equivalent data-protection law, you have the right to access, correct, delete, port, restrict, or object to the processing of your personal data, and to withdraw consent where processing is based on consent. You can export your replies to CSV at any time from the History page and delete your account in one click from Settings. For anything not available in-app, email us at team@happyreplies.com. We respond to verified requests within 30 days. You also have the right to lodge a complaint with a data-protection authority — in the UK, the Information Commissioner's Office (ico.org.uk); in the EU, the supervisory authority for your country of residence.

Data breach notification

If we become aware of a personal-data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware and, where the risk is high, notify you directly without undue delay.

Data controller

HappyReplies is operated by Rhys Morgan, trading as HappyReplies. Rhys Morgan is the data controller for personal data processed through the service. For GDPR data-subject requests (access, correction, deletion, portability), email team@happyreplies.com and we will respond within 30 days. Postal address: HappyReplies, 447 Broadway, 2nd Fl #793, New York, NY 10013, United States.

Changes to this policy

We may update this policy as the product changes or as new subprocessors are added. For material changes we will email account holders and post a notice in-app before the change takes effect. The date at the top of this page reflects the most recent revision.