Privacy Policy

Your privacy is fundamental to us. Learn how we collect, use, and protect your personal information.

Last updated: May 18, 2026

Quick Overview

Your emails stay private

We never use your emails to train AI models

GDPR compliant

Full data control and deletion rights

Transparent tracking

Only with your explicit consent

Data minimization

We only collect what's necessary

1
Introduction

Welcome to ReplyFabric.ai ("we," "our," or "us"). We are committed to protecting your privacy and ensuring transparency about how we collect, use, and protect your personal information. This Privacy Policy explains our practices regarding data collection and use when you visit our website or use our services.

ReplyFabric BV, with registered office at Stanislas Leclefstraat 18, 2600 Antwerp, Belgium, registered under company number 1026329284 (RLE Antwerp) and VAT number BE1026329284, acts as the data controller for the personal data processed as described in this Privacy Policy, such as for website analytics when you visit our website, client relationship management, account administration, billing, security, legal compliance, and direct communications.

When business customers use the ReplyFabric service to process emails, mailbox content, and related data on behalf of their organization, ReplyFabric generally acts as a processor on behalf of that customer, which acts as the controller.

2
Information We Collect

2.1 Information You Provide Directly

  • Contact Information: Name, email address, company name when you sign up for our waitlist or contact us
  • Account Information: When you create an account, we collect your login credentials and profile information
  • Communication Data: Messages, feedback, and other communications you send to us
  • Business Information: Details about your organization, team size, and use case when relevant to our services
  • Connected Mailbox Data: email content, attachments, mailbox metadata, labels, thread information, sender and recipient details, and related configuration data where the Service is connected to a mailbox.

2.2 Information Collected Automatically when you visit our website:

  • Technical Information: IP address, browser type, operating system, device information
  • Usage Data: Pages visited, time spent on our site, click patterns, referral sources
  • Cookies and Tracking Technologies: As described in our Cookie Policy below

2.3 Email Data when you use ReplyFabric's email processing services.

This data may include personal data relating to the Customer’s employees, correspondents, customers, suppliers, and other third parties contained in business email communications, such as :

  • Identification data
  • Contact data
  • Email Content: We process email content to provide categorization and response generation
  • Metadata: Email headers, timestamps, sender/recipient information
  • Team Data: User roles, permissions, and collaboration data within your organization

2.4 Fraud Prevention and Abuse Protection (Google reCAPTCHA)

We use Google reCAPTCHA v3, a service provided by Google LLC, to protect our website and services from spam, bots, and abusive automated activity.

reCAPTCHA operates in the background and analyzes user interactions to determine whether an action is performed by a human or an automated system. This helps us ensure the security and availability of our website, forms, and services.

Data processed by reCAPTCHA may include:

  • IP address
  • Browser and device information
  • Mouse movements, scrolling behavior, and interaction patterns
  • Date and time of interaction
  • Referring URL

This data is processed directly by Google and is subject to Google's own privacy policies.

We do not use reCAPTCHA data for advertising purposes and do not combine it with other personal data to identify individual users.

Google may process this information as an independent controller in accordance with its own privacy documentation. We use reCAPTCHA solely for security, fraud prevention, and abuse protection purposes.

3
How We Use Your Information

3.1 Service Provision

The purposes described below apply depending on the nature of our relationship with you and the context in which the data is processed. Some processing activities are carried out by ReplyFabric as controller, while others are carried out by ReplyFabric as processor on behalf of a business customer, such as:

  • Provide and improve our AI-powered email management services
  • Process and categorize emails as requested
  • Generate AI-powered email responses
  • Facilitate team collaboration features

The disclosure of data with regard to the email management services purposes is further explained under the titles “8a. Google API Data Disclosure” and “8b. Microsoft API Data Disclosure”.

3.2 Business Operations as a controller

  • Provide customer support and respond to inquiries
  • Manage user accounts and access permissions
  • Process payments and billing
  • Send service-related communications
  • Maintain, improve, troubleshoot, secure, and develop our services*

*: we do not use customer emails or mailbox content to train generalized AI models

3.3 Marketing and Analytics as a controller

  • Send marketing communications (with your consent)
  • Analyze website usage and service performance
  • Improve our website and user experience
  • Conduct market research and customer feedback analysis

6
Data Sharing and Disclosure

We do not sell your personal information. We may share your data in the following limited circumstances:

6.1 Service Providers

We work with trusted third-party service providers who help us operate our business:

  • Matomo Cloud: Web analytics (privacy-focused, GDPR-compliant)
  • Cloud Providers: Infrastructure, hosting, storage, analytics, security, communications
  • Payment Processors: For billing and payment processing

We may use carefully selected subprocessors and service providers to help deliver the Service. Where relevant, an up-to-date overview of key subprocessors is made available through our Trust Center, or on request.

6.2 Legal Requirements

We may disclose information when required by law or to:

  • Comply with legal processes or government requests
  • Protect our rights, property, or safety
  • Prevent fraud or security threats
  • Enforce our terms of service

6.3 Business Transfers

In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction.

6.4 Google reCAPTCHA

As part of our security measures, limited technical data may be shared with Google when reCAPTCHA is loaded.

  • Google acts as an independent data controller for reCAPTCHA processing
  • Data is processed according to Google's privacy policies
  • No data is shared for advertising or profiling purposes by ReplyFabric

7
Data Security

We make every effort to guarantee the security of your personal data. We have implemented reasonable technical and organisational measures to guarantee your personal data against accidental or unlawful destruction, loss, modification, unauthorised disclosure and/or unauthorised access to the data transmitted, saved or otherwise processed. Please note that the internet is an open network; we cannot therefore guarantee that unauthorised third parties will not be able to circumvent these measures or use your personal data for inappropriate purposes.

This website may include links to third-party websites. We will not be held liable for the content of these websites, nor for the privacy standards and practices of the corresponding third party. You must read and understand the relevant third-party and website privacy policies before accepting cookies and visiting a website, to ensure your personal data is sufficiently protected.

We implement appropriate technical and organizational measures to protect your personal information, such as:

Encryption

Data is encrypted in transit and at rest

Access Controls

Limited access to personal data on a need-to-know basis

Regular Audits

Security assessments and monitoring

Employee Training

Regular privacy and security training for our team

8a
Google API Data Disclosure

ReplyFabric.ai uses Google OAuth to allow users to connect their Gmail or Google Workspace accounts. This section explains how we access, use, store, and share Google user data, in accordance with Google's API Services User Data Policy, including the Limited Use Policy.

8a.1 Data We Access

With your explicit consent, ReplyFabric may access the following Google data:

  • Gmail messages: Including email subject, body, metadata, sender/recipient, timestamps, and attachments
  • Gmail labels: For organizing processed messages
  • Email metadata: Message-ID, thread ID, headers required for categorization and replying

We do not access Drive, Calendar, Contacts, Photos, or any other Google data.

8a.2 How We Use Google User Data

We use Gmail data solely to provide the core functionality of ReplyFabric:

  • Categorizing incoming emails
  • Detecting intents
  • Drafting AI-powered replies or forwards
  • Processing attachments to extract relevant information
  • Managing shared inbox workflows
  • Synchronizing reply status with your mailbox

We do not:

  • Use Gmail data for advertising
  • Sell Gmail data
  • Use Gmail data to train machine learning models
  • Share Gmail data with third parties except as required to provide the service (e.g., cloud hosting)

8a.3 How We Store Google User Data

Depending on your settings, ReplyFabric may temporarily store:

  • Email metadata
  • AI-generated reply drafts
  • Processing logs (pseudonymized where possible)
  • Attachments (temporarily for processing)

Full email bodies are processed in encrypted systems and stored during 3 months to deliver the feature, unless your organization configures retention for analysis or audit logs.

All data is encrypted in transit and at rest.

8a.4 How Long We Retain Google User Data

  • Email content: Ephemeral, processed and then discarded unless your settings require retention (e.g., shared inbox history)
  • Metadata and logs: Retained only as long as necessary for service functionality
  • Attachments: Discarded after processing unless saved by the user

8a.5 Sharing of Google User Data

We do not share Google user data with:

  • Advertisers
  • Data brokers
  • External third parties for machine learning

Limited sharing may occur with:

  • Cloud hosting providers (for secure processing)
  • Subprocessors listed on our website (all GDPR compliant)

8a.6 Compliance with Google's Limited Use Policy

ReplyFabric conforms to Google's Limited Use Policy:

  • Data is used only to provide, maintain, secure, and improve user-facing features
  • Data is not used to train generalized models
  • Data is not transferred except as required to operate the service
  • Data is not used for ads

8a.7 User Control and Revocation

You can revoke ReplyFabric's access to your Google account at any time:

Once access is revoked, ReplyFabric can no longer read, process, or send emails on your behalf.

8b
Microsoft API Data Disclosure

ReplyFabric.ai uses Microsoft OAuth (via Microsoft Identity Platform) to allow users to connect their Outlook or Microsoft 365 accounts. This section explains how we access, use, store, and share Microsoft user data, in accordance with Microsoft's API Terms of Use and applicable data protection requirements.

8b.1 Data We Access

With your explicit consent, ReplyFabric may access the following Microsoft data via Microsoft Graph API:

  • Outlook / Microsoft 365 messages: Including email subject, body, metadata, sender/recipient, timestamps, and attachments
  • Mail folders and categories: For organizing and routing processed messages
  • Email metadata: Message-ID, conversation ID, headers required for categorization and replying
  • Basic profile information: Display name and email address, used solely for account identification within the Service

We do not access OneDrive, SharePoint, Teams, Calendar, Contacts, or any other Microsoft 365 data beyond what is listed above.

8b.2 How We Use Microsoft User Data

We use Outlook and Microsoft 365 data solely to provide the core functionality of ReplyFabric:

  • Categorizing incoming emails
  • Detecting intents
  • Drafting AI-powered replies or forwards
  • Processing attachments to extract relevant information
  • Managing shared inbox workflows
  • Synchronizing reply status with your mailbox

We do not:

  • Use Microsoft data for advertising
  • Sell Microsoft data
  • Use Microsoft data to train machine learning models
  • Share Microsoft data with third parties except as required to provide the service (e.g., cloud hosting)

8b.3 How We Store Microsoft User Data

Depending on your settings, ReplyFabric may temporarily store:

  • Email metadata
  • AI-generated reply drafts
  • Processing logs (pseudonymized where possible)
  • Attachments (temporarily for processing)

Full email bodies are processed in encrypted systems and stored during 3 months to deliver the feature, unless your organization configures retention for analysis or audit logs.

All data is encrypted in transit and at rest.

8b.4 How Long We Retain Microsoft User Data

  • Email content: Ephemeral, processed and then discarded unless your settings require retention (e.g., shared inbox history)
  • Metadata and logs: Retained only as long as necessary for service functionality
  • Attachments: Discarded after processing unless saved by the user

8b.5 Sharing of Microsoft User Data

We do not share Microsoft user data with:

  • Advertisers
  • Data brokers
  • External third parties for machine learning

Limited sharing may occur with:

  • Cloud hosting providers (for secure processing)
  • Subprocessors listed on our website (all GDPR compliant)

8b.6 User Control and Revocation

You can revoke ReplyFabric's access to your Microsoft account at any time through your Microsoft account settings:

Microsoft 365 administrators can additionally manage and revoke application permissions via the Azure Active Directory admin portal at portal.azure.com. Once access is revoked, ReplyFabric can no longer read, process, or send emails on your behalf.

9
Your Rights

Data protection legislation provides various rights for the data subject with regard to the processing of personal data to ensure the data subject has sufficient control over the processing of their personal data. Depending on your location, you may have the following rights regarding your personal information:

General Rights

  • Information: Request information about how we process your data
  • Access: Receive confirmation from us of whether your personal data is processed by us. If we do process your personal data, you are entitled to request to view and obtain a copy of your personal data.
  • Correction: Update or correct inaccurate information
  • Deletion: Request deletion of your personal data
  • Restriction: request that we limit the processing of your personal data to check the accuracy of your personal data
  • Portability: Receive your data in a machine-readable format
  • Right not to be subject to automated individual decision-making
  • Right to withdraw consent
  • Right to lodge a complaint with the competent data protection authority. In Belgium, this is the Data Protection Authority, Drukpersstraat 35, 1000 Brussels, Belgium.

Marketing Rights

  • Right to object: Opt out of marketing emails at any time via the Unsubscribe-button of the marketing mailing or with regard to other types of processing
  • Preference Management: Update your communication preferences

Exercising Your Rights

To exercise any of these rights, please contact us at privacy@replyfabric.ai. We will respond within the time periods required by applicable data protection law, usually within 30 days.

We can request you verify your identity to ensure your request is lawful and that we are sending the reply to a person entitled to make such a request and to receive the data.

Please note that we may refuse access to your personal data or may not be able to grant your data subjects’ request under specific circumstances when we are entitled to do so under the applicable data protection legislation.

10
International Data Transfers

ReplyFabric primarily aims to store core customer email and mailbox content within the European Union. However, some personal data may be processed by service providers or subprocessors located outside the European Economic Area (EEA), including in the United States, for example in connection with infrastructure, authentication, analytics, diagnostics, AI model services, communications, payments, or abuse prevention. The international transfer of data outside the EEA is legal if the recipient of the data resides in a country covered by an adequacy decision, i.e. a country with a level of protection deemed adequate by the European Commission or by the certification scheme provided by the EU-US Data Privacy Framework. Some of these countries may not have enacted equivalent data protection legislation to protect the use of your personal data. In such cases, we have researched whether appropriate preventive measures similar to those implemented within the EU are possible, for example by adopting standard contractual clauses. In specific cases, we will request your prior consent to the transfer of your personal data outside the EEA. Please follow the procedure set out in Rights of the data subject for further information on data transfer.

11
Children's Privacy

Our services are not intended for children under 16 years of age. We do not knowingly collect personal information from children.

If we become aware that we have collected information from a child under 16, we will take steps to delete such information promptly.

12
Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or applicable laws. We will:

  • Post the updated policy on our website
  • Update the "Last updated" date
  • Notify you of material changes via email or prominent website notice
  • Obtain consent for material changes where required by law

13
Contact Information

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

ReplyFabric Team

Email: privacy@replyfabric.ai

Website: https://replyfabric.ai/contact

Address: Stanislas Leclefstraat 18, 2600 Antwerp (Belgium)

Effective Date

This Privacy Policy is effective as of May 18, 2026 and applies to all information collected by ReplyFabric.ai from that date forward.

Ready to streamline your workflow?

Join us and boost your productivity with ReplyFabric. Start your free trial today and see the difference in just 14 days.

14-day free trial
No setup fees
Cancel anytime