Privacy Policy
Last updated: September 2026
AI Reply Writer (“we”, “us”, “the Service”) provides a Chrome extension and a web app that help you draft and summarize replies on the sites you already use. This notice explains what we collect, why we collect it, who else sees it, and the choices and rights you have. We have tried to describe what the product actually does rather than list every possibility, so you can tell what applies to you.
If you do not agree with this notice, please stop using the Service. Questions at any time: support@aireplywriter.com.
Contents
- Who we are
- What information we collect
- How we use your information
- AI processing of your content
- The Chrome extension and its permissions
- Cookies and local storage
- Who we share information with
- International transfers
- How long we keep information
- How we keep information safe
- Your privacy rights
- California residents (CCPA/CPRA)
- Do-Not-Track signals
- Children
- Changes to this notice
- How to contact us
1. Who we are
AI Reply Writer operates the website https://aireplywriter.com, the web app, and the “AI Reply Writer” Chrome extension. For data-protection purposes we are the controller of the personal information described here.
The Service is operated by Grow Rankly LLC, a limited liability company formed in the State of New Mexico, United States, whose address for correspondence is:
Grow Rankly LLC
1209 Mountain Rd Pl NE, Ste 6410
Albuquerque, NM 87110
United States
Contact for any privacy matter: support@aireplywriter.com.
2. What information we collect
Account information. Sign-in is handled by Clerk, our authentication provider. When you register — with an email and password, or with “Continue with Google” — Clerk passes us your email address, a unique account identifier, and, if you used Google, the name and profile picture on that Google account. We never receive or store your password, and signing in with Google gives us no access to your Gmail, Drive, contacts, or any other Google service.
Content you submit for drafting. To generate or summarize a reply, the extension or app sends the text you have chosen — the conversation, post, comment, review, or page content you are replying to or asking about — and media that is part of that content — images, a voice note or other audio you are replying to, and documents such as PDFs — to our server, which forwards it to an AI model provider to produce your result. If the conversation contains links, our server may fetch those links to read what they point at, so the reply can take the linked page into account. We do not store the body of this content in our database after your result is returned, we do not sell it, and we do not use it to build advertising profiles or to train AI models. The deliberately narrow exceptions — each described in its own paragraph below — are corrections you make to drafts, the contact memory and commitments features, knowledge you add yourself, and a cache of link summaries and generated audio.
Drafts you correct, and instructions you give. There is one deliberate exception to the sentence above, and it is worth reading. If you change a draft before sending it, or ask for it to be rewritten with an instruction such as “shorter” or “less formal”, we keep that correction — the draft as written, your version of it, and any instruction you typed — so the Style agent can learn how you write and produce drafts that need less correcting. This is stored in your account, and it is the one part of your drafting content that is.
What that means in practice: the version you actually send is a message intended for a real person, and it stays on file. So three limits apply. It is only ever used to describe your own writing back to you — never to train an AI model, never shared with another user, never sold. The description it produces is about voice, not content: the Style agent is instructed to record habits like “signs off with just a first name” and never facts like where you work or who you were writing to. And you can delete all of it at any time — the samples and the profile built from them — from your writing-style settings, or by emailing us. Corrections that are only a typo fix are discarded rather than stored.
Business knowledge you add. If you fill in “About You” / “About Your Business”, or add documents to the knowledge feature — a refund policy, a price list, an FAQ — we store that text in your account, split into retrievable pieces with search embeddings, so replies can be grounded in your own facts. It is yours alone: never shared with other users, never used to train models, and you can view and delete it at any time from your settings. Delete a document and its pieces go with it.
Contact memory. So that a reply can sound like someone who has met the other person before, we keep a short, durable profile of the people you reply to: the name or handle as it appeared on screen, a one-line summary of who they are to you, a capped list of reply-relevant facts and open promises, and how formally you write to them. We do not keep transcripts or a message archive for this — the profile exists precisely so the raw conversation does not have to be kept. These notes describe people who have not signed up to our Service, so they are held to the narrowest design we could build: scoped to your account only, never combined across users, never used to build a profile of anyone beyond your own reply context, hard-capped in size per person, and listable and deletable by you — individually or all at once — from your profile page. It is deleted along with your account, in full, when you delete that account.
Where contact memory goes. These notes are not kept only to be looked at — their purpose is to be used, so the relevant ones are placed into the request that produces your reply. That means a contact’s name and the short facts stored about them are sent to the AI provider serving the model you chose, in the same way the conversation itself is, and are covered by section 4. We send no account identifier with it: the provider receives the text and nothing that says whose it is. If you would rather nothing about a particular person were used this way, delete that person from your profile page and nothing further about them is stored or sent.
Commitments and follow-ups. When a conversation you submit contains a promise — “I’ll send the quote on Friday”, in either direction — we may store that one line, with the contact’s name, the due date if one was given, and its open/done status, so the follow-up list can remind you. You can mark these done or delete them at any time, and they are deleted with your account.
Reply feedback. If you rate a draft with a thumbs up or down, we store the vote together with the rated reply, the message it answered, and the chat title, linked to your account, so we can find and fix bad output patterns.
Voice features. The microphone button uses your browser’s own speech recognition to turn what you say into text: the audio is processed by your browser vendor’s speech service under their terms, and we receive only the recognised text, which is treated like any typed instruction. If you have a reply read aloud, its text is sent to our server and synthesised into speech by the AI provider; the resulting audio is kept in a cache keyed by the text itself (not by your account), so the same sentence is never synthesised twice.
Link previews. When our server reads a link found in a conversation, it keeps a short title-and-summary of that page in a cache keyed by the web address — not by your account — so a link shared in many conversations is only fetched once. The cache holds what the page says, never who submitted it.
Diagnostics from the extension. So we can tell when a button stops appearing after a website changes its layout, the extension reports events describing what happened, not what you wrote: the platform (for example “Gmail”), the button or anchor position involved, whether it succeeded, an error category and message, the model used, an HTTP status, the extension version, the URL of the page the event happened on, and your account id and email if you are signed in.
Usage records. For each generation we record which model was used, whether it counted as a regular or advanced request, whether it came from the web app or the extension, how many credits it consumed, and whether it succeeded. This is what enforces your plan’s monthly allowance.
Approximate location and timezone. To show times correctly and set sensible defaults, the extension asks the free service ipwho.is for the timezone, city, and country associated with your IP address. Your IP address is visible to that service when this happens. The result is cached on your own device and refreshed occasionally; we do not store it in our database. If the lookup fails or is blocked, the extension falls back to your device’s own timezone and nothing is lost.
Support tickets. If you report an issue or send an enquiry, we store the name, email, and message you provide so we can reply and keep a record.
Billing. If you buy a paid plan, Stripe collects and processes your payment details and we store only an identifier linking your account to your Stripe customer and subscription status. We never see or store full card numbers.
3. How we use your information
We use the information above only for the purposes below. For people in the UK, EEA, and Switzerland, the “legal basis” column is the ground we rely on under the GDPR.
| Purpose | Information used | Legal basis |
|---|---|---|
| Provide the Service — generate and summarize replies | Content you submit, account | Performance of our contract with you |
| Create and manage your account, keep you signed in | Account information | Performance of a contract |
| Enforce plan allowances and prevent abuse | Usage records, account | Legitimate interests — running a sustainable service |
| Keep the extension working as websites change | Diagnostics | Legitimate interests — reliability |
| Learn how you write, so drafts need less correcting | Drafts you corrected, instructions you gave | Legitimate interests — making the product work as promised; you can object or delete at any time |
| Ground replies in your own facts | Business knowledge you added | Performance of a contract — you added it for exactly this |
| Remember who you are replying to, and what was promised | Contact memory, commitments | Legitimate interests — coherent replies and follow-ups; you can delete either at any time |
| Read links shared in a conversation | Link previews | Legitimate interests — replies that account for what a link says |
| Read replies aloud without re-synthesising them | Cached synthesised audio | Legitimate interests — performance and cost |
| Find and fix bad output patterns | Reply feedback | Legitimate interests — quality; you choose whether to rate |
| Answer support requests | Support tickets, account | Performance of a contract; legitimate interests |
| Take payment and manage subscriptions | Billing identifiers | Performance of a contract; legal obligation (tax records) |
| Show correct times and regional defaults | Approximate location, timezone | Legitimate interests — usability |
| Send service notices about changes that affect you | Account information | Legitimate interests; legal obligation |
| Comply with law and respond to lawful requests | As required | Legal obligation |
We do not sell your personal information, we do not share it for cross-context behavioural advertising, and we do not use your submitted content for marketing. Where we rely on legitimate interests, you can object — see section 11.
4. AI processing of your content
Generating a reply requires sending your selected content to an AI model. Depending on the model you pick, that is:
- Google (Gemini API) — for the Gemini models.
- OpenRouter — which routes the request onward to the provider that serves the model you chose, such as OpenAI or Anthropic.
The same applies to media in that content: an image is described, and a voice note is transcribed, by the AI provider, so its contents can be taken into account — this happens only when you ask for a reply to a message that carries that media.
These providers process your content to produce the response and handle it under their own terms and privacy policies, which we encourage you to read. We do not control their internal retention. We ourselves do not retain the content of your requests after returning your result, and we never use it to train models.
Please treat AI output as a draft. It can be wrong, and you should read anything before you send it. Avoid submitting content you are not permitted to share with a third-party processor — for example material covered by a confidentiality obligation, or special-category data such as health information.
5. The Chrome extension and its permissions
The extension asks for only what it needs. Chrome shows you the permissions below before you install — except the last one, which is optional: it is not part of the install, and the extension asks for it separately, at the moment it would be used, if you choose that feature.
- Access to the listed websites — so it can place the “AI Reply” button in the right place and read the specific conversation you ask it to draft a reply for.
- activeTab and scripting — so that when you click the toolbar icon, it can open the on-page assistant and read the current page’s text to answer your question.
- storage — to remember your preferences, the cached timezone lookup, and the link to your account.
- contextMenus — to add the “AI Review” entry to the right-click menu on the Chrome Web Store.
- sidePanel — to open the store-review drafter in Chrome’s side panel beside the listing you are reviewing.
- tabs — optional, and off unless you turn it on — Chrome describes this to you as “Read your browsing history”, and it is the broadest permission we ask for, so it is worth being precise about. It lets us read the address and title of your open tabs. The extension does not hold it. It is listed as an optional permission, so it is not granted when you install and Chrome never shows it to you at install time. The only way it is ever granted is if you open the store-review drafter and press “Use the name from this tab” — Chrome then asks you, in its own dialog, and you can say no. We use it for one thing: reading the name of the Chrome Web Store listing you are looking at, so the drafter can fill it in instead of asking you to type it. Chrome forbids extensions from running any code at all on the Web Store’s pages, so there is no other way to know which item you are reviewing. If you never press that button, the permission is never requested and the extension cannot read any tab’s address. If you do grant it, you can take it back at any time from chrome://extensions → Details → “Site and permission settings”, and the drafter simply goes back to asking you to type the name. We do not log your tab addresses, build a browsing history, or send this anywhere — the name is read at the moment you open the drafter and kept only in the browser’s session storage until you close it.
The extension also fetches a small configuration file from our server from time to time — a description of where each supported website currently places its buttons and messages — so that layout fixes reach you without waiting for an extension update. That request carries no page content and nothing about you; it is configuration data, not code, in line with Chrome’s rules.
The extension reads page content only in response to something you do — clicking the AI Reply button or the toolbar icon — and only to produce the result you asked for. It does not run in the background collecting the pages you visit, and it does not read pages on websites outside its listed set. Our AI provider keys stay on our server and are never exposed to the websites you visit or stored in the extension.
A note about Gmail specifically. The extension works on Gmail the same way it works on any other supported website: through a content script on mail.google.com that runs when you use it. It does not use the Gmail API, requests no Gmail OAuth scopes, cannot read your mailbox in the background, cannot access your archive or history, and cannot send email on your behalf. If that ever changes, this notice will be updated before the feature ships.
6. Cookies and local storage
We keep this deliberately small. Our authentication provider sets a session cookie so you stay signed in — this is strictly necessary and the Service cannot work without it. The website and extension also use your browser’s local storage to remember preferences such as your chosen language, theme, and text size, and to cache the timezone lookup described above. We do not use advertising cookies, third-party tracking pixels, or cross-site advertising networks. Blocking or clearing this storage will sign you out and reset your preferences, but nothing else breaks.
7. Who we share information with
We share information only with service providers who process it on our behalf to run the Service, and only as far as their part requires:
- Clerk — authentication and account management.
- Vercel — hosting of the website, app, and API.
- Neon — our PostgreSQL database.
- Google (Gemini API) and OpenRouter (routing to providers such as OpenAI and Anthropic) — AI generation.
- Stripe — payment processing and subscriptions.
- Resend — delivering support and service emails.
- ipwho.is — timezone and approximate city from IP, as described in section 2.
Beyond these, we may disclose information where we are legally required to — to comply with applicable law, a court order, or a lawful request from a public authority — or where necessary to investigate suspected abuse, fraud, or threats to someone’s safety, or to establish or defend legal claims. If we are ever involved in a merger, acquisition, or sale of assets, information may be transferred as part of that transaction; we would notify you and this notice would continue to apply until replaced.
We do not sell your personal information and we do not share it with data brokers or advertising networks.
8. International transfers
We and our service providers operate internationally, and the providers listed above are largely established in the United States. If you use the Service from the UK, EEA, Switzerland, or elsewhere outside the US, your information will be transferred to and processed in countries whose data-protection laws may differ from your own. Where we transfer personal information out of the UK or EEA, we rely on appropriate safeguards — typically the European Commission’s Standard Contractual Clauses and the UK Addendum, incorporated into our agreements with those providers. You can ask us for details of the safeguards that apply by emailing support@aireplywriter.com.
9. How long we keep information
| What | Kept for |
|---|---|
| Content you submit for drafting | Not retained after your result is returned |
| Drafts you corrected, and instructions you gave | Kept while your account is open, so the Style agent can learn your voice. Deleted the moment you clear your writing style, and with your account |
| Business knowledge you added | Until you delete it, and with your account |
| Contact memory | Until you delete it (per person or all at once), and with your account; hard-capped in size per person |
| Commitments / follow-ups | Until marked done, dropped, or deleted, and with your account |
| Reply feedback | While your account is open, then deleted or anonymised |
| Link previews | Cached by web address, not linked to any account; pruned as the cache is swept |
| Synthesised audio (read-aloud) | Cached by content hash, not linked to any account; unused entries are swept |
| Account information | While your account is open, then deleted or anonymised |
| Usage records (for plan allowances) | While your account is open, then aggregated |
| Diagnostic events | A limited period for reliability and abuse-prevention, then deleted or aggregated |
| Support tickets | As long as needed to resolve your request and for our records |
| Billing and tax records | As long as tax and accounting law requires, typically several years |
Where information cannot be deleted immediately — for example because it sits in an encrypted backup — we isolate it from further processing until deletion is possible.
10. How we keep information safe
We use industry-standard technical and organisational measures: encrypted connections (HTTPS) everywhere, AI provider keys held server-side and never shipped to the browser or extension, access to production data limited to those who need it, and authentication delegated to a specialist provider so we never handle your password. No method of transmission or storage is completely secure, and we cannot guarantee absolute security, but we work to protect your information and will notify you and the relevant authority of a qualifying breach as the law requires.
11. Your privacy rights
Depending on where you live, you may have the right to: access a copy of your personal information; correct information that is inaccurate; delete your information; restrict or object to processing, including processing based on legitimate interests; receive your information in a portable format; and withdraw consent where we relied on it, without affecting processing that already happened.
To exercise any of these, email support@aireplywriter.com from the address on your account. We will respond within the time the applicable law allows — one month under the GDPR, extendable where a request is complex — and we may need to verify your identity first, using information we already hold rather than asking for more where we can avoid it. We will not charge you or treat you differently for exercising these rights.
Several of these rights need no email at all: your writing-style samples and profile, your business knowledge, your contact memory, and your commitments can each be viewed and deleted directly from your account settings and profile pages.
Deleting your account deletes the data with it. Use “Delete account” on your profile page, or email us. This removes the drafts you corrected and the style profile built from them, your business knowledge and documents, your contact memory and commitments, your reply feedback, any team you own along with the invitations you sent, and the account record itself. A small number of operational records are kept with your identity stripped out rather than deleted, because they are needed without it: the usage counts that enforced your plan, error diagnostics, and any support ticket that concerned a payment. You can also stop all collection immediately by signing out and uninstalling the extension.
If you are not a user of the Service
You may be in our records without ever having signed up, because someone who does use the Service replied to you with it. In that case we hold what section 2 calls contact memory: your name or handle as it appeared on that person’s screen, a one-line note of who you are to them, a capped list of reply-relevant facts and any open promises between you, and how formally they write to you. We never hold a transcript of your messages, we do not combine these notes across different users, and they are never used to build a profile of you outside that one person’s reply context.
You have the same rights over that information as anyone else — to know what is held, to have it corrected, and to have it erased. Email support@aireplywriter.com and tell us enough to find you: the name or handle you would have appeared under, and the platform. We will ask for what we need to be confident you are who you say you are, and no more.
Two honest limits. Because these notes are stored under the account of the person who wrote to you and are keyed by the name shown on their screen, we may need your help to locate them, and we cannot tell you who else holds notes about you without disclosing that person’s information in turn. And the quickest route is usually the other one: the person you were messaging can delete you from their profile page at any moment, individually, and it takes them one click.
If you are in the EEA or UK and think we have handled your information unlawfully, you may complain to your local supervisory authority — the EEA authority list, the UK’s ICO, or Switzerland’s FDPIC. We would appreciate the chance to address it first.
12. California residents (CCPA/CPRA)
If you are a California resident, you have the rights to know, delete, correct, and opt out described below, and you will not be discriminated against for using them.
Categories we collect. In the past twelve months we have collected:
| Category | Examples | Collected |
|---|---|---|
| A. Identifiers | Email address, account identifier, name and profile picture if you sign in with Google, IP address (seen by ipwho.is at the moment of lookup) | Yes |
| B. California Customer Records information | Name and email in support tickets; billing identifiers | Yes |
| C. Protected classification characteristics | Age, gender, race, religion | No |
| D. Commercial information | Plan purchased, subscription status, credits consumed | Yes |
| E. Biometric information | Fingerprints, voiceprints | No |
| F. Internet or network activity | Diagnostic events including the page URL an event occurred on; which features you use | Yes |
| G. Geolocation data | Approximate city, country, and timezone derived from IP | Yes — coarse only, never precise device location |
| H. Audio, visual, or similar information | Images and voice notes contained in content you submit for drafting (processed, not retained); synthesised speech for read-aloud (cached by content hash) | Yes |
| I. Professional or employment information | Employment history, job applications | No |
| J. Education information | Student records | No |
| K. Inferences | Your writing-style profile (learned from drafts you corrected); the short contact summaries described in section 2. Both are scoped to your own account and deletable by you at any time | Yes |
Sensitive personal information. We do not ask for it. Content you choose to submit for drafting could contain it, which is why we do not retain that content and why we ask you not to submit anything you should not share with a processor.
Selling and sharing. We have not sold personal information or shared it for cross-context behavioural advertising in the past twelve months, and we do not intend to. We disclose the categories above to the service providers listed in section 7 for the business purposes in section 3.
To exercise a California right, email support@aireplywriter.com. You may use an authorised agent if they provide proof of authorisation. Under the “Shine the Light” law you may also request the categories of personal information disclosed to third parties for their own direct marketing — we disclose none.
13. Do-Not-Track signals
There is still no finalised standard for Do-Not-Track, so we do not respond to DNT browser signals. This matters little here: we do not run cross-site advertising trackers in the first place. If a standard is adopted that applies to us, we will follow it and update this notice.
14. Children
The Service is not directed to children under 13, or under the minimum age of digital consent where you live (16 in parts of the EEA), and we do not knowingly collect their personal information. If you believe a child has given us information, email support@aireplywriter.com and we will delete it.
15. Changes to this notice
We may update this notice as the Service changes or the law does. The “Last updated” date above always reflects the current version. If a change materially affects your rights or how we use your information, we will give notice within the Service or by email before it takes effect where we reasonably can.
16. How to contact us
For any question, request, or complaint about this notice or your personal information: support@aireplywriter.com. See also our Terms of Service.