← Reply Hotter

Legal

Privacy Policy

Last updated: September 3, 2026 · Effective: September 3, 2026

The promise on the upload card is the real one: your screenshots are not saved. They are sent to an AI model, read, and dropped — unless you tick the research box yourself. What we do keep is the reconstructed text of your conversations so the app can show you your threads, plus the boring account and billing facts. We don't sell any of it, and we don't run ad trackers.

Contents

  1. Who we are
  2. Screenshots: what happens to them
  3. What we collect
  4. What we don't collect
  5. How we use it
  6. Who we share it with
  7. The research opt-in
  8. Other people in your screenshots
  9. Cookies and local storage
  10. How long we keep things
  11. Your controls and rights
  12. US state privacy rights
  13. International users
  14. Security
  15. Children
  16. Changes to this policy
  17. How to reach us

1.Who we are

Reply Hotter is operated by Clarity Decoded, in Austin, Texas. This policy explains what personal information the Service handles, why, and what you can do about it. It forms part of our Terms & Conditions. For privacy questions, write to legal@replyhotter.com.

2.Screenshots: what happens to them

This is the part people actually want to know, so here is the whole sequence:

  1. You upload one or more screenshots from your device.
  2. They are sent over an encrypted connection to our server, and from there to an AI model provider (Google's Gemini models, or OpenAI as a fallback) so the conversation can be read.
  3. The model returns a reconstruction of the conversation as text, plus four suggested replies.
  4. We keep the reconstructed text and the suggested replies, so your thread is still there when you come back and so later rounds understand the history.
  5. The image files themselves are discarded. They are not written to our database and there is no screenshot archive.
The single exception: if you tick the research checkbox on the upload card, or turn on the standing permission in Settings > Privacy, that round's images are saved so we can review them and improve the product. That choice is off by default, it is yours to make, and you can reverse it at any time.

3.What we collect

Account information

Your email address, and — if you sign in with Google — the basic profile Google returns (name, profile picture URL and a Google account identifier). If you sign up with email and password, authentication is handled by Supabase, which stores a hashed password. We never see your Google password, and we do not store your Reply Hotter password in readable form. We also keep your plan, role, referral code and the date the account was created.

Conversation content

The reconstructed text of the conversations you upload, the suggested replies generated for them, an optional label you give a thread, and your notes on it. This is stored server-side and associated with a per-device identifier your browser generates, and with your account once you sign in. If you use Relationship Mode, the context you choose to record about that relationship is stored too.

Device and session records

For each signed-in device we keep a session record: a hashed session token, a short device description (such as the browser and operating system), the times it was created and last used, and an approximate location derived from the network connection at city or region level. Location metadata is optional — turn it off in Settings > Privacy and we stop recording it and clear what we already had for your sessions.

Usage and billing

Which plan you are on, how many rounds you have used in the current window, your usage-credit balance, your spend limit and auto-reload settings, a record of each round for metering, your purchase history and receipt links, and identifiers Stripe gives us for your customer and subscription records.

Product analytics

A deliberately content-free event log: the type of event, which model provider served a round, whether it succeeded, which heat level was copied, how long it took, and where people drop off. No screenshots, no message text and no generated replies are written to the analytics store. It records the shape of behaviour, not what was said.

Security signals

Cloudflare, which hosts the Service, processes technical request data such as IP address and user agent to route traffic and to stop attacks, and we use Cloudflare Turnstile to tell humans from bots. This is standard infrastructure logging, handled by Cloudflare as our provider.

4.What we don't collect

  • Your screenshots, unless you opt in per round or in Settings.
  • Your card number. Card details go straight to Stripe; we see only the last four digits and card brand that Stripe reports back, plus the identifiers it gives us.
  • Your contacts, photo library, camera roll or messages. The Service only ever receives the specific images you choose to upload.
  • Precise location. We never ask for GPS or device location permission.
  • Advertising or cross-site tracking data. There are no ad networks, no third-party analytics scripts and no tracking pixels on this site.
  • Special-category data by design. We don't ask for your race, religion, health, politics or sexual orientation. Conversations you upload are personal by nature, which is exactly why images aren't kept and analytics is content-free.

5.How we use it

  • To run the Service: read your screenshots, generate replies, keep your threads, remember your settings.
  • To keep your account secure: sign you in, show you your active devices, let you revoke them, and detect abuse.
  • To bill you correctly: meter rounds, apply plan allowances and credits, process payments and issue receipts.
  • To improve the product: using the content-free analytics log, and — only where you opted in — reviewing kept submissions to judge whether the replies are any good.
  • To communicate: service messages such as password resets, receipts, and notices about changes to these documents.
  • To comply with the law and to enforce our Terms.

We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We don't use your conversations to build advertising profiles.

Where the GDPR or UK GDPR applies, our legal bases are: performance of a contract (running the Service and billing you), legitimate interests (security, abuse prevention, content-free product analytics), consent (the research opt-in and optional location metadata, each withdrawable), and legal obligation.

6.Who we share it with

We share personal information only with the providers that make the Service work, each acting on our behalf and limited to what their job requires:

ProviderWhat it doesWhat reaches it
Cloudflare Hosting, database storage, bot protection Everything the Service stores, plus technical request data
Google Sign-in with Google; Gemini models that read screenshots and write replies Your basic Google profile at sign-in; your screenshots and conversation text at generation time
OpenAI Fallback model when the primary model is unavailable Your screenshots and conversation text, for that round only
Supabase Email and password authentication, password resets Your email address and hashed password
Stripe Payments, subscriptions and receipts Your email address, payment details you enter with Stripe, and purchase records

Content is sent to the AI providers through their APIs. Under the API terms we operate on, data submitted this way is used to serve your request and is not used to train their public models. Those providers may retain data briefly for abuse monitoring under their own policies.

We may also disclose information if the law requires it, in response to a valid legal process, to protect the rights and safety of people or of Clarity Decoded, or in connection with a merger, acquisition or sale of assets — in which case we'll say so before your information becomes subject to a different policy.

7.The research opt-in

There are three ways a submission gets kept, and all three are opt-in:

  • The per-round checkbox on the upload card. Off by default. It applies to the round you are about to run.
  • The standing permission in Settings > Privacy, if you'd rather not decide each time. Off by default, and switching it off stops future retention.
  • A co-founder account, where full visibility is the explicit deal in exchange for rounds at cost, and which is described as such when it's granted.

A kept submission includes the screenshot images, the reconstructed conversation, the replies generated, which reply you copied, and the account it came from. It is reviewed internally by the Reply Hotter team to judge and improve reply quality. It is not published, and it is not sold.

Settings shows how many of your rounds have been kept. Ask us at legal@replyhotter.com to delete them, or delete your account, which removes them automatically.

8.Other people in your screenshots

A screenshot of a conversation contains someone else's words, and often their name and photo. That person is not our user and has no account here, so a few things follow.

Under our Terms, you are responsible for having the right to upload what you upload. We process the other person's information as part of delivering the Service to you. Because their images aren't stored and their text lives inside your thread, the practical way to remove it is for you to delete the thread — or your account.

If you appear in someone else's screenshot and want to raise a concern, write to legal@replyhotter.com. We will need enough detail to identify the material, and we'll do what we reasonably can.

9.Cookies and local storage

There are no advertising or analytics cookies on Reply Hotter. We use only what the app needs to work:

  • Two short-lived cookies during Google sign-in, which protect the sign-in round trip against forgery and remember where to send you back to. They are HttpOnly and expire in ten minutes.
  • Browser local storage on your own device, holding your session token, a per-device identifier for your threads, and preferences such as calm mode and your research choice. Clearing your browser's site data clears them.
  • Cloudflare Turnstile, which may set its own storage to verify you're not a bot.

10.How long we keep things

WhatHow long
Screenshot imagesOnly for the moments it takes to generate the round, unless you opted in
Conversation text and repliesUntil you delete the thread or your account
Account, plan and settingsUntil you delete your account
Session recordsUntil the session is revoked or expires
Opted-in research submissionsUntil you ask us to delete them, or you delete your account
Billing and transaction recordsAs long as tax and accounting law requires, typically several years
Content-free analytics eventsRetained in aggregate; they contain no conversation content

Deleting your account removes your account record, your conversations and any research submissions tied to your email. Backups and provider logs may take a short time to age out, and we keep the minimum needed for legal, tax and fraud-prevention purposes.

11.Your controls and rights

Most of it you can do yourself, right now, in Settings:

  • Export everything. Settings > Account gives you a JSON file with your account, plan, usage, sessions and privacy choices.
  • Delete your account. Settings > Account. This deletes your data as described above, and it is not reversible.
  • Delete a conversation. The trash icon on the thread bar.
  • Turn the research permission on or off. Settings > Privacy, or the checkbox on any upload.
  • Turn off location metadata. Settings > Privacy. Existing session locations are cleared when you do.
  • Sign out a device. Settings > Devices, revoke any session.
  • Cancel billing. Settings > Billing.

Depending on where you live, you may also have the right to access, correct, delete or port your personal information, to object to or restrict certain processing, to withdraw consent, and not to be discriminated against for exercising these rights. Write to legal@replyhotter.com and we'll respond within the time the applicable law allows. We may need to verify your identity — usually by confirming control of the email address on the account — before acting on a request.

12.US state privacy rights

Residents of Texas, California, Colorado, Connecticut, Virginia and other states with comprehensive privacy laws have the rights described above, including the right to know what we collect, to get a copy, to correct it, to delete it, and to appeal a decision we make about a request. To appeal, reply to our decision at legal@replyhotter.com with the word "appeal" and we'll review it again and explain the outcome in writing.

We do not sell personal information, and we do not share it for targeted advertising or cross-context behavioural advertising — under any of these laws' definitions. We do not use personal information for profiling that produces legal or similarly significant effects. We honour browser opt-out preference signals such as Global Privacy Control where they apply, though since we neither sell nor share data for advertising, there is nothing for such a signal to turn off.

You may use an authorized agent to submit a request on your behalf, with proof of their authority.

13.International users

Reply Hotter is operated from the United States, and our infrastructure providers process data on servers in the United States and other countries. If you use the Service from outside the US, your information is transferred to and processed in the US, where privacy law differs from your own. Where required, our providers rely on recognised transfer mechanisms such as the European Commission's Standard Contractual Clauses.

If you are in the EEA or UK, you also have the right to lodge a complaint with your local supervisory authority.

14.Security

Traffic is encrypted in transit. Session tokens are stored hashed, never in the clear. Passwords are hashed by our authentication provider. Access to stored data is limited to the people who need it to run the Service. Not storing screenshots is itself a security measure: the safest data is the data that was never kept.

No system is perfectly secure, and we can't guarantee absolute security. If a breach affects your personal information, we'll notify you and the relevant authorities as the law requires.

15.Children

Reply Hotter is for adults. It is not directed to anyone under 18, and we do not knowingly collect personal information from children. If you believe a minor has given us information, write to legal@replyhotter.com and we will delete the account and its data.

16.Changes to this policy

We'll update this page as the Service changes. The "last updated" date at the top always reflects the current version, and for material changes we'll give notice in the app or by email before they take effect.

17. How to reach us

Clarity Decoded
111 E 17th St #13327
SMB #117122
Austin, TX 78701
United States

legal@replyhotter.com
Reply Hotter
  • Home
  • Terms & Conditions
  • Privacy Policy
  • Contact

© 2026 Clarity Decoded. All rights reserved. Reply Hotter is a trademark of Clarity Decoded.