Legal

Privacy Policy

This policy explains what personal data ReplyRate collects, why we process it, how long we keep it, who we share it with, and the rights you have under UK GDPR. We keep it plain and specific on purpose.

Last updated: 4 July 2026

1. Who we are (data controller)

ReplyRate ("we", "us", "the service") is operated by ReplyRate Ltd, a company registered in England and Wales. We are the data controller for personal data we process about you. You can reach us any time at hyder@replyrate.ai.

2. What personal data we collect

We collect and process the following categories of personal data:

2.1 Account data

  • Email address (used for sign-in)
  • Display name (optional, set at sign-up)
  • Authentication ID (a unique identifier we use internally)
  • Stripe customer ID (only if you subscribe)
  • Subscription status, plan, and renewal date

2.2 Service usage data

  • CV content you upload or generate
  • Cover letter drafts
  • Interview preparation notes and answers
  • Saved job applications, interview events, and contacts
  • Voice interview audio (transcribed by OpenAI's gpt-4o-transcribe speech-to-text model, then discarded)
  • Email content you paste to be scored
  • Settings, preferences, and user-specific configuration

2.3 Analytics data

  • Page views, button clicks, and feature usage
  • Browser type, operating system, and approximate region (country-level only)
  • Session duration and navigation patterns

2.4 Technical data

  • IP address (used for rate limiting and abuse prevention)
  • Basic device information (for security purposes)

3. How we collect this data

  • Directly from you when you create an account, fill in profile fields, or use a feature
  • Automatically as you interact with the service (analytics, technical data)
  • From third parties only when you authorise it (for example, signing in with Google shares your Google email with us)

Anonymous page counts

We keep a simple daily count of how many times a few pages are opened, such as the pricing page, so we can see how many people reach them. This count is not personal data and it is not analytics in the usual sense: we add one to a number for that day. Alongside it we keep how long the page was on screen and which country the visit came from, both described just below, and nothing else. No cookie is set, no identifier is recorded, and your IP address is not saved. Two visitors cannot be told apart in these figures, and no one can be followed from one day to the next. Because there is nothing in it that relates to you, it runs whether or not you accept cookies, and there is nothing in it for us to show you or delete on request.

Where visits come from

With those counts we keep a tally of which countries our pages are opened from, so we can see where the people using a UK job-search service actually are. It is one number per country per month: add one to the figure for that country, and nothing else. No cookie, no identifier, no record of any individual visit.

Your IP address is still not saved. The country is worked out from the connection at the moment the request arrives — the same way a website knows which language to offer — and the address itself is never written down. We store the two-letter country code and not the city, the region, the postcode or anything more precise, and we never combine it with what was opened, so there is no record anywhere of a particular page being opened from a particular place.

We also refuse to publish a country that would identify anybody. Any country with fewer than five visits in a month is added into an Other total instead of being named, and after the month closes the individual figures below that threshold are deleted rather than simply hidden from view. Somebody being the only visitor from a small country that month should not be a fact we hold.

These are counted requests rather than people. Nothing here separates a person from an automated crawler, so a crawler running in a data centre counts as that data centre's country. We would rather tell you that than present the figure as a visitor count.

Like the other two, this does not relate to you, so it runs whether or not you accept cookies, and there is nothing in it for us to show you or delete on request — a number that says four thousand visits came from the United Kingdom contains nothing of yours to return.

Anonymous time on a page

Beside those counts we keep how long our pages are actually on screen, so we can tell which ones people read and which ones they pass straight through. It is recorded under the same rule: numbers per page per day, added to, with nothing stored that relates to you. No cookie, no identifier, no IP address, and no record of any individual visit — only a running total of seconds, how many times the page was opened, and a tally of how many visits fell into each of six length bands (under ten seconds, ten to thirty seconds, and so on). Nothing is stored on your device at any point.

The clock runs only while the page is actually visible in front of you: switch to another tab and it stops, come back and it starts again. It does not start at all until the page has seen a sign that a person is there rather than an automated crawler — a mouse move, a tap, a key or a scroll — and a single visit can contribute at most thirty minutes. We call this engaged time rather than time on page because that is honestly what it is: if you read a page without touching anything, we count that the page was opened and we record no time at all.

This is separate from the analytics in section 2.3, which runs through PostHog only after you accept cookies and does relate to you. These figures do not relate to you, so they run whether or not you accept cookies, and there is nothing in them for us to show you or delete on request.

4. Why we process your data (legal basis)

We rely on the following legal bases under UK GDPR Article 6:

4.1 Performance of a contract

  • To provide the service you signed up for
  • To process payments and manage your subscription
  • To run features such as CV tailoring, contact finding, scoring and interview prep

4.2 Legitimate interests

  • To improve the service using aggregated, anonymised analytics
  • To prevent fraud, abuse, and unauthorised access
  • To respond to your support requests

4.3 Consent

  • Optional analytics cookies
  • Marketing email — we do not currently send it; if we ever do, it will be opt-in only

4.4 Legal obligation

  • Where we must retain records for tax, accounting, or law-enforcement reasons

5. Who we share data with (processors)

We share personal data with the service providers below, each acting under contract and with its own privacy policy. Every provider outside the UK/EEA is covered by UK and EU Standard Contractual Clauses (SCCs).

ProviderPurposeLocation
StripePayment processing and subscription managementUS (SCCs)
Firebase / Google CloudAuthentication, database, hostingUS (SCCs)
VercelApplication hosting and edge functionsUS (SCCs)
AnthropicAI generation (CVs, cover letters, scoring, interview prep)US (SCCs)
OpenAIAI generation and speech-to-text transcription (gpt-4o-transcribe)US (SCCs)
Apollo.ioHiring-contact enrichmentUS (SCCs)
HunterEmail finderUS/EU
JinaAI embeddingsEU/US
PostHogProduct analytics (EU-hosted)EU
SentryError monitoring (EU-hosted). Crash reports only — no cookie and no identifier, and your IP address is not stored. Sentry does derive an approximate city from it as the report arrives, and keeps thatEU
We do not sell your personal data, and we do not share it with advertisers.

6. International transfers

Some processors are based outside the UK/EEA, primarily in the United States. We rely on UK and EU Standard Contractual Clauses to ensure an adequate level of protection. You can request a copy of these arrangements at hyder@replyrate.ai.

7. How long we keep your data

  • Account and usage data: for as long as your account is active, plus 30 days after deletion (to settle any pending billing)
  • Analytics data: raw events for 90 days; aggregated statistics indefinitely. The country tally described in section 3 is thinned once a month, with any country below the five-visit threshold deleted and added into an Other total
  • Email content you paste for scoring: processed in memory, not stored permanently
  • Billing records: 6 years after the relevant tax year (UK accounting requirement)

8. Your rights (UK GDPR Articles 15–22)

You have the following rights over your personal data:

8.1 Access

Download a full export of your data via Settings › Account › Export data — a machine-readable JSON file with your account info, applications, calendar, profile, settings and drafts.

8.2 Rectification

Update your details in Settings, or email us for anything you cannot change yourself.

8.3 Erasure ("right to be forgotten")

Delete your account permanently via Settings › Account › Delete account. This removes your data across our databases and cancels any active subscription. Some records (billing) may be retained where the law requires.

8.4 Data portability

The export above is provided in a standard, machine-readable JSON format that is portable to other services.

8.5 Restrict processing

Email hyder@replyrate.ai to request restriction.

8.6 Object

Email hyder@replyrate.ai to object to processing based on legitimate interest.

8.7 Withdraw consent

Withdraw consent for analytics cookies via the cookie preferences in the site footer, or revoke all consent by deleting your account.

8.8 Complain

If you are unhappy with how we handle your data, you can complain to the UK Information Commissioner's Office (ICO): ico.org.uk, phone 0303 123 1113.

9. Children

ReplyRate is not intended for anyone under 18. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.

10. Security

We use industry-standard safeguards, including:

  • TLS encryption for all data in transit
  • Access controls and security rules on our databases
  • Stripe-managed payments — we never see or store your card number
  • Hardened, reputable infrastructure providers

No system is completely secure. If we discover a personal-data breach affecting you, we will notify you and the ICO within 72 hours, as required by UK GDPR.

11. Changes to this policy

We may update this policy from time to time. Material changes will be notified by email or in-app, and the "Last updated" date above will always reflect the current version.

12. Contact us

For any privacy question, data subject access request, or complaint:

Email: hyder@replyrate.ai
Post: ReplyRate Ltd, United Kingdom