Repraft
How it works Pricing Get started

Repraft LLC — Privacy Policy

Last updated: September 6, 2026

1. Who We Are and What This Policy Covers

Repraft LLC ("Repraft," "we," "us") is an Illinois limited liability company that provides a hosted platform which ingests customer reviews on behalf of business customers, drafts responses to them using AI, and routes those drafts through human review and approval.

This Policy explains how we handle personal information in two distinct roles. The distinction matters, and it determines who you should contact about your data.

1.1 When we are the business (controller)

For information about our customers and their personnel — the people who sign up for Repraft, log into the app, and pay us — we decide how and why the information is used. This Policy governs that information directly.

1.2 When we are the service provider (processor)

For review content and the people who appear in it — the reviews, reviewer names, and anything a reviewer wrote into a review — we process that information only on behalf of, and under the instructions of, the business customer who connected that review source. That business is the controller; we are its service provider under the CCPA and its processor generally.

If you left a review for a business and want to know what happened to your information, or want it deleted, contact that business directly. We will support and route such requests, but we will not act on them independently, because we do not have the relationship or the authority to. If you contact us and we can identify the customer, we will forward your request and tell you we did.

1.3 What this Policy does not cover

This Policy does not cover the review platforms, CRMs, or messaging tools our customers connect to Repraft. Those services have their own privacy policies and their own relationships with you.


2. Information We Collect

2.1 Account and contact information

Name, business email address, business name, job title, phone number, account credentials (stored as salted hashes, never in plaintext), API keys and webhook secrets issued to your account, and your communications with our support team.

2.2 Billing information

Plan, subscription status, billing contact, billing address, invoice and transaction history, and limited payment-instrument metadata (card brand, last four digits, expiration date). We do not collect or store full payment card numbers. Payments are processed by Stripe, which collects card details directly.

2.3 Customer content (processed on our customers' behalf)

Reviews and other customer feedback ingested from connected platforms, including the review text, star rating, timestamps, platform-assigned identifiers, and the reviewer's name or handle as the platform supplies it. Also: response drafts we generate, edits your team makes, approval and rejection decisions, the reviewer, and flags raised by our guardrails.

Reviews are free text written by members of the public. A reviewer may include personal information we did not ask for and do not need — an email address, phone number, an order or account number, a date of birth, or details about their experience. We apply automated masking to a defined set of such patterns before log data leaves our systems (Section 6), but we cannot prevent a reviewer from writing something into a review, and the review itself is retained as your business record.

2.4 Integration data

Connection metadata and access tokens or credentials for the third-party platforms you connect, along with webhook delivery records, retries, and failures.

2.5 Technical and usage data

IP address, browser and device information, timestamps, pages and endpoints accessed, API request metadata, rate-limit and authentication events, error and exception records, performance and latency metrics, and diagnostic logs.

2.6 Cookies and similar technologies

We use cookies that are strictly necessary to authenticate your session, remember preferences, and protect against abuse. We do not currently use analytics, advertising, or cross-context behavioral-advertising cookies. If that changes, this section will be updated before any such technology is deployed.

2.7 Information we do not want

We ask customers not to send us data regulated under HIPAA, GLBA, PCI-DSS, or FERPA, and not to submit government identification numbers, payment card numbers, financial account numbers, or health information. We are not designed for that data and we do not act as a HIPAA business associate. If such data reaches us anyway inside review text, we treat it under the safeguards in Section 6 and delete it under Section 7 when possible.


3. Where the Information Comes From

  • Directly from you — registration, account settings, billing, support requests.
  • From platforms you connect — reviews and review metadata delivered to our webhook endpoints or retrieved from a connected platform's API, at your direction and using credentials you authorize.
  • Automatically from your use — logs, device and network data, and product usage.
  • From service providers — for example, subscription and payment status from Stripe.

4. How We Use Information

Purpose What this involves
Provide the Service Ingest reviews, run sentiment and safety analysis, generate response drafts, route items for approval, deliver notifications
Authenticate and secure Verify accounts and API keys, enforce tenant isolation, rate-limit, detect and investigate abuse, prompt-injection, and unauthorized access
Operate and troubleshoot Monitoring, error tracking, debugging, capacity planning, incident response
Billing Process subscriptions and payments, send invoices, collect amounts due
Communicate Service and security notices, support responses, and — where permitted — product updates you can opt out of
Improve the Service Analyze aggregated, de-identified usage and quality metrics (see Section 4.1 on training)
Comply and protect Meet legal obligations, enforce our Terms, establish or defend legal claims

4.1 AI processing and model training

Review text and related context are sent to our third-party model provider's API to generate sentiment analysis and response drafts. We do not use customer content to train, fine-tune, or improve any machine-learning model, and our model provider is engaged under enterprise API terms that prohibit training on data submitted through the API. Model providers may retain inputs for a limited period for abuse monitoring under their own terms.

Our pipeline is designed to avoid a model call entirely where an input is detected as hostile or as a prompt-injection attempt — such inputs are short-circuited to human review before any drafting step runs.

4.2 No sale, no sharing, no targeted advertising

We do not sell personal information. We do not share personal information for cross-context behavioral advertising. We do not use personal information for targeted advertising, and we have not done either in the preceding twelve months. We do not use personal information for profiling that produces legal or similarly significant effects about an individual.


5. Who We Disclose Information To

We do not sell your information. We disclose it to the following categories of recipients, each under a written agreement limiting use to the services they provide us:

5.1 Subprocessors

Subprocessor Role Data involved
Railway Corp. Application hosting and managed PostgreSQL database All service data, at rest and in processing
Anthropic, PBC Large language model API used for sentiment analysis and response drafting Review text and drafting context sent per request
Axiom, Inc. Log storage, search, and alerting Application logs and telemetry, with sensitive patterns masked before transmission
Sentry (Functional Software, Inc.) Error and exception monitoring Stack traces, error context, and request metadata
Slack Technologies (Salesforce) Approval and alert notifications to customer and internal channels Notification content, including review and draft excerpts routed to your workspace at your configuration
Stripe, Inc. Payment processing and subscription billing Billing contact and payment data collected by Stripe directly

We review this list periodically and will update it as we add or remove subprocessors.

5.2 Other disclosures

  • At your direction — to platforms and destinations you connect or configure.
  • Legal and safety — to comply with law, valid legal process, or a governmental request; to enforce our Terms; or to protect the rights, property, or safety of Repraft, our customers, or the public. Where we are legally permitted, we will notify the affected customer before disclosing their data.
  • Business transfers — in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy or a successor policy with notice to affected customers.
  • Professional advisors — accountants, auditors, and legal counsel, under confidentiality obligations.

5.3 International transfers

Our infrastructure and subprocessors are located in the United States. If you access the Service from outside the U.S., your information will be transferred to and processed in the U.S.


6. How We Protect Information

We maintain administrative, technical, and physical safeguards appropriate to the size of our organization and the sensitivity of the data we handle. Current measures include:

  • Encryption in transit — TLS for all connections to the Service and to our subprocessors.
  • Encryption at rest — database and backup storage encrypted by our infrastructure provider.
  • Database-enforced tenant isolation — PostgreSQL row-level security policies on tenant-scoped tables, so one customer's records are not readable in another customer's session context. Enforcement is at the database level rather than only in application code, and is covered by automated tests that connect as the real application role.
  • Least-privilege database roles — the application connects under a restricted role that cannot read across tenants; broader-privilege roles are separated, used only where required, and their credentials are rotated when exposure is suspected.
  • Automated masking of sensitive patterns in logs — a redaction step runs inside our logging pipeline, before log data is written out or shipped to third-party log storage. It walks the full event structure, including nested values and exception tracebacks, and masks matches across categories including Social Security numbers, payment card numbers, passport and driver's license numbers, medical record and account numbers, dates of birth, email addresses, and phone numbers. This is enforced structurally in the pipeline rather than by developer discipline at each call site.
  • Leak detection and alerting — automated monitors continuously scan shipped log data for unmasked sensitive patterns and alert our team by email and Slack.
  • Adversarial input handling — detectors for hostile content and prompt-injection attempts run before any language-model call, and matching inputs are stopped and routed to human review rather than drafted against.
  • Human review in the loop — response drafts are surfaced for human approval rather than published automatically.
  • Access control — access to production systems is limited to personnel who need it, and credentials believed to be exposed are treated as compromised and rotated.
  • Testing — an adversarial test corpus and automated test suite exercise the masking and guardrail paths on an ongoing basis.

No system is perfectly secure. These are risk-reduction controls, not guarantees. We cannot promise that unauthorized access will never occur, and detection and masking controls are pattern-based and can miss novel formats. If we become aware of a breach affecting personal information, we will notify affected customers and individuals as required by applicable law, without unreasonable delay.


7. How Long We Keep Information

Data Retention
Account and profile data For the life of the account, then deleted or de-identified within 90 days of account closure
Customer content (reviews, drafts, approvals) For the life of the account; exportable for 30 days after termination, then deleted or de-identified
Application and security logs Up to 90 days
Error and exception records Up to 90 days
Billing and tax records As required by law, generally 7 years
Backups Deleted on their normal expiration cycle
Aggregated, de-identified metrics Retained indefinitely; not re-identified

We may retain information longer where required by law or where necessary to establish, exercise, or defend legal claims, and we will delete it once that need ends.


8. Your Privacy Rights

8.1 California residents (CCPA/CPRA)

If you are a California resident, you have the right to:

  • Know the categories and specific pieces of personal information we have collected about you, the sources, the business purpose, and the categories of third parties to whom we disclose it.
  • Delete personal information we collected from you, subject to exceptions.
  • Correct inaccurate personal information.
  • Opt out of sale or sharing — we do not sell or share personal information, so there is nothing to opt out of, and we provide no "Do Not Sell or Share My Personal Information" link because none is required.
  • Limit use of sensitive personal information — we do not use or disclose sensitive personal information for any purpose beyond those permitted without a right to limit.
  • Non-discrimination — we will not deny service, charge different prices, or provide a different level of service because you exercised a right.

Categories of personal information collected in the preceding 12 months, using the CCPA's statutory categories:

CCPA category Collected Examples
Identifiers Yes Name, business email, account ID, IP address, reviewer name as supplied by a platform
Customer records (Cal. Civ. Code § 1798.80) Yes Billing contact and address, phone number
Commercial information Yes Subscription plan, transaction history, service usage
Internet or network activity Yes Log data, endpoints accessed, device and browser information
Geolocation data Coarse only Approximate location inferred from IP address
Audio, electronic, or similar information Yes Review text and response drafts, as content
Professional or employment information Yes Job title and employer, where provided
Inferences Limited Sentiment classification of review content
Sensitive personal information Not intentionally Account credentials (in hashed form). Other sensitive categories may appear only if a reviewer writes them into a review; we do not solicit them and do not use them for any purpose beyond providing the Service
Biometric information No —
Education information No —

How to exercise a right. Email [email protected] with the subject line "Privacy Request." We will verify your request using information already associated with your account — typically by confirming control of the account email or matching identifying details you provide. We will respond within 45 days, extendable by another 45 days with notice. An authorized agent may submit a request on your behalf with written permission signed by you; we may require you to verify your identity directly.

Requests about review content: if your personal information reached us because you left a review for one of our customers, see Section 1.2 — direct the request to that business.

8.2 Other U.S. state privacy laws

Residents of states with comprehensive privacy laws — including Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, and others as they take effect — have comparable rights to access, correct, delete, obtain a portable copy, and opt out of targeted advertising, sale, and certain profiling. We do not engage in targeted advertising, sale, or profiling with legal effects. Use the same contact address above. Where your state provides an appeal process, you may appeal a denial by replying to our response with "Appeal"; we will respond within the period your state's law requires, and will tell you how to contact your state attorney general if you remain dissatisfied.

8.3 Everyone

Regardless of where you live, you may email [email protected] to ask what we hold about you, correct it, or ask us to delete it, and we will do our best to honor the request consistent with our legal and contractual obligations.

8.4 Marketing communications

You can opt out of product and marketing emails using the unsubscribe link in any such message or by emailing us. You cannot opt out of transactional and security notices while you hold an account — billing notices, service interruptions, security alerts, and changes to these terms.

8.5 Global Privacy Control

We honor the Global Privacy Control (GPC) browser signal where it applies. Because we do not sell or share personal information, a GPC signal does not change how we handle your data.


9. Children

The Service is a business tool and is not directed to anyone under 18. We do not knowingly collect personal information from children. If we learn that we have collected personal information from a child under 13, we will delete it. If you believe a child has provided us information, contact [email protected].


10. Changes to This Policy

We may update this Policy. When we do, we will change the "Last Updated" date above. If the changes are material, we will notify account holders by email or through the Service at least 30 days before they take effect. We encourage you to review this page periodically. Prior versions are available on request.


11. Contact Us

Repraft LLC c/o Northwest Registered Agent Service, Inc. 2501 Chatham Rd Suite N Springfield, IL 62704, USA

  • Privacy requests and questions: [email protected]
  • Security reports: [email protected]
  • General support: [email protected]
  • Legal notices: [email protected]

We will acknowledge privacy inquiries within 10 business days.

Repraft

Repraft LLC, an Illinois limited liability company.

  • [email protected]
  • Terms of Service
  • Privacy Policy

© 2026 Repraft LLC