Effective date: 18 September 2026.
This policy explains what data the ReplAI service (replai.kg and its
subdomains) processes, why, and on what terms. It is written in plain
language: if anything seems vague, write to support@replai.kg and we will
clarify and fix the text.
This is a translation of the Russian version of the policy (Политика конфиденциальности). The two versions have the same content; if they ever differ, the Russian version prevails.
Data controller: ОсОО «Сторес Компани» (a limited liability company), Kyrgyz Republic. Contact for any data question: support@replai.kg.
Two roles, and why they matter
ReplAI is a business service. It handles data of two different groups of people, and our role differs for each.
Dashboard owner — an entrepreneur or store employee who created an account. For their data (email, name, settings, payments) we are the controller: we decide why and how it is processed and are accountable to them for it.
Store shopper — a person who wrote to the store's website chat, Telegram, WhatsApp or Instagram. We process their messages, phone number and delivery address on behalf of the store: the store is the controller of that data, and we are a processor acting on its instructions. So a shopper sends requests to delete messages or contact details to the store, and the store forwards them to us if needed. The store is responsible for obtaining its shoppers' consent and publishing the required notices.
What data we process
When you register and use the dashboard
- email address, first and last name, phone number (if provided);
- organization name;
- password — only as an irreversible hash (bcrypt); the original password is not stored and cannot be recovered;
- role in the organization and access rights;
- service records: registration date, onboarding completion, uploaded profile photo.
When you sign in with a Google account
If you use the “Sign in with Google” button, we receive from Google:
- your email address and whether it is verified;
- the first and last name on the account;
- the permanent Google account identifier (
sub).
That is all. We do not request access to Gmail, Google Drive, contacts, calendar or any other Google service, and we never see or store your Google password.
The data is used for exactly two things: to recognise you at sign-in and to show your name and email address in the dashboard. We do not share it with third parties, do not use it for advertising, and do not allow humans to read it, except when necessary to investigate a security incident, when required by law, or when you explicitly ask us to in a support request.
ReplAI's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
You can revoke access at any time at Google Account → Third-party apps & services. After that, signing in with Google stops working; your ReplAI account is kept, and you can sign in with a password (set one via “Forgot password?”).
Data the store uploads
Product catalog, categories, prices and stock, the agent's knowledge base, system prompt and channel settings, orders. The dashboard owner enters all of this or connects it through a feed from their website (ReplAI Feed).
Store shoppers' data
- conversations with the agent and the store operator, including attachments;
- contact details the shopper provides when placing an order: name, phone, delivery address;
- the shopper's identifier in the messaging channel (for example, a Telegram chat ID or WhatsApp number) — needed so the reply reaches the person who wrote;
- the address of the web page where the chat is open and the time spent on it — so the operator sees the context of the request. One-time tokens and parameters that look like contact details are stripped from the address before it is saved.
Technical data
- service access logs and error reports, including IP address — needed to find failures and block password guessing;
- rate-limit counters (kept for minutes);
- registration and password-reset confirmation codes — valid for 15 minutes and deleted automatically.
We do not use advertising or tracking cookies, build advertising profiles, or sell data.
Why we process it
| Data | Purpose | Legal basis |
|---|---|---|
| Email, name, password | Dashboard access, account recovery | Performance of our contract with you |
| Google account data | Password-free sign-in | Performance of the contract, your action |
| Catalog, prompt, knowledge base | Running the agent | Performance of the contract |
| Shoppers' messages and contacts | Replying to shoppers, placing orders | Instructions of the store |
| Logs, IP, rate-limit counters | Security and reliability | Our legitimate interest |
| Payment events | Accounting for payments and plan | Performance of the contract, legal obligations |
Who we share data with
The service runs on third-party infrastructure. Each provider receives only the minimum needed for its task.
| Provider | What it receives | Why |
|---|---|---|
| OpenAI, Anthropic, Google, DeepSeek | Conversation text and agent settings | Generating a reply with the selected model |
| Meta Platforms (WhatsApp, Instagram) | Messages and chat identifiers | Delivering messages in these channels |
| Telegram | Messages and chat identifiers | Delivering messages in Telegram |
| Resend | Recipient address and email text | Emails with confirmation codes |
| Cloudflare | Uploaded files, service traffic | File storage and content delivery |
| Sentry | Technical error details | Diagnosing failures (sending personal data is disabled) |
| Stripe, Finik | Payment amount and ID | Accepting payments |
Card details never pass through us: they are entered on the payment provider's side, and we only receive confirmation of a successful payment.
The providers are located outside the Kyrgyz Republic, so data is also processed on servers in other countries. By using the service you agree to this cross-border transfer — the AI agent cannot technically work without it.
Beyond the above, we disclose data only upon a lawful, justified request from government authorities.
Conversations and model training
For the agent to reply to a shopper, the conversation text is sent to the provider of the selected model. We use these providers' API modes, whose terms do not provide for training models on the data sent. The dashboard owner chooses the provider in the agent settings; each provider's current terms are available on its website.
How long we keep data
- Account and organization data — while the account exists.
- Conversations and orders — until the store deletes them or closes the account.
- Technical logs — up to 90 days.
- Confirmation codes — 15 minutes.
- Information about a visitor's presence on a page — minutes; the record clears itself.
- Data we must keep by law (for example, payment records) — for the period required by law.
Your rights
You can:
- get a copy of your data;
- correct it — most fields can be edited directly in the dashboard;
- delete your account and related data (how to request deletion);
- revoke the Google account's access (see above);
- complain about how we handle your data.
For any of these, just email support@replai.kg from the address the account is registered to. We reply within 30 days. Account deletion is irreversible: agents, catalog, conversations and orders are deleted with it.
How we protect data
- All traffic goes over HTTPS.
- Passwords are stored hashed (bcrypt) and are not available in plain text to anyone, including us.
- The session refresh token is kept in an
HttpOnlycookie, inaccessible to scripts on the page. - Store employees' access to data is limited by roles; the owner decides who sees what.
- Server access is restricted and protected with keys.
No service can promise absolute protection. If an incident does occur and affects your data, we will notify you at your contact address.
Cookies
We use only strictly necessary cookies:
refresh_token— extends the dashboard session,HttpOnly;- a session cookie — temporary state of Google sign-in (protection against request forgery).
The access token is kept in the browser's local storage and deleted on sign out. Disabling these cookies makes signing in to the dashboard impossible.
Age
The service is intended for entrepreneurs and is not designed for people under 18. We do not knowingly collect children's data.
Changes
We may update this policy. The effective date is shown at the top of the page; we notify dashboard owners of material changes at their contact address at least 14 days in advance.
Contact
For any data question: support@replai.kg.