ReplyLens
Back to Home

Privacy Policy

Effective: August 22, 2026

This policy covers the ReplyLens website, Chrome extension, and API. ReplyLens analyzes X context visible on the page only when needed for user-requested features and does not post automatically.

1. Data we process

  • • Your public X screen name and X user ID after you authorize ReplyLens to verify account ownership. X also provides your public display name, avatar URL, and verification status when available.
  • • The extension version, a hashed extension session identifier, and basic request metadata needed for access control, security, and usage limits.
  • • X content visible in the page when you request a suggestion, such as the target post, conversation context, replies, author profile information, links, and media references. This can include protected content you are permitted to view if you invoke ReplyLens on that page.
  • • The selected suggestion and final published reply only after X reports a successful CreateTweet response. We use this verified example to personalize future suggestions.
  • • Reply-generation events such as candidates shown, selection, editing, abandonment, and verified publication. A local IndexedDB outbox keeps unsent events on your device until delivery succeeds.
  • • Personal expression memories shown in your Dashboard: voice constraints, negative preferences, user-confirmed opinions or facts, evidence-backed interaction episodes, and limited public author context. Each memory has a scope, confidence, evidence count, and status.
  • • Private tags, notes, and interface preferences remain in browser storage unless a feature explicitly states that it syncs them.

2. Data we do not request

  • • We do not request or store your X password, direct messages, payment card details, or X content outside the page where you invoke the extension.
  • • X OAuth requests only the users.read permission needed to verify your identity. The short-lived X access token is used once to call X /2/users/me and is not stored by ReplyLens; ReplyLens does not store a refresh token or use the token to read posts.
  • • ReplyLens does not currently offer payments, checkout, or subscriptions.

3. Why we use data

  • • To generate context-aware reply suggestions, enforce beta access and plan limits, prevent replay or abusive requests, diagnose failures, and improve suggestions for your own account.
  • • User opinions and facts are kept separate from writing style. Only items you confirm and mark as usable in public replies can be supplied to the model as your position or personal fact. Private and ask-before-use items are not automatically disclosed.
  • • We do not sell personal information or use your reply history to build advertising profiles.

4. Service providers and transfers

  • • ReplyLens runs its website, API, and PostgreSQL database on privately managed VPS infrastructure. AI requests are routed through a self-hosted model gateway to configured model providers. The minimum context needed to generate a reply may therefore be processed by those providers.
  • • Cloudflare may process network and security metadata for the replylens.com domain. We disclose data when required by law or when necessary to protect users and the service.

5. Retention and security

  • • Generation records, usage events, security nonces, OAuth identity records, and verified reply examples are retained only as needed to operate, secure, and improve the service. Short-lived OAuth states, request nonces, and generation caches expire automatically.
  • • Data is encrypted in transit with HTTPS. Extension session secrets are stored server-side as one-way hashes. No system can guarantee absolute security.
  • • Recent-author memories expire automatically unless refreshed. Raw events remain evidence records; deleting a derived memory immediately removes it from future generation, while limited security and audit records may be retained as described below.

6. Your choices and rights

  • • The Dashboard lets you inspect, add, correct, confirm, reject, and delete personal expression memories. Deleted memories stop participating in generation immediately.
  • • You may stop data collection by disabling or uninstalling the extension. You may request access, correction, export, or deletion of personal data associated with your X screen name by emailing [email protected].
  • • We may retain limited records when legally required or necessary to investigate abuse, and may keep aggregate data that no longer identifies you.

7. Children and changes

  • • ReplyLens is not directed to children under 13. If local law requires a higher minimum age, that higher age applies.
  • • We will update the date and content of this policy when data practices materially change.

8. Contact

Privacy questions and requests: [email protected].