Legal
Privacy Policy
This policy explains what personal data ReplyX handles, how and why, who we share it with, and the choices and rights you have — for both our customers and their end-customers.
Last updated: 27 July 2026
1.Introduction
This Privacy Policy explains how Softifybd Limited ("ReplyX", "we", "us") handles personal data when you use our platform, websites and APIs (the "Service"). It covers both the data of our direct customers (the businesses that sign up) and the data of their end-customers whose messages flow through the Service.
2.Our roles: controller and processor
Our responsibilities depend on whose data it is:
- Account data — we are the controller. For the personal data of the business users who register and manage a workspace (name, email, billing details, usage), we decide how and why it is processed.
- Conversation data — we are the processor. For the personal data contained in your customers' messages, contacts and related content, we act on your instructions as a service provider. The business using ReplyX is the controller of that data and is responsible for having a lawful basis to collect and send it.
3.Information we collect
- Account & workspace information — name, email, password (stored only as a secure hash), workspace and team details.
- Billing information — plan, invoices and payment records. Card and mobile-wallet details are handled by our payment partners; we do not store full payment credentials.
- Customer conversation data — messages, contact identifiers (such as name, phone, email or channel ID), and any attachments or details your customers share, processed on your behalf.
- Knowledge base & product content — the material you add so the AI can answer questions.
- Usage & technical data — log data, device and browser information, IP address and diagnostic events used to operate, secure and improve the Service.
- Cookies — essential cookies to keep you signed in and to keep the Service secure. See "Cookies" below.
4.How we use information
- to provide, maintain and secure the Service;
- to generate AI-assisted replies from your knowledge base and settings;
- to process payments, prevent fraud and abuse, and enforce usage limits;
- to communicate with you about your account, security and service updates;
- to troubleshoot, analyse and improve the Service (using aggregated or minimised data where practical);
- to comply with legal obligations.
5.AI processing and sub-processors
To generate replies and power search, relevant message text and knowledge-base content is sent to AI and infrastructure providers acting as our sub-processors — which may include Anthropic, OpenAI, Google and Voyage AI, alongside hosting and email providers. They process the data only to return a result to us and under their own security and privacy commitments.
We do not sell personal data, and we do not use your Customer Data to train our own models. A current list of sub-processors is available on request through our contact page.
7.International transfers
Some of our providers process data outside Bangladesh. Where data is transferred internationally, we take reasonable steps so that it remains protected consistent with this Policy and applicable law.
8.Data retention
We keep personal data for as long as your account is active and as needed to provide the Service, then for a reasonable period to meet legal, accounting or dispute-resolution needs. You can delete much of your data from within the product, and you can request deletion of your workspace by contacting us; some records may be retained where the law requires.
9.The ReplyX mobile app
The ReplyX app for Android and iOS is an inbox for the people who answer customers. It shows the same conversations as the web portal and adds nothing to what we collect about your customers. What follows is specific to the app, so it can be read on its own.
- Camera, photo library and microphone — used only at the moment an agent chooses to attach a photo or record a voice message for a customer. The app never opens them in the background, and nothing is captured unless the agent taps the button.
- Notification token — a random identifier issued by the operating system so the app can be woken when a customer needs a person. It identifies an installation, not a person, and is deleted when the agent signs out or the app is removed.
- What a notification says — the customer's name and up to 140 characters of their message, so an agent can tell an urgent message from a routine one without opening the app. That preview passes through the notification services operated by Google and Apple, and through Expo's push relay, exactly as any messaging app's notifications do. Conversations the AI is handling on its own send no notification at all.
- What the app stores on the phone — the sign-in token and the workspace being viewed, held in the device keystore (Android Keystore / iOS Keychain), never in ordinary app storage. Signing out deletes them and revokes the session on our side.
- Device details — the model name and app version, so an owner can recognise which phone is signed in and cut off one that is lost.
The app contains no advertising, no advertising identifier, no third-party analytics or tracking SDK, and does not request location. Nothing it collects is sold or shared for advertising.
10.Data from Meta Platforms (Facebook & Instagram)
When a business connects a Facebook Page or Instagram account to ReplyX, we receive limited data from Meta Platforms strictly to provide the messaging service:
- Page / account identifiers and access tokens — used to receive and send messages on the connected Page or account. Tokens are stored encrypted (AES-256-GCM).
- Message content and sender identifiers (PSID/IGSID) — used to display conversations in the business's inbox and to deliver replies.
- Sender name and profile picture — shown next to the conversation so support agents know who they are talking to.
We use this data only to operate the connected channel. We do not use it for advertising, do not sell it, and do not combine it across workspaces. It is deleted when the business disconnects the channel or deletes the conversation, as described under "Data deletion" below.
11.Data deletion
You can delete data from ReplyX at any time:
- Conversations & contacts — delete them from the Inbox and Contacts pages inside your workspace.
- A connected channel (including a Facebook Page or Instagram account) — open Channels → the channel → Settings → Delete/Disable. Deleting a channel removes its stored access token and, when history is deleted, its conversations, messages and contacts.
- Your whole account and workspace — email support@replyx.io from your account email with the subject "Delete my account". We complete deletion within 30 days, except for records we must keep by law (e.g. invoices).
- End-customers — if your data was handled because you messaged a business that uses ReplyX (for example via Facebook or Instagram), ask that business to delete it, or contact us at the address above and we will assist. This also serves as our data deletion instructions for data received from Meta Platforms.
12.How we protect data
Security is built into how the Service is designed. Measures include:
- Tenant isolation with PostgreSQL row-level security, so one workspace cannot read another's data — enforced at the database level.
- Encryption at rest for provider keys and channel access tokens using AES-256-GCM.
- Least-privilege access, signature-verified webhooks, and an append-only audit log of sensitive operator actions.
No system is perfectly secure, but we work to protect your data and to respond quickly if an issue arises. Learn more on our security page.
13.Your rights and choices
Depending on your location, you may have rights to access, correct, export or delete your personal data, or to object to or restrict certain processing. For account data, contact us to exercise these rights.
If you are an end-customer of a business that uses ReplyX, that business controls your data — please direct your request to them, and we will support them in responding.
15.Children
The Service is intended for businesses and is not directed to children. We do not knowingly collect personal data directly from children under 18.
16.Changes to this policy
We may update this Policy from time to time. We will post the updated version with a new effective date and, for material changes, take reasonable steps to notify you.
17.Contact us
For privacy questions or to exercise your rights, contact us at support@replyx.io or through our contact page.
The data controller is Softifybd Limited, Tower of Aakash, Level- 18, 54 Gulshan Avenue, Dhaka-1212, Bangladesh.