Replai Security & Privacy - How We Protect Your Data

Replai never auto-sends, never trains AI on your text, and connects to your inbox only when you choose. Privacy came first, and the product was designed around it.

No account needed for the free tool · Connect your inbox only when you choose

Never sends email on your behalf
Never trains AI on your text
Never stores session text
Inbox access only with your permission
Payments handled by Stripe - We never see your card
Google
Microsoft
Salesforce
Shopify
Stripe
Slack
HubSpot
Atlassian
Zoom
Dropbox

Replai AI email security - Built to protect your privacy

You control what we access

Replai connects to your inbox only with your explicit permission. You decide which features to turn on and what access to grant, and you can connect or disconnect any time from your settings. We request only the permissions each feature actually needs - Nothing more. Using a non-Gmail, non-Outlook account? See how custom email setup works.

Drafts only - You always press send

Replai writes a draft with our email reply generator. You copy it, edit it, and send it yourself. The tool cannot send email on your behalf, and that will not change. You stay in full control of what goes out.

Your text never trains AI models

Text you submit to generate a reply produces that reply and nothing else. It is not stored beyond the session, not shared with third parties, and not used to train or fine-tune any AI model - Ours or anyone else's.

Privacy is not a feature.
It is a constraint we design around.

Most email AI tools ask for your inbox first and explain why later. We built Replai the other way around - Privacy constraints came first, and the product works within them.

Privacy by design

We assess every feature for its data footprint before it ships. If one would mean storing email content or accessing your inbox, we look for another way to reach the same result without the privacy cost.

Minimal data collection

We collect only what the service needs to run. Account data is limited to email and billing. Writing examples you save for your reply identity are stored securely under your account and deletable any time from your settings.

Transparency over trust

We would rather show exactly how the product works than ask you to take our word for it. Question about how specific data is handled? Contact us and we will answer directly. For a vendor-neutral checklist of what to verify before connecting any AI tool to your inbox, read is AI email safe?

How we protect the data we do hold

Replai minimizes data collection by design. For what we do handle - Account information, saved writing examples, payment details - We apply standard security practices across the board.

Encrypted in transit and at rest

Every connection uses HTTPS with TLS 1.2+. Data at rest - Including account records and saved writing examples - Is encrypted at the storage layer.

Payments handled by Stripe

Replai never stores card numbers, CVCs, or raw payment data. All billing runs through Stripe, a PCI DSS Level 1 certified payment provider.

Access controls and least privilege

Internal access to production systems is restricted on a need-to-know basis. No single person holds broad access to user data as a matter of routine.

Delete your data, any time

Remove saved writing examples from your settings one by one or all at once. Closing your account deletes all associated data. Contact us to confirm what is held and request removal.

Transparency

Have a specific question about how your data is handled?

Our privacy policy covers data collection, retention, and your rights in full. If something is unclear, or you want a direct answer about a specific scenario, our team replies to security and privacy questions within one business day.

Security and privacy - Common questions

Only if you choose to connect it. Some features - Like the free email reply generator - Work entirely from text you type in, with no inbox connection. When you do connect your inbox for other features, Replai requests only the specific permissions that feature needs. You can revoke access at any time from your account settings.
Text you submit to generate a reply is used to produce that reply and is not stored beyond the session. If you are on the Pro plan and save writing examples to your reply identity, those examples are stored securely under your account and are visible only to you. You can delete them at any time from your account settings.
No. Text you submit to generate a reply is never used to train or fine-tune any AI model - Ours or a third party's. Writing examples you save to your reply identity inform only your own drafts. They are not shared or used for training.
No. Replai generates draft text that you copy into your email client. The product has no way to send email. You write, review, edit, and send every message yourself.
Yes. Replai processes personal data in line with GDPR requirements. We collect only the data needed to run the service, explain clearly how it is used, and honor deletion requests. Have a specific compliance question? Contact us and we will respond directly.
All payments run through Stripe, a PCI DSS Level 1 certified provider. Replai never sees, stores, or handles your card number or CVV. Stripe runs the billing infrastructure end to end. You can review invoices and manage your subscription from your account dashboard.
Cancel your Pro subscription and your account stays accessible until the end of the billing period. Close it entirely and your saved writing examples and account data are deleted. You can also request deletion of specific data any time by contacting us - No need to close your account to do it.
Internal access to production systems and user data is restricted on a least-privilege basis. Staff reach email-level data only when a specific support issue requires it, and with the account holder's knowledge. No one has routine broad access to user writing examples or submitted text.

Try Replai - No inbox access, no sign-up.

The reply generator is free to use. No account, no email connection, no strings.