Privacy Policy
This Privacy Policy explains how Reply Pocket handles information when you use our free, individual-use web service to save and reuse reply snippets.
Last updated: September 21, 2026
Controller and contact
The controller is Reply Pocket. For privacy questions or rights requests, contact hello@replypocket.dev.
Information we collect
- Your account email, when you sign in with Google OAuth or through a magic link sent to your email;
- the snippets, tags, and global variables you store;
- your feedback submissions;
- minimal operational metadata needed to run and secure the service.
Temporary content
Content you temporarily use to complete or adapt a reply before copying it is not saved as history, not persisted as an adapted reply, and discarded after that use.
Legal bases
We process data necessary to provide the service on the basis of contract and rely on legitimate interests to protect the service, prevent abuse and maintain its security. If optional processing requires consent, we will ask for it separately.
How we use information
- create and maintain your account;
- authenticate you;
- store and retrieve your snippets;
- resolve variables;
- deliver the features you request;
- process feedback and support;
- operate, maintain, secure and troubleshoot the service;
- prevent abuse.
Service providers
- Supabase, for database and authentication;
- Vercel, for hosting and running the service;
- Resend, for transactional email;
- Google, when you choose to sign in with OAuth.
Some providers may process information outside the EEA, subject to the applicable safeguards and transfer mechanisms. We do not sell your personal data.
AI assistants (MCP)
When you choose to connect and authorize a compatible AI assistant or MCP client, it can search and read your snippets. The integration is read-only and cannot create, edit or delete snippets. You can revoke access from Settings.
Content retrieved by external clients may be processed by those clients or providers under their own terms and privacy policies.
Reply Pocket does not send your library to an AI provider simply because you store it with us. Content is made available to an external client only when you choose to connect and authorize it.
Retention and deletion
Data associated with your account is deleted from Reply Pocket's active systems when you delete your account from Settings → Privacy & Data. Some residual copies may remain temporarily in protected backups or provider logs until they expire under the applicable retention lifecycle.
Cookies
We use only cookies or similar technologies that are strictly necessary to authenticate you, maintain your session, remember essential preferences and operate the service. We do not use analytics, advertising or tracking cookies.
Your rights
- access
- rectification
- erasure
- portability
- objection
- restriction
You may exercise these rights where applicable. Where processing is based on consent, you may also withdraw that consent at any time.
You can use the actions in Settings → Privacy & Data to export or delete your data, or contact hello@replypocket.dev for help.
If you are in the EEA, you also have the right to lodge a complaint with your local data protection authority. In Spain, this is the Agencia Española de Protección de Datos (AEPD).
Security
We use TLS to protect data in transit, access controls and row-level security (RLS) to isolate each user's data.
Children
Reply Pocket is not intended for users under 16, and we do not knowingly collect personal information from children.
Changes to this policy
We may update this Policy when the service or our processing changes. We will publish the new version here and update the date above. If a change materially affects your rights or how we process your data, we will provide reasonable notice through the service or by email when appropriate.
Contact
For privacy questions or rights requests, email hello@replypocket.dev.