InReply InReply
How it worksFeaturesUse casesSecurityPricing
Sign inStart free trial
How it worksFeaturesUse casesSecurityPricingSign inStart free trial
Legal

Privacy Policy

Last updated: 17 July 2026

This Privacy Policy explains how Strategic Minds Group Limited, trading as InReply (“we”, “us”, “our”), collects, uses, and protects your information when you use the InReply web application (“the App”) and the website at https://inreply.ai (“the Website”), together referred to as “the Service”.

We are registered in England and Wales. Our registered office is at 57 Nine Elms Lane, London, SW11 7DF. For the purposes of the UK General Data Protection Regulation (“UK GDPR”) and the Data Protection Act 2018, we are the data controller for the personal data described in this policy, except where we act as a processor on behalf of a business customer (see section 2).

1. About InReply

InReply is a cloud-based software-as-a-service platform that connects to your Gmail or Outlook inbox and uses artificial intelligence to read incoming customer support emails, find the answer in your own knowledge base (FAQs, PDFs, documents, and saved replies), and draft or send accurate replies in your business’s voice. The Service is a cloud application delivered entirely over the web; all processing happens on our servers and those of our subprocessors.

2. Data Controller and Processor Roles

We act as the data controller for personal data relating to account holders, workspace members, and visitors to our Website, including name, email address, authentication identifiers, billing details, and website usage data.

Where a business customer connects their Gmail or Outlook mailbox to InReply so that we process the support emails their own customers send them, we act as a data processor on that customer’s behalf, and the business customer is the controller of their end users’ personal data. A Data Processing Addendum (DPA) is available on request by emailing hello@inreply.ai.

3. Information We Collect

3.1 Account and workspace data

When you create an InReply account or join a workspace, we collect your name, email address, password (stored as a secure hash by our authentication provider), authentication identifiers from any Google or Microsoft sign-in you use, and your role within your workspace. We also store workspace-level configuration such as workspace name, reply playbooks, labels, tone-of-voice settings, and confidence thresholds you choose.

3.2 Knowledge base content

To ground the AI in your business, you can upload documents such as FAQs, PDFs, and text files, and add saved replies and notes. We store this content, generate vector embeddings from it so the AI can retrieve relevant passages, and reference it when drafting replies. You can delete uploaded documents at any time from within the App.

3.3 Connected mailbox data (Gmail and Outlook)

When you connect a Gmail mailbox, you authorise InReply through Google’s OAuth flow using the gmail.modify scope. When you connect an Outlook or Microsoft 365 mailbox, you authorise InReply through Microsoft’s OAuth flow (the Microsoft identity platform) using the Microsoft Graph scopes Mail.ReadWrite, Mail.Send, MailboxSettings.ReadWrite, User.Read, and offline_access. In each case we store the resulting OAuth access and refresh tokens in encrypted form, and we process the content of the emails in the connected mailbox in order to classify them, draft replies, apply labels or categories, and send replies you approve. This includes sender and recipient names and email addresses, subjects, message bodies, attachments, labels or categories, and thread metadata. We only request the scopes needed to provide the features you enable, and you can disconnect the mailbox at any time, which revokes our access.

3.4 Billing data

Paid subscriptions are processed by Stripe. When you subscribe, Stripe collects and processes your billing details (including name, billing address, VAT number where applicable, and payment card details) as a joint controller for payment processing and tax compliance. We receive a limited set of information from Stripe, namely your Stripe customer ID, email address, subscription state, and invoice metadata, which we store to operate your subscription and provide support. We never see or store full payment card details.

3.5 Website and product usage data

When you use the Website and the App we set only the strictly necessary cookies required to sign you in, keep your session active, and process secure payments. We do not currently use analytics or advertising cookies. See our Cookie Policy for full details of the cookies we set and the choices available to you.

3.6 Diagnostic and operational data

To keep the Service secure and reliable, our hosting provider (Vercel) generates runtime and request logs. These can include your IP address, browser and device metadata, request paths, and timestamps. We use this information solely to operate, secure, and debug the Service, relying on our legitimate interest in operating a secure and reliable Service (Article 6(1)(f)).

4. Legal Bases for Processing

Under the UK GDPR we rely on the following legal bases:

  • Contract, to create and operate your account, deliver the Service you have subscribed to, process payments, and provide customer support (Article 6(1)(b)).
  • Legitimate interests, to secure, operate, and improve the Service, and to send occasional product-update or marketing emails to existing customers in accordance with the soft opt-in under the Privacy and Electronic Communications Regulations 2003, where our interests do not override your rights and freedoms (Article 6(1)(f)). You can opt out of marketing emails at any time.
  • Consent, where we ask for it, for example for pre-customer marketing communications. You can withdraw consent at any time (Article 6(1)(a)).
  • Legal obligation, to retain transaction and tax records as required by accounting and tax legislation (Article 6(1)(c)).

5. How We Use Your Information

  • To provide, maintain, and secure the Service.
  • To read and classify incoming emails in your connected mailbox, and to draft and (where you allow it) send replies grounded in your knowledge base using the AI processing described in section 6.
  • To process subscriptions, invoices, and refunds via Stripe.
  • To respond to support enquiries and communicate important service messages.
  • To send occasional product updates and marketing emails to existing customers, and to prospects who have opted in. Every marketing email includes an unsubscribe link.
  • To comply with legal, regulatory, and tax obligations.

6. AI Processing

To classify emails, generate embeddings of your knowledge base, and draft replies, the relevant email content and knowledge base context are sent to OpenAI’s models (currently gpt-4o, gpt-4o-mini, and the text-embedding-3-small embedding model) via the Vercel AI Gateway. OpenAI processes this content as our subprocessor and, under its API terms, does not use API inputs to train its models. If you do not wish for your emails to be processed by AI, do not connect a mailbox to InReply; a partial opt-out is not currently available.

7. Subprocessors

We share personal data only with the subprocessors listed below, and only to the extent necessary to provide the Service. This list may change; we will update this page when it does.

  • Vercel Inc. (United States). Application hosting, edge network, runtime logs, and the AI Gateway that routes our AI requests.
  • Supabase Inc. PostgreSQL database, authentication, and file storage for your knowledge base documents.
  • OpenAI, L.L.C. (United States). Large language model inference and text embeddings for email classification and reply generation.
  • Stripe Payments Europe, Ltd. / Stripe, Inc. Handles subscription billing and invoicing.
  • Google LLC (United States). Gmail API access for the mailbox you connect, and Google sign-in. Data is only shared with Gmail when you explicitly connect a mailbox to your workspace.
  • Microsoft Corporation (United States). Microsoft Graph API access for the Outlook or Microsoft 365 mailbox you connect, and Microsoft sign-in. Data is only shared with Microsoft when you explicitly connect a mailbox to your workspace.

We may also disclose your information if required to do so by law, regulation, or legal process, or if we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others.

8. International Data Transfers

Several of our subprocessors are based outside the United Kingdom, primarily in the United States and the European Economic Area. Where personal data is transferred outside the UK, we rely on appropriate safeguards such as the UK International Data Transfer Addendum or the European Commission’s Standard Contractual Clauses, or we rely on an adequacy decision where one is in place.

9. Data Retention

  • Account and workspace data: retained for as long as your workspace is active and deleted within 30 days of workspace closure, other than data we are required to retain for legal or tax reasons.
  • Connected mailbox access: mailbox OAuth tokens (Google and Microsoft) are deleted and access is revoked immediately when you disconnect the mailbox or close your workspace.
  • Knowledge base content and email-derived data: controlled by the business customer who owns the workspace. It is deleted on request from the workspace owner or within 30 days of workspace closure.
  • Billing and transaction records: retained for up to 7 years to comply with UK tax and accounting requirements.
  • Support correspondence: retained for up to 2 years after the last communication.
  • Operational and diagnostic logs: retained in accordance with our hosting provider’s default settings.

10. Your Rights

Under the UK GDPR, you have the following rights in relation to the personal data we hold about you:

  • Right of access, request a copy of the personal data we hold about you.
  • Right to rectification, ask us to correct inaccurate or incomplete data.
  • Right to erasure, ask us to delete your personal data, subject to our legal obligations.
  • Right to restrict processing, ask us to limit how we use your data.
  • Right to data portability, request your data in a structured, commonly used, machine-readable format.
  • Right to object, object to our processing where we rely on legitimate interests.
  • Right to withdraw consent, withdraw consent at any time where we process data based on your consent.

To exercise any of these rights, please contact us at hello@inreply.ai. We will respond within one month of receiving your request. If we need more time (up to an additional two months for complex requests), we will let you know.

If your personal data is processed by InReply as a processor on behalf of a business customer, please direct your request to that business customer in the first instance; we will support them in responding to your request.

11. Complaints

If you are unhappy with how we have handled your personal data, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO):

  • Website: https://ico.org.uk
  • Telephone: 0303 123 1113

12. Children’s Privacy

InReply is a business tool and is not directed at individuals under the age of 18. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided us with personal data, please contact us at hello@inreply.ai and we will take steps to delete that information.

13. Security

We take appropriate technical and organisational measures to protect the personal data we process. These include encryption in transit (TLS) and at rest, encryption of stored mailbox OAuth tokens, principle-of-least-privilege access controls for staff, authentication and session management delegated to our authentication provider, and regular review of our subprocessors. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. The updated version will be indicated by the “Last updated” date at the top of this page. We encourage you to review this Privacy Policy periodically. Your continued use of the Service after any changes constitutes your acceptance of the updated policy.

15. Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us:

  • Email: hello@inreply.ai
  • Post: Strategic Minds Group Limited, 57 Nine Elms Lane, London, SW11 7DF
InReply InReply

The AI email agent for small businesses. Answers grounded in your own knowledge, sent from the inbox you already use.

Product

FeaturesUse casesPricingAI email agentEmail answering serviceAI email assistant for OutlookAI email assistant for GmailShared inbox software

Use cases

For property agentsFor gymsFor vacation rental hostsFor agenciesFor real estateFor sales teams

Compare

InReply vs FyxerInReply vs JaceInReply vs SerifInReply vs EllieInReply vs ShortwaveInReply vs GmeliusInReply vs HiverFyxer alternativesJace alternativesSerif alternativesShortwave alternativesHiver alternativesSuperhuman alternatives

Resources

BlogBest AI email assistantsEmail management softwareFyxer AI reviewJace AI reviewAuto-reply email guideCustomer service email templatesGmail auto-reply setupOutlook auto-reply setupContact

Legal

PrivacyTermsCookies
© 2026 InReply. All rights reserved.Made in the UK