Privacy Policy
Effective date: 2026-08-04
This Privacy Policy explains how HotReply ("we", "our", "us") collects, uses, stores, and protects your personal data when you use the HotReply mobile application (the "App"). HotReply is an AI-powered dating copilot that helps you draft messages on dating apps. This policy is written in compliance with the EU General Data Protection Regulation (GDPR) and the EU AI Act (Regulation 2024/1689).
1. Information We Collect
Account Information
- Email address (for account creation and authentication)
- Hashed password (we never store passwords in plaintext)
Profile Information
- User Identity: first name, age, occupation, bio, interests, personality traits, gender (optional — female / male / unspecified)
- Voice Profile: your writing-style preferences (tone, message length, emoji usage, writing samples)
Usage Information
- Conversation text: messages you paste or type to generate replies
- Generated replies: AI-generated reply variants (safe / bold / funny)
- Match profile data (Premium): profile information extracted by AI from screenshots you upload (name, age, bio, photo descriptions, interests, location, vibe, gender)
- Screenshots (Premium, transient): images you upload for profile extraction — see Section 7 for retention
- Subscription data: subscription status, billing period, RevenueCat ID (no payment-card data — that is processed exclusively by Google Play)
- Technical data: IP address, device identifier, timestamps, app version (for security and error analysis)
2. How We Use Your Information
- To provide and operate the App and its AI-powered messaging features
- To generate personalized reply suggestions based on your Voice Profile and conversation context
- To extract structured profile data from screenshots you voluntarily upload (Premium feature)
- To authenticate your account and manage your subscription
- To enforce free-tier usage limits (3 generations / day) and prevent abuse
- To respond to your support requests and inquiries
- To comply with legal obligations and respond to lawful requests
3. Data Storage and Security
We implement appropriate technical and organizational measures under Art. 32 GDPR to protect your personal data against unauthorized access, alteration, disclosure, or destruction:
- Transport encryption (HTTPS / TLS) for all communication between the App and our servers
- Encryption at rest in the database
- EU hosting (Supabase, Frankfurt, Germany)
- Database-level access control (Row-Level Security, IDOR protection, atomic counters)
- Prompt-injection protection on AI interactions (sandbox delimiters for untrusted inputs)
- Regular security audits and dependency updates
4. Third-Party Services
We share data with carefully selected providers. Except where stated otherwise below, each acts as a processor under a data-processing agreement (Art. 28 GDPR):
Supabase (Auth, Database)
- Provider: Supabase Inc. (USA, with EU hosting infrastructure)
- Purpose: authentication and PostgreSQL database
- Data location: Frankfurt, Germany (EU region)
- Privacy policy: supabase.com/privacy
Railway (Backend Hosting)
- Provider: Railway Corp. (USA)
- Purpose: hosting the backend server that processes the App's requests; uploaded screenshots are processed here in memory only and are never stored
- Data location: European Union (Amsterdam region)
- Privacy policy: railway.com/legal/privacy
OpenAI (AI Processing)
- Provider: OpenAI, L.L.C. (USA)
- Purpose: processing conversation text (GPT-4o) for reply generation; processing screenshots (GPT-4o Vision) for profile extraction
- Important: OpenAI contractually confirms that API inputs are not used to train models (OpenAI Business Data Processing Addendum)
- Data location: USA
- Privacy policy: openai.com/policies/privacy-policy
RevenueCat (Subscription Management)
- Provider: RevenueCat, Inc. (USA)
- Purpose: subscription status management, purchase validation, billing cycles
- Data location: USA
- Privacy policy: revenuecat.com/privacy
PostHog (Product Analytics)
- Provider: PostHog, Inc. (EU-hosted instance)
- Purpose: product analytics — pseudonymous usage events (e.g. app opened, screen viewed), an anonymous device identifier and a user identifier. We do not send your conversation content to PostHog.
- Data location: European Union (eu.i.posthog.com)
- Privacy policy: posthog.com/privacy
Brevo (Transactional Email)
- Provider: Brevo (Sendinblue SAS), France (EU)
- Purpose: sending transactional authentication emails (registration confirmation, password reset); only the recipient's email address is processed
- Data location: European Union (France / Germany) — no transfer outside the EEA
- Privacy policy: brevo.com/legal/privacypolicy
Google Play (App Distribution and Payments)
- Provider: Google Ireland Limited (EU) / Google LLC (USA)
- Purpose: App distribution, in-app-purchase processing, payment handling
- Privacy policy: policies.google.com/privacy
- Relationship: Google acts as merchant of record and as an independent controller for Play payments; this is governed by the Google Play Developer Distribution Agreement, not by an Art. 28 processing agreement.
Meta Platforms Ireland (Advertising Performance Measurement)
- Joint controller: Meta Platforms Ireland Ltd (Ireland, EU) — a joint controller under Art. 26 GDPR, not a processor. Joint controllership covers only the stage where this data is collected in the App and sent to Meta, where we jointly determine the purpose and means; any further processing on Meta's side happens under Meta's sole responsibility as an independent controller, per the Meta terms we accepted when integrating the SDK.
- Scope: the device advertising identifier (Google Advertising ID, GAID) and these events: app install, app launch, first generated reply, subscription purchase (including the purchase amount and currency). With every event, the Meta SDK also sends standard technical transmission data — IP address, basic device attributes (model, OS version, language, time zone), the App identifier and version, and a timestamp.
- What we do NOT send to Meta: the content of your conversations, generated suggestions, screenshots, your name, your email address, your profile data, or any information about your match. The SDK has no access to any of this.
- Our purpose vs. Meta's purposes: our only purpose is measuring the effectiveness of HotReply's own ad campaigns on Meta's services (Facebook, Instagram); we never use this data for anything else and never combine it with your conversation content. After receiving the data, Meta processes it as an independent controller for its own purposes too — including personalising features and content (ads and recommendations), delivering ads, security, research and development, and improving its products (see the Meta Business Tools Terms and Meta's Privacy Policy). We have no influence over this and cannot restrict it — if you do not want it to happen, simply do not switch this consent on.
- Linkage with your Meta account: if you use Facebook or Instagram, Meta may link the transmitted events to your account there. We never send Meta your name or email address, but the linkage can still occur on Meta's side via the device identifier.
- Legal basis: consent (Art. 6(1)(a) GDPR) and Art. 5(3) of the ePrivacy Directive (2002/58/EC), as implemented in Poland — our country of establishment — through Art. 399 of the Polish Electronic Communications Law. The ePrivacy Directive is implemented separately in each EU member state; the requirement for prior, freely given consent is the same everywhere, and we apply it to all users alike.
- Voluntariness and revocability: collection by the Meta SDK is off by default. It switches on only with your active consent (Settings → Privacy Policy) and you can withdraw it there at any time. Withdrawal stops new data immediately but — per Art. 7(3) GDPR — does not affect the lawfulness of processing before withdrawal and does not delete data already sent to Meta; request that deletion directly from Meta (see "Exercising your rights" below).
- How to opt out: (1) in the App — turn off the toggle under Settings → Privacy Policy, stopping new data immediately; (2) on your device — delete the advertising identifier or turn off ad personalisation in your Android settings, which applies across all apps; (3) with Meta — in the ad settings of your Meta account.
- Transfer to the US: data may be transferred onward to Meta Platforms, Inc. (United States) under the EU-U.S. Data Privacy Framework (see Section 10).
- Retention: we do not retain this data on our side — it never reaches our database. On Meta's side, event data is retained for a maximum of 2 years under Meta's own terms; we have neither access to it nor any influence over its deletion.
- Essence of the arrangement (Art. 26(2) GDPR): the Meta Business Tools Terms and their joint-controller addendum set out the roles: we are responsible for obtaining your consent before the SDK starts and for the Art. 13–14 GDPR information duties (fulfilled by this Policy); Meta is responsible for handling Art. 15–20 GDPR rights over data held on its side and for the security of its own processing. Meta publishes the full text at facebook.com/legal/controller_addendum; a summary is available on request to support@hotreply.app.
- Exercising your rights: under Art. 26(3) GDPR you may direct any request (access, rectification, erasure, restriction, objection) to either joint controller — us or Meta directly; the choice is entirely yours. Contact us at support@hotreply.app. For data held on Meta's side, the fastest route is your Meta account settings or Meta's Privacy Policy; if you would rather go through us, write to support@hotreply.app and we will help direct your request. For data we process directly, exercise your rights as described in Section 6.
We do not sell personal data. Meta Platforms Ireland is currently the only entity to which we transmit data for an advertising purpose — solely to measure the effectiveness of our own campaigns (see above), and only after you have given your consent. Having received that data, Meta also processes it for its own purposes as an independent controller, as described above.
5. Data Sharing
We do not sell, trade, or rent your personal information to third parties. We share data only in the following circumstances:
- With your explicit consent
- To comply with legal obligations or court orders
- To protect our rights, property, or safety, or that of our users
- In connection with a business transfer or merger (with prior notice)
- With service providers listed in Section 4, under strict confidentiality and on the terms set out there
- With Meta Platforms Ireland, solely to measure the performance of our own advertising campaigns, and only once you switch on that consent in Settings → Privacy Policy — see the Meta subsection in Section 4 for full details (data shared, the joint-controller relationship, and how to opt out)
6. Your Rights (GDPR)
Under the GDPR you have the following rights regarding your personal data:
- Access (Art. 15): request a copy of the personal data we hold about you
- Rectification (Art. 16): request correction of inaccurate or incomplete data
- Erasure (Art. 17 — "right to be forgotten"): request deletion of your personal data, subject to legal retention obligations
- Restriction (Art. 18): request restriction of processing under specific conditions
- Portability (Art. 20): receive your data in a structured, machine-readable format, or have it transferred to another controller
- Objection (Art. 21): object to processing based on legitimate interests at any time
- Withdrawal of consent: withdraw consent at any time, without affecting the lawfulness of processing prior to withdrawal
- Complaint: lodge a complaint with your national supervisory authority (Art. 77)
To exercise these rights, write to support@hotreply.app.
7. Data Retention
We retain personal data only as long as necessary for the purposes described:
- Account, User Identity, Voice Profile: until you delete your account
- Conversations and generated replies: until you delete them, or until you delete your account
- Match profile data (extracted text): as part of the relevant conversation — until that conversation is deleted
- Screenshots (image files): processed in memory only and removed immediately after AI analysis completes. We do not persist uploaded images.
- Subscription data: for the duration of the active subscription, then for the period required by accounting / tax obligations
- Technical log data (security, rate limiting): maximum 30 days
- Data sent to Meta (advertising-attribution SDK, only with your consent): we do not retain it on our side — it never reaches our database. On Meta's side it is kept for up to 2 years under Meta's own terms. The record of your consent (type, and date given or withdrawn) is kept until you delete your account, and afterwards in anonymised form, as evidence of compliance with Art. 7(1) GDPR.
8. Use of Artificial Intelligence (EU AI Act, Art. 50)
HotReply uses artificial intelligence to generate message suggestions and to analyse profile screenshots:
- Models: GPT-4o and GPT-4o-mini (OpenAI)
- Purpose: generating reply suggestions based on conversation context; extracting information about your match from pasted bio or screenshots
- No training on your data: the OpenAI API does not use your data to train models (OpenAI Business Data Processing Addendum)
- User control: every generated suggestion is just that — a suggestion. You decide what to send. You can edit or reject any suggestion.
- Labelling: AI-generated content is marked with an "AI" label and a verification note in line with Art. 50(4) of EU Regulation 2024/1689
9. Automated Decision-Making (GDPR Art. 13(2)(f))
HotReply does not subject you to any automated decision-making that produces legal effects or similarly significant impact. The AI only generates text suggestions — every decision (sending a message, interacting with a match) is made by you.
The 3-generations-per-day limit on free accounts is a hard service rule, not profiling.
10. International Data Transfers
Some of the providers listed in Section 4 (OpenAI, RevenueCat, the parent companies of Supabase, and — for data from the advertising-attribution SDK — Meta Platforms, Inc.) process data in the United States. Such transfers are made on the basis of:
- Standard Contractual Clauses (SCCs) under Art. 46(2)(c) GDPR (Commission Implementing Decision (EU) 2021/914), and / or
- EU–US Data Privacy Framework (DPF) where the relevant provider is certified under the European Commission's adequacy decision of 10 July 2023
- For Meta Platforms, Inc., the adequacy decision for the EU-U.S. Data Privacy Framework (Art. 45(1) GDPR, decision of 10 July 2023); should that decision lapse or Meta lose its certification, the transfer would instead rely on Standard Contractual Clauses (Art. 46(2)(c) GDPR)
For Google Play payments Google acts as an independent controller under the Google Play Developer Distribution Agreement and applies its own transfer safeguards.
On request, we provide a copy of the safeguards agreed with each processor: support@hotreply.app.
11. Children's Privacy
HotReply is intended exclusively for users 18 years of age or older. We do not knowingly collect personal data from minors. The App enforces an age confirmation gate at first launch.
If you become aware that a person under 18 has provided us with personal data, contact us at support@hotreply.app and we will promptly delete that data.
12. Cookies and Similar Technologies
HotReply is a mobile application and does not use website cookies. The App stores authentication tokens securely on the device using the operating-system keychain (Expo SecureStore). This storage is essential for keeping you signed in. For product analytics the App uses PostHog (see Section 4); this analytics data is pseudonymous, hosted in the EU, contains no conversation content, and is never used for advertising.
13. Account Deletion
How to request deletion. Send an email from the address registered with HotReply to support@hotreply.app with the subject "Account deletion". We confirm receipt within 48 hours and complete deletion within 30 days (Art. 12(3) GDPR). If your identity is unclear we may ask for additional confirmation, solely to protect your data against unauthorised deletion (Art. 12(6) GDPR).
What we erase: account credentials (email, hashed password, UUID), User Identity, Voice Profile, all conversations (messages, threads, AI variants, match-profile data), subscription status (locally and on RevenueCat), and anonymised rate-limit / screenshot-extraction logs.
What we retain and why: anonymised consent records (GDPR compliance evidence); deletion-request history (record of fulfilling the right to be forgotten); AI generation and moderation logs containing only a 16-character cryptographic hash of content (AI Act Art. 50 and Google Play AI-Generated Content Policy evidence, retained 24 months from your last activity); subscription billing records (accounting and tax obligations, typically 5 years). Encrypted database backups, where they exist, may still contain your data for up to 30 days after deletion and are not used to restore deleted accounts.
You can withdraw a deletion request only before processing begins (usually within 24 hours of submission). Once deletion has started the operation is irreversible.
14. Changes to This Policy
We may update this Privacy Policy from time to time to reflect legal, technical, or operational changes. Material changes will be communicated through the App or by email at least 30 days before they take effect. The current version is always available at this URL and in the App under Settings → Privacy Policy.
15. Contact
For privacy-related inquiries or to exercise your GDPR rights, contact us at:
HotReply
Email: support@hotreply.app