HotReply ← Home

Privacy Policy

Effective date: 2026-05-20

This Privacy Policy explains how HotReply ("we", "our", "us") collects, uses, stores, and protects your personal data when you use the HotReply mobile application (the "App"). HotReply is an AI-powered dating copilot that helps you draft messages on dating apps. This policy is written in compliance with the EU General Data Protection Regulation (GDPR) and the EU AI Act (Regulation 2024/1689).

1. Information We Collect

Account Information

Profile Information

Usage Information

2. How We Use Your Information

3. Data Storage and Security

We implement appropriate technical and organizational measures under Art. 32 GDPR to protect your personal data against unauthorized access, alteration, disclosure, or destruction:

4. Third-Party Services

We share data with carefully selected processors that operate under Data Processing Agreements (Art. 28 GDPR):

Supabase (Auth, Database, Storage)

OpenAI (AI Processing)

RevenueCat (Subscription Management)

Google Play (App Distribution and Payments)

We do not share data with third parties for marketing or advertising purposes.

5. Data Sharing

We do not sell, trade, or rent your personal information to third parties. We share data only in the following circumstances:

6. Your Rights (GDPR)

Under the GDPR you have the following rights regarding your personal data:

To exercise these rights, write to privacy@hotreply.app.

7. Data Retention

We retain personal data only as long as necessary for the purposes described:

Premium feature limits. To prevent abuse, screenshot extraction is limited to a maximum of 10 extractions per 24 hours and 3 per hour.

8. Use of Artificial Intelligence (EU AI Act, Art. 50)

HotReply uses artificial intelligence to generate message suggestions and to analyse profile screenshots:

9. Automated Decision-Making (GDPR Art. 13(2)(f))

HotReply does not subject you to any automated decision-making that produces legal effects or similarly significant impact. The AI only generates text suggestions — every decision (sending a message, interacting with a match) is made by you.

The 3-generations-per-day limit on free accounts is a hard service rule, not profiling.

10. International Data Transfers

Some of the processors listed in Section 4 (OpenAI, RevenueCat, parent companies of Supabase and Google) process data in the United States. Such transfers are made on the basis of:

On request, we provide a copy of the safeguards agreed with each processor: privacy@hotreply.app.

11. Children's Privacy

HotReply is intended exclusively for users 18 years of age or older. We do not knowingly collect personal data from minors. The App enforces an age confirmation gate at first launch.

If you become aware that a person under 18 has provided us with personal data, contact us at privacy@hotreply.app and we will promptly delete that data.

12. Cookies and Similar Technologies

HotReply is a mobile application and does not use website cookies. The App stores authentication tokens securely on the device using the operating-system keychain (Expo SecureStore). This storage is essential for keeping you signed in and is not used for tracking or advertising.

13. Account Deletion

How to request deletion. Send an email from the address registered with HotReply to support@hotreply.app with the subject "Account deletion". We confirm receipt within 48 hours and complete deletion within 30 days (Art. 12(3) GDPR). If your identity is unclear we may ask for additional confirmation, solely to protect your data against unauthorised deletion (Art. 12(6) GDPR).

What we erase: account credentials (email, hashed password, UUID), User Identity, Voice Profile, all conversations (messages, threads, AI variants, match-profile data), subscription status (locally and on RevenueCat), and anonymised rate-limit / screenshot-extraction logs.

What we retain and why: anonymised consent records (GDPR compliance evidence); deletion-request history (record of fulfilling the right to be forgotten); AI generation and moderation logs containing only a 16-character cryptographic hash of content (AI Act Art. 50 and Google Play AI-Generated Content Policy evidence, retained 24 months from your last activity); subscription billing records (accounting and tax obligations, typically 5 years). Encrypted database backups may still contain your data for up to 30 days after deletion and are automatically overwritten thereafter.

You can withdraw a deletion request only before processing begins (usually within 24 hours of submission). Once deletion has started the operation is irreversible.

14. Changes to This Policy

We may update this Privacy Policy from time to time to reflect legal, technical, or operational changes. Material changes will be communicated through the App or by email at least 30 days before they take effect. The current version is always available at this URL and in the App under Settings → Privacy Policy.

15. Contact

For privacy-related inquiries or to exercise your GDPR rights, contact us at:

HotReply
Email: privacy@hotreply.app
General support: support@hotreply.app