ReplyMate

BDSoft · Your data

ReplyMate Privacy Policy

Effective date: October 4, 2026

ReplyMate is developed and operated by Buğra Doğan under the BDSoft name. BDSoft is the public developer brand.

This policy describes the ReplyMate mobile application and related ReplyMate service. External providers, including OpenAI, RevenueCat, Apple and Google, may process information under their own policies when their services are involved. This policy does not govern their independent practices.

Messages and AI processing

You type or paste an incoming conversation message and select a relationship, goal and tone. The generation request also includes a language value. Before Generate or Regenerate sends this content, ReplyMate checks your AI processing permission on this device.

With permission, the request is sent to ReplyMate's API. When AI generation is enabled, the server sends the message and generation preferences to OpenAI, the currently implemented live AI provider, to produce reply suggestions. This processing takes place off your device.

ReplyMate processes incoming messages transiently and does not persist the incoming message in its application database. ReplyMate requests store:false for OpenAI Responses API calls, asking OpenAI not to store the response through that API option. This is not a guarantee of zero provider retention; separate provider processing and retention rules may apply.

Your AI processing choice

You can Allow AI processing or Stop AI processing through Settings → Privacy & Data. Permission is stored locally on this device and is checked again before future Generate and Regenerate actions. Allowing permission does not automatically generate replies.

Stopping AI processing prevents future requests until you allow it again. It does not cancel an already-running request or retroactively delete generated replies, History, already processed provider data, usage accounting or purchase information. It does not cancel ReplyMate+.

Generated replies and History

Generated replies are stored in ReplyMate's database so they can appear in History. Stored information includes generated text and generation/reply metadata, such as your selected relationship, goal, tone and language, creation time, strategy and provider processing metadata. Generated text can itself contain sensitive information.

History access is limited to saved generations for which the device retains a secret read capability. You can delete an individual generation through History. After server authorization, deletion removes that generation and its generated replies from ReplyMate's database.

Copy and feedback

ReplyMate stores limited interaction metadata: whether a reply was copied and whether you liked or disliked it. These fields support product functionality; they are not advertising or analytics tracking.

Only when you explicitly tap Copy does ReplyMate place the selected generated reply text in the system clipboard. The separate copied-status request contains reply identity metadata, not the copied text. Your operating system and other applications may have their own clipboard handling.

Pseudonymous identity and free usage

ReplyMate creates a random installation UUID on your device and maps it to an internal pseudonymous user UUID on the server. These app-generated identifiers support application identity, existing generation operations and free-generation accounting. They are not hardware or advertising IDs and are not authentication credentials.

There is no traditional named account registration. ReplyMate does not request your name or email to establish application identity. Pseudonymous identifiers can still link generated content, usage and subscription access within the service.

The server retains free-usage accounting identifiers, reservation/consumption state and timestamps to enforce the generation allowance. Deleting a saved generation does not delete consumed usage accounting or refund a consumed free generation.

ReplyMate+ purchases and subscriptions

ReplyMate uses RevenueCat for purchase and subscription integration. ReplyMate provides RevenueCat its internal pseudonymous user ID to associate subscription access. ReplyMate does not send incoming conversation text, generated reply text, relationship, goal, tone or History contents to RevenueCat.

RevenueCat and the Apple App Store or Google Play process the purchase and subscription information needed for transactions and access. ReplyMate does not directly handle payment-card or bank-account details. These providers' independent retention is outside ReplyMate's control.

ReplyMate's server checks entitlement through RevenueCat. ReplyMate does not persist RevenueCat customer information, receipts or a local premium flag as its authorization source. The RevenueCat SDK may maintain its own device cache; it does not authorize server access.

Local device storage and regeneration

ReplyMate stores onboarding completion, installation identity and AI processing permission locally. Secret generation-read capabilities are stored through Expo SecureStore and authorize access to individual saved generations. Generated reply text is fetched into memory, rather than intentionally persisted in ReplyMate's own local application storage.

The original validated request used for Regenerate, including the incoming message, remains only in JavaScript process memory. It is not persisted for History restoration and is lost on a full runtime restart. A cold-restored History result does not recreate that request.

Clearing application data or uninstalling may affect local data and access to saved content. Exact behavior depends on the operating system and device; removing local data is not server-side content deletion.

Purposes and service providers

ReplyMate uses this information to generate reply suggestions, provide History, support Copy and feedback, enforce free usage, provide ReplyMate+ access, and maintain security and authorization boundaries. OpenAI handles enabled AI generation; RevenueCat and the app stores handle purchase/subscription integration. The production API hosting provider has not yet been selected.

ReplyMate does not currently include advertising or analytics tracking. The public site's static source uses no JavaScript, third-party assets, forms, intentional cookies or browser storage. Hosting infrastructure may process ordinary technical network logs. Cloudflare Pages is the intended static website host, not the ReplyMate API or database host.

Retention and deletion boundaries

Incoming messages are not retained in ReplyMate's application database. This does not determine retention by OpenAI or other external providers.

Generated replies are retained for History until you delete the individual generation or the service's future retention behavior changes. There is currently no automatic age-based deletion workflow.

Individual History deletion removes selected content. Consumed quota records remain separately retained and are not refunded or deleted with that content. It does not delete your pseudonymous identity, other generations or provider/store records. Local capability cleanup follows confirmed server deletion; operating-system storage failures can prevent complete local cleanup without restoring deleted server content.

ReplyMate currently has no named-account deletion flow or delete-all feature. AI permission revocation, local data clearing and individual History deletion have different effects and do not promise complete identity or provider-data erasure.

Security

Server secrets are not embedded in mobile configuration. Generation-read capabilities are treated as secrets and use SecureStore on mobile. Normal production application logging excludes raw incoming messages, generated/provider content and private identifiers.

A production API HTTPS deployment remains an external requirement and has not yet been verified. These measures do not establish end-to-end encryption, encryption of all data at rest or guaranteed security.

Policy updates

This policy may change as product or data practices change. The effective date will be updated when the policy is revised.

Privacy questions and requests

Contact Buğra Doğan, BDSoft, at dev.bugradogan@gmail.com. Please avoid sending private conversation content unless necessary to explain your request.

Because ReplyMate uses pseudonymous identities, a real-world name or email alone may not identify every server record. This contact does not imply a currently implemented account-wide deletion process or a fixed response deadline.