Privacy Policy
Last Updated: 29 June 2026
This Privacy Policy describes how knowReply Ltd ("we", "us", or "our") collects, uses, and protects your personal information when you use knowReply ("the Service") at knowreply.io.
knowReply Ltd is a company registered in England and Wales. As a UK-based company, we comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
---
1. Information We Collect
1.1 Information You Provide
Account Information
- Email address
- Name and profile information
- Password (stored as a one-way hash — we never store plaintext passwords)
Service Configuration
- Knowledge base entries (FAQs, policies, product information)
- Auto-reply settings and preferences
- Triage thresholds and review window configuration
Payment Information
- Billing information processed through Stripe (we do not store card numbers)
- Subscription tier and billing history
1.2 Information Automatically Collected
Usage Data
- Number of replies sent and suggested
- Inbox activity and triage events
- Login timestamps and session information
Technical Data
- IP address
- Browser type and version
- Device and operating system information
- Referring pages and timestamps
1.3 Information from Third-Party Integrations
You may connect the following services to your knowReply account. Each integration collects specific data:
Shopify
- Store name, shop domain, and shop ID (via OAuth)
- Customer order data including order number, email, fulfilment status, line items, and tracking information (read-only, `read_orders` scope)
- We do not store order data — it is fetched in real time when needed to draft a reply and is not persisted
Instagram (Meta)
- Instagram Business account ID and username (via OAuth)
- Direct message content from your connected account (received via Meta webhook)
- We process message content to generate reply suggestions
X (Twitter)
- X account ID and username (via OAuth)
- Direct message content from your connected account
Email (IMAP/SMTP)
- Email address and connection credentials (stored encrypted)
- Incoming email content for triage and reply suggestion
Google OAuth
- Email address, name, and profile picture (used for sign-in only)
---
2. How We Use Your Information
2.1 To Provide the Service
- Authenticate your account and manage sessions
- Receive and triage incoming messages from connected channels
- Generate AI-powered reply suggestions using your knowledge base
- Fetch live order data from your connected Shopify store to answer customer order queries
- Send auto-replies on your behalf when you enable auto-reply
- Display your inbox and conversation history
2.2 For Billing
- Process payments through Stripe
- Manage your subscription, billing cycle, and plan changes
- Send invoices and payment receipts
- Handle Shopify App Pricing charges for merchants who install via the Shopify App Store
2.3 For Communications
- Send service notifications (usage limits, errors, important updates)
- Respond to support requests
- Communicate changes to these terms or this policy
2.4 For Improvement
- Analyse usage patterns to improve the product
- Monitor performance and debug errors
---
3. How We Share Your Information
We do not sell your personal information.
3.1 Third-Party Service Providers
Shopify — We query the Shopify Admin API using your stored OAuth token to fetch order data in real time when a customer asks about an order. We do not share your data with Shopify beyond what is required for this query.
Meta (Instagram) — Message content is received via Meta webhooks and processed to generate reply suggestions. Subject to Meta's Privacy Policy.
Stripe — Payment and billing information for subscription management. Subject to Stripe's Privacy Policy.
Firebase / Google Cloud — Account data, conversation metadata, and knowledge base entries are stored on Google Cloud infrastructure (Firebase Firestore). Subject to Google's Privacy Policy.
Groq — Message content may be sent to Groq's API to generate AI reply suggestions. Content is not stored by Groq beyond the duration of the API request. Subject to Groq's Privacy Policy.
3.2 Legal Requirements
We may disclose information if required by law, court order, or government request, or to protect our rights, prevent fraud, or ensure user safety.
3.3 Business Transfers
If knowReply Ltd is acquired or merges with another entity, your information may be transferred. You will be notified in advance.
---
4. Data Security
We implement appropriate technical and organisational measures to protect your data:
- Encryption: Data encrypted in transit (TLS/SSL) and at rest
- Authentication: Secure OAuth 2.0 flows; passwords stored as bcrypt hashes
- Access Controls: Minimal internal access on a need-to-know basis
- Infrastructure: Hosted on Firebase / Google Cloud Platform
No system is completely secure. You are responsible for keeping your account credentials safe and notifying us of any suspected unauthorised access.
---
5. Data Retention
- We retain your data for as long as your account is active
- When you delete your account, personal data is deleted within 30 days
- Some data may be retained for legal, tax, or fraud-prevention purposes
- Backup systems may retain data for up to 90 days after deletion
- Message content processed for AI suggestions is not stored beyond the session
---
6. Your Rights (UK GDPR)
As a UK resident (or any individual whose data we process), you have the following rights:
- Right of Access — Request a copy of your personal data
- Right to Rectification — Correct inaccurate or incomplete data
- Right to Erasure — Request deletion of your data
- Right to Restriction — Limit how we process your data
- Right to Data Portability — Receive your data in a portable format
- Right to Object — Object to processing based on legitimate interests
- Right to Withdraw Consent — Where processing is based on consent
To exercise any of these rights, email support@knowreply.io.
We will respond within 30 days. If you are unsatisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
Legal bases for processing:
- Performance of a contract (providing the Service)
- Legitimate interests (security, fraud prevention, product improvement)
- Consent (marketing communications, optional integrations)
- Legal obligation (tax, regulatory compliance)
---
7. California Residents (CCPA/CPRA)
If you are a California resident, you have the right to know what personal information we collect, access it, request deletion, and opt out of the sale of personal information. We do not sell personal information. To submit a request, email support@knowreply.io with "California Privacy Rights" in the subject line. We will respond within 45 days.
---
8. International Data Transfers
Your data may be processed outside the UK by our third-party providers (Google Cloud, Stripe, Meta, Groq). These providers implement appropriate safeguards including Standard Contractual Clauses and equivalent data protection measures.
---
9. Children's Privacy
The Service is not intended for individuals under 18. We do not knowingly collect data from children. If you believe we have done so, contact us at support@knowreply.io and we will delete it immediately.
---
10. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or in-app notice at least 14 days in advance. The "Last Updated" date at the top will always reflect the current version.
---
11. Contact Us
knowReply Ltd
London, United Kingdom
Email: support@knowreply.io
Website: https://knowreply.io
For UK GDPR enquiries or to exercise your rights, contact us at the email above. We aim to respond within 7 business days.