Skip to main content
Privacy & Data Safety Disclosure

Privacy Policy for REPLU

Effective Date: September 2026•App Version: 1.0.0•Developer: SydFoundry

This Privacy Policy explains how REPLU (developed by SydFoundry, “we”, “our”, or “the App”) handles user information and explains our commitment to user privacy, data protection, and transparent use of device permissions.

Core Privacy Guarantee

REPLU is built on an on-device privacy architecture. We never sell your data, we never upload full chat logs to remote databases, and all AI processing is encrypted in transit through our authenticated API gateway with local on-device style personalization.

1Prominent Disclosures & Device Permissions

To provide context-aware reply assistance, voice dictation, and seamless messaging integration, REPLU explicitly requests only the permissions necessary for its core assistive functionality:

A. Accessibility Service API (android.permission.BIND_ACCESSIBILITY_SERVICE)

REPLU uses Android's Accessibility Service API strictly to deliver its core assistive functionality in compliance with Google Play Developer Policies:

  • Why we use Accessibility: To detect incoming chat message text on active conversation screens and allow users to insert their chosen AI-generated response directly into the chat compose box with 1 tap.
  • Target Scope: The service is strictly restricted to active conversation windows of officially supported messaging applications: WhatsApp, WhatsApp Business, and Instagram Direct.
  • Explicit Exclusions: Our Accessibility Service NEVER reads or processes system UI, banking applications, payment apps, password input fields, lock screens, or Android system settings.
  • Sensitive Content Filtering: Automated on-device regex filtering immediately discards OTPs, verification codes, 2FA prompts, passwords, and credit card numbers prior to any processing.
  • No Automated Messaging: REPLU never sends messages on your behalf. Text is only pasted into the compose field when you explicitly tap the “Insert” button.
  • User Control: You must explicitly grant permission after reviewing the in-app disclosure. You can revoke this permission at any time in your device's Settings > Accessibility > Installed Apps > REPLU.

B. Microphone Permission (android.permission.RECORD_AUDIO)

  • Purpose: Used exclusively for the optional Voice Dictation and Speech-to-Text translation feature.
  • Active Only on Physical Touch: Audio is recorded only while you physically press and hold down the microphone button in the assistant panel.
  • No Background Listening: REPLU never listens to ambient sounds, phone calls, or background audio. When you release the mic button, recording terminates immediately.
  • Immediate Deletion: The temporary audio snippet stored in the device cache is deleted immediately from disk once transcription finishes.

C. Display Over Other Apps (android.permission.SYSTEM_ALERT_WINDOW)

Purpose: Allows REPLU to present the compact floating assistant bubble and smart reply panel on top of supported messaging screens so you can interact with suggestions without switching apps.

2Information We Process & What Is Stored Locally

To provide intelligent reply suggestions, voice dictation, and personalized communication styles, REPLU processes and stores the following:

  • In-Transit AI Processing via Secure API GatewayActive conversation turns (the immediate message context needed to craft a relevant answer) are transmitted over encrypted TLS 1.3/HTTPS through our secure backend API Gateway to OpenAI solely to generate suggested replies. Our gateway verifies app authenticity using hardware-backed Android KeyStore tokens and Play Integrity. We do not store your chat logs on any remote database, and data transmitted via OpenAI's commercial API is not used to train AI models in accordance with OpenAI's API Data Privacy Policy.
  • Voice Dictation Audio (Ephemeral)When you record voice input, audio is temporarily cached on-device, transmitted via encrypted HTTPS for transcription, and permanently deleted from local storage immediately upon completion.
  • On-Device Voice Persona (“Sound Like Me”)If you enable adaptive persona learning, your own sent messages are analyzed locally on your device to learn stylistic preferences (formality, warmth, emoji frequency, and favorite greeting phrases). This derived style data is stored strictly locally on your device in private application storage and is never uploaded to remote databases.
  • Contact Relationship Preferences (Local)Communication tone assignments (e.g. Professional, Casual Friend, Flirty) mapped to specific contact names are stored solely in your device's local private storage.
  • Voluntary AI Quality & Safety ReportsIf you voluntarily report an inappropriate or harmful AI suggestion via the in-app “Report Suggestion” dialog, the report reason (e.g. harmful, inappropriate, inaccurate) and the active app package name are submitted to our Firebase Firestore database solely to review AI safety and improve moderation guardrails.
  • App Diagnostics & Usage Counters (Local)Daily reply counts, feature usage metrics, and crash stack traces are kept in private local storage to enforce limits and diagnose bugs.

3Information We DO NOT Collect or Transmit

We do not upload your chat logs or message history to any remote database.
We do not collect or upload your contact address book.
We do not record keystrokes or password entries.
We do not track your precise GPS location.
We do not sell, rent, or monetize your personal conversations with advertisers or data brokers.
User Control & Data Deletion: You have full control. You can view, export, or permanently erase all locally stored persona phrases, contact settings, and usage logs at any time via the in-app Privacy Dashboard > Clear All Data.

4Third-Party Service Providers

To provide AI capabilities and ensure app stability, REPLU interacts with the following trusted providers:

  • OpenAI API: Processes conversational text prompts and audio snippets via encrypted HTTPS solely to generate reply suggestions and audio transcription, governed by the OpenAI Business Privacy Policy. Inputs provided via OpenAI's commercial API are not used to train AI models.
  • Google Firebase (Crashlytics, Analytics & Firestore): Collects anonymous device diagnostic metadata (device model, Android OS version, crash stack traces) to fix crashes, and securely stores user-submitted AI safety reports.
  • Google Play In-App Billing: Handles subscription processing securely. We never receive or store your credit card or payment information.

5Security of Your Data

All network communications between REPLU and our API Gateway are encrypted using industry-standard Transport Layer Security (TLS 1.3 / HTTPS). Local app preferences and tokens are stored using Android's EncryptedSharedPreferences (AES-256 GCM) and hardware-backed Android KeyStore authentication.

6Children's Privacy & Policy Updates

REPLU does not knowingly collect or solicit personal information from children under the age of 13. If you believe a child under 13 has provided personal data, please contact us to remove it immediately.

We may update this policy periodically. Any changes will be reflected with a revised “Effective Date” at the top of this document. Continued use of the App indicates acceptance of the updated policy.

8. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or your privacy rights, please contact our team:

SydFoundry • Developer of REPLU

[email protected]
Get REPLU on Google Play