Legal
Privacy Policy
Effective November 25, 2026 · ReplyNow, operated by Hawkmountain Apps Oy
ReplyNow is designed around a simple rule: your conversations are yours. This policy explains what personal data Hawkmountain Apps Oy ("we") processes when you use ReplyNow, and the choices you have.
1. Controller
The controller of your personal data is Hawkmountain Apps Oy, Finland. Contact us at pekka@nebelung.io.
2. What we collect
- Account data — email address, sign-in method (Google or email + password), and, if you sign in with Google, your basic Google profile (name, avatar).
- Profile data — display name, role, bio, signature, preferred tone, and the languages you speak.
- Uploaded conversations — screenshots, images, or text you paste into ReplyNow so we can generate replies. See "Retention" below.
- Generated replies — the four suggestions we return, and which one you copy.
- Usage data — number of replies generated per month, selected goals/tones, chosen plan and subscription status.
- Technical data — IP address, browser/user-agent, and timestamps needed for security, fraud prevention, and error logging.
3. Why we process it (purposes and legal bases)
- Provide the service — generating replies, storing your profile, running your subscription. Legal basis: contract performance (GDPR art. 6(1)(b)).
- Security and abuse prevention — detecting fraud, preventing account takeover, enforcing our Acceptable Use Policy. Legal basis: legitimate interests (GDPR art. 6(1)(f)).
- Product improvement — aggregated, non-identifying metrics such as feature usage. Legal basis: legitimate interests.
- Legal obligations — tax, accounting, responding to lawful requests. Legal basis: legal obligation (GDPR art. 6(1)(c)).
4. Retention
The screenshot, image, or text you upload is deleted immediately after the AI generates replies. We do not persist the raw conversation on our servers.
- Uploaded conversation: discarded within seconds — the moment the AI response is returned.
- Generated replies and metadata (goal, tone, timestamp): stored in your browser's local storage (not on our servers) and visible only to you. You can clear it any time from the History screen.
- Account and profile: kept for as long as your account exists. When you delete your account, all associated data is removed within 30 days, except records we must keep for legal reasons (e.g. tax invoices handled by Paddle — see below).
- Server logs: kept for up to 30 days for security and debugging, then deleted.
5. AI training
Your conversations and prompts are never used to train ReplyNow's own models or the underlying models of our AI providers.
Requests are routed through the Lovable AI Gateway to OpenAI (GPT-family) under a data-processing agreement that opts out of provider training. If this ever changes for a specific feature, we will disclose it clearly and require your opt-in first.
6. Who we share data with (sub-processors)
- Supabase — EU-hosted database, authentication, and storage for your account and profile.
- Lovable AI Gateway / OpenAI / Anthropic / Google AI — AI inference. Prompts are transmitted for generation and not retained for training.
- Paddle — our Merchant of Record. Paddle processes payment data, subscription state, invoices, and tax on our behalf. See Paddle's privacy notice.
- Cloudflare — hosting, CDN, and edge-compute (Workers).
We do not sell your personal data and do not share it with advertising networks.
7. International transfers
Some of the sub-processors listed above operate outside the EU/EEA. Transfers rely on the European Commission's Standard Contractual Clauses and/or the EU–US Data Privacy Framework where applicable. You can request a copy of the transfer safeguards by emailing pekka@nebelung.io.
8. Your rights (GDPR)
- Access — request a copy of the data we hold about you.
- Rectification — correct inaccurate data.
- Erasure — delete your account and all associated data.
- Restriction — ask us to pause certain processing.
- Portability — receive your profile data in a machine-readable form.
- Objection — object to processing based on legitimate interests.
- Complaint — lodge a complaint with your local supervisory authority. In Finland this is the Office of the Data Protection Ombudsman.
To exercise any right, email pekka@nebelung.io. We aim to respond within one month.
9. Security
We use TLS 1.3 in transit, AES-256 at rest, row-level security in the database, and least-privilege access to production data. See our Security page for more.
10. Cookies
Details are in our Cookie Policy. We use only essential cookies for authentication and Paddle checkout.
11. Changes
We will announce material changes at least 14 days before they take effect, in the app or by email.
Questions about this document? Email pekka@nebelung.io.
