Privacy Policy

Version and last updated: August 5, 2026

This document is provided in English.

This notice explains how Responses handles personal data in its web, iOS, Android and API services. When the product asks you to acknowledge this Privacy Policy, you acknowledge that you have read the current version. That acknowledgement is not consent and is not presented as the legal basis for all processing.

1. Who is responsible

The controller for account administration, authentication and security, billing, diagnostics, support and the operation of the service is Andrii Serhiiovych Tretiakov, Individual Entrepreneur (FOP), Ukraine. Full provider details are available in the Legal Notice.

A workspace owner determines why and how its customer communications are handled and is the controller of that Customer Content. Responses provides the tool and processes Customer Content, connected-platform credentials and end-user data on the workspace owner's instructions. See the Data Processing Addendum for the processing scope.

2. Who this notice covers

Responses is a business tool offered to people aged 18 or older. It is not directed to children, accounts for children are not offered, and children's data is not knowingly processed for account purposes. A workspace owner remains responsible for the age and authority rules that apply to the customers it communicates with.

3. Data handled by Responses

4. Sources

5. Purposes and legal bases

Where the EU or UK GDPR or a comparable law applies, these purposes rest on the following legal bases:

6. AI processing

The deployment selects one configured provider: OpenAI, Google Gemini or Anthropic Claude. A request can include recent conversation history, active assistant instructions and selected knowledge snippets. Pattern-based redaction masks detected email addresses, phone numbers, payment-card numbers and IBANs before this text is sent. Names, addresses and other free-form personal data can remain. AI output can be wrong and can be reported in Responses.

AI processing is off for each newly connected channel. Before enabling it, Responses shows this data-sharing scope and requires the workspace operator to confirm; disabling the channel stops new messages from being sent to the AI provider.

OpenAI Responses API and Gemini Interactions API calls set store: false. Anthropic calls use the Messages API without application-managed provider conversation state. Those implementation choices do not by themselves establish a contractual zero-retention commitment by a provider.

Replies sent automatically, without your review, carry a marker identifying them as AI-written. A workspace can turn that marker off in its assistant settings; it is on unless someone changes it.

7. Reporting, operator access and blocking

A report can identify a customer message, AI output or customer identity. Message text is not copied into the report record; the report points to the stored message. Authorized Responses operators may view reported content and the minimum surrounding context needed for safety, abuse handling, support and enforcement. Each such content view is audited, and report decisions record the reviewing user and time.

Reports stay within Responses and are not forwarded to Meta, Google, Telegram or another platform. Reports belong to the workspace and are cascade-deleted when their conversation or workspace is deleted. Blocking also applies only inside Responses; it does not invoke a connected platform's block function.

8. Processors, recipients and processing locations

Responses does not sell personal data and does not share it for cross-context behavioural advertising.

The service is operated from Ukraine and hosted in the United States, and the processors above operate in the United States, the European Union and other countries. Transfers out of the European Economic Area or the United Kingdom rely on the European Commission's Standard Contractual Clauses together with the UK Addendum where applicable, or on another transfer mechanism the processor makes available, including an adequacy decision where one covers the recipient. A copy of the transfer terms relied on for a specific processor can be requested at support@responses.me.

9. Retention and deletion

Product controls can delete conversation history, a workspace or an account. Workspace deletion cascades through messages, reports, channel credentials, knowledge data and other workspace records. Account deletion cancels account billing through the configured billing service, deletes owned workspaces, removes memberships and account-level records, and then deletes the user. See data-deletion instructions.

10. Security and access

Responses uses TLS endpoints, role-scoped workspace access, argon2id password hashes, hashed refresh tokens and AES-256-GCM encryption for connected-platform credentials. Operational logging is designed to exclude bodies, messages, prompts and credentials; configured redaction provides an additional safeguard. No system is perfectly secure.

11. Your rights, choices and requests

Account holders can export account-level records, and workspace owners can export workspace data, delete a conversation, delete a workspace or delete their account using product controls. Authentication secrets and connected-platform credentials are excluded from exports. A person whose message is controlled by a workspace owner should normally contact that business first. Meta also provides a signed data-deletion callback for app-scoped Facebook and Instagram data.

Where the EU or UK GDPR, the Ukrainian personal-data law or a comparable law applies, you can request access to your personal data, correction, deletion, restriction of processing, portability, and object to processing based on legitimate interests. Where processing rests on consent, you can withdraw it at any time in the app's privacy settings. Requests sent to support@responses.me are answered within 30 days; if a request is complex, the deadline can be extended once by a further 60 days and you are told about the extension and the reason inside the first 30 days.

If a request is refused, you can appeal by replying to the decision at the same address, and the appeal is reviewed by the provider. You can also complain to a supervisory authority: in Ukraine, the Ukrainian Parliament Commissioner for Human Rights; in the European Economic Area or the United Kingdom, the data-protection authority of your habitual residence, place of work or place of the alleged infringement.

12. Changes and contact

Responses publishes the current version at this URL. Reading or acknowledging a new Privacy Policy does not silently accept new Terms.

Provider
Andrii Serhiiovych TretiakovIndividual Entrepreneur (FOP), Ukraine
Contact
support@responses.me
Legal information
Full provider details