Privacy Policy
Version and last updated: August 5, 2026
This document is provided in English.
This notice explains how Responses handles personal data in its web, iOS, Android and API services. When the product asks you to acknowledge this Privacy Policy, you acknowledge that you have read the current version. That acknowledgement is not consent and is not presented as the legal basis for all processing.
1. Who is responsible
The controller for account administration, authentication and security, billing, diagnostics, support and the operation of the service is Andrii Serhiiovych Tretiakov, Individual Entrepreneur (FOP), Ukraine. Full provider details are available in the Legal Notice.
A workspace owner determines why and how its customer communications are handled and is the controller of that Customer Content. Responses provides the tool and processes Customer Content, connected-platform credentials and end-user data on the workspace owner's instructions. See the Data Processing Addendum for the processing scope.
2. Who this notice covers
Responses is a business tool offered to people aged 18 or older. It is not directed to children, accounts for children are not offered, and children's data is not knowingly processed for account purposes. A workspace owner remains responsible for the age and authority rules that apply to the customers it communicates with.
3. Data handled by Responses
- Account and contact data: name, email, password hash, email-verification state, account kind, workspace membership and role, preferences, support messages and the recorded versions of Terms acceptance and Privacy Policy acknowledgement.
- Session and security data: hashed refresh and auth tokens, token expiry, hashed IP context, user agent, login and security events, and request metadata such as method, path, status and duration.
- Customer communications: inbound and outbound message text, platform attachment references, customer display names and platform identifiers, thread and delivery metadata, assignments, AI drafts and approved replies.
- Public store reviews: for a connected App Store or Google Play app, the review text, its star rating, the reviewer nickname the store publishes and the developer response. Both the review and the response are public on the storefront: a response is not delivered to one person but published under the app, where anyone can read it, and it is removed by the store rather than by Responses.
- Connected-channel data: platform, account identifiers, display name, connection state and encrypted access or refresh credentials.
- Workspace configuration: team membership, assistant instructions, knowledge documents, channel and webchat configuration, API-key hashes and audit events.
- Webchat visitor data: an opaque visitor identifier and any display name or email the visitor chooses to enter. Responses does not persist a webchat visitor's IP, user agent, referrer or page URL in the visitor record.
- Billing and usage: plan and subscription status, Stripe customer and subscription identifiers where applicable, store product and hashed subscription references, billing-event identifiers, and counters for inbound messages, AI replies and AI tokens.
- Notifications and diagnostics: browser push endpoints and keys, APNs or FCM device tokens, optional server exceptions sent to Sentry, and mobile analytics and crash diagnostics sent through Firebase only after each optional service is enabled.
4. Sources
- Account holders, workspace members, webchat visitors and people contacting support.
- Official APIs and webhooks for Instagram, Facebook, WhatsApp, Telegram, Gmail and Outlook after a workspace connects the relevant account.
- The App Store Connect and Google Play Developer APIs, which are read on a schedule for the public reviews of an app a workspace has connected. Nobody is contacted to obtain them: a review is published by its author on the storefront and is read from there.
- Stripe, Apple App Store and Google Play for subscription state.
- Web, iOS and Android clients and the service infrastructure during operation.
5. Purposes and legal bases
- Authenticate users, maintain sessions and enforce workspace roles.
- Receive, organize, display and send customer communications.
- Connect official platform accounts and maintain webchat sites.
- Generate AI classifications and reply drafts and apply configured handoff rules.
- Operate subscriptions, limits, notifications, support and data controls.
- Protect the service, diagnose failures and maintain content-free audit records.
- Handle in-product reports for safety, abuse handling, support and enforcement.
Where the EU or UK GDPR or a comparable law applies, these purposes rest on the following legal bases:
- Performance of the contract: creating and administering an account and workspace, receiving and sending customer communications, generating AI drafts, operating connected channels, subscriptions, limits and support.
- Legitimate interests: keeping the service secure and available, rate limiting, abuse handling, moderation of reported content, fraud prevention, content-free audit and security records, and defending legal claims.
- Legal obligation: tax, accounting and billing records, and responses to lawful requests.
- Consent: optional mobile analytics, optional crash diagnostics, and push notifications. Each has its own control, shown on the screen where the current Terms and Privacy Policy are accepted and switched on there by default. Nothing is collected while that screen is open: collection begins only when it is completed, and every control can be turned off before that. Each can be changed or withdrawn at any time in the app's privacy settings without affecting the lawfulness of prior processing.
6. AI processing
The deployment selects one configured provider: OpenAI, Google Gemini or Anthropic Claude. A request can include recent conversation history, active assistant instructions and selected knowledge snippets. Pattern-based redaction masks detected email addresses, phone numbers, payment-card numbers and IBANs before this text is sent. Names, addresses and other free-form personal data can remain. AI output can be wrong and can be reported in Responses.
AI processing is off for each newly connected channel. Before enabling it, Responses shows this data-sharing scope and requires the workspace operator to confirm; disabling the channel stops new messages from being sent to the AI provider.
OpenAI Responses API and Gemini Interactions API calls set store: false. Anthropic calls use the Messages API without application-managed provider conversation state. Those implementation choices do not by themselves establish a contractual zero-retention commitment by a provider.
Replies sent automatically, without your review, carry a marker identifying them as AI-written. A workspace can turn that marker off in its assistant settings; it is on unless someone changes it.
7. Reporting, operator access and blocking
A report can identify a customer message, AI output or customer identity. Message text is not copied into the report record; the report points to the stored message. Authorized Responses operators may view reported content and the minimum surrounding context needed for safety, abuse handling, support and enforcement. Each such content view is audited, and report decisions record the reviewing user and time.
Reports stay within Responses and are not forwarded to Meta, Google, Telegram or another platform. Reports belong to the workspace and are cascade-deleted when their conversation or workspace is deleted. Blocking also applies only inside Responses; it does not invoke a connected platform's block function.
8. Processors, recipients and processing locations
- Connected platforms: Meta services, Telegram, Google, Microsoft and Apple provide inbound content and receive outbound replies for connected accounts. For a connected app, Apple and Google additionally publish the developer response to a review on their storefront, where it is public and stays under the store's control.
- AI: the one configured provider among OpenAI, Google Gemini and Anthropic receives the minimized context described above.
- Billing: Stripe handles web checkout; Apple and Google handle in-app purchases. Responses stores provider identifiers and mirrored subscription state, not full payment-card details.
- Communications and diagnostics: Postmark handles transactional and support email; Sentry receives server exceptions only when configured; Firebase provides separately controlled mobile analytics and crash diagnostics and FCM delivery for Android; Apple provides APNs delivery for iOS.
- Infrastructure: the application, its database and its logs run on IONOS SE hosting, United States (Missouri). Encrypted database backups are stored on Cloudflare R2, European Union jurisdiction.
Responses does not sell personal data and does not share it for cross-context behavioural advertising.
The service is operated from Ukraine and hosted in the United States, and the processors above operate in the United States, the European Union and other countries. Transfers out of the European Economic Area or the United Kingdom rely on the European Commission's Standard Contractual Clauses together with the UK Addendum where applicable, or on another transfer mechanism the processor makes available, including an adequacy decision where one covers the recipient. A copy of the transfer terms relied on for a specific processor can be requested at support@responses.me.
9. Retention and deletion
- Stored raw webhook events have a seven-day database TTL.
- Billing webhook idempotency records have a 90-day database TTL.
- Audit events have a 365-day TTL and security events a 180-day TTL.
- Sessions and email-verification/password-reset token records expire at their own expiry.
- Meta deletion status records have a 180-day TTL.
- Message retention is applied by plan: currently 14, 30, 90 or 365 days. It deletes stored message rows older than the applicable cutoff.
- Connected-platform credentials are deleted when the channel is disconnected.
- Server and worker logs — request identifiers, routes, status codes and durations, never message content — are kept on the host journal for 30 days and then removed.
- The Mongo backup script encrypts archives and rotates local and rclone-backed remote copies after
BACKUP_RETENTION_DAYS(30 days by default).
Product controls can delete conversation history, a workspace or an account. Workspace deletion cascades through messages, reports, channel credentials, knowledge data and other workspace records. Account deletion cancels account billing through the configured billing service, deletes owned workspaces, removes memberships and account-level records, and then deletes the user. See data-deletion instructions.
10. Security and access
Responses uses TLS endpoints, role-scoped workspace access, argon2id password hashes, hashed refresh tokens and AES-256-GCM encryption for connected-platform credentials. Operational logging is designed to exclude bodies, messages, prompts and credentials; configured redaction provides an additional safeguard. No system is perfectly secure.
11. Your rights, choices and requests
Account holders can export account-level records, and workspace owners can export workspace data, delete a conversation, delete a workspace or delete their account using product controls. Authentication secrets and connected-platform credentials are excluded from exports. A person whose message is controlled by a workspace owner should normally contact that business first. Meta also provides a signed data-deletion callback for app-scoped Facebook and Instagram data.
Where the EU or UK GDPR, the Ukrainian personal-data law or a comparable law applies, you can request access to your personal data, correction, deletion, restriction of processing, portability, and object to processing based on legitimate interests. Where processing rests on consent, you can withdraw it at any time in the app's privacy settings. Requests sent to support@responses.me are answered within 30 days; if a request is complex, the deadline can be extended once by a further 60 days and you are told about the extension and the reason inside the first 30 days.
If a request is refused, you can appeal by replying to the decision at the same address, and the appeal is reviewed by the provider. You can also complain to a supervisory authority: in Ukraine, the Ukrainian Parliament Commissioner for Human Rights; in the European Economic Area or the United Kingdom, the data-protection authority of your habitual residence, place of work or place of the alleged infringement.
12. Changes and contact
Responses publishes the current version at this URL. Reading or acknowledging a new Privacy Policy does not silently accept new Terms.
- Provider
- Andrii Serhiiovych Tretiakov — Individual Entrepreneur (FOP), Ukraine
- Contact
- support@responses.me
- Legal information
- Full provider details