Data residency
Where your data goes
ReplyPen reads your support inbox and writes draft replies, so real customer emails pass through real companies. There are two of them, and neither may train on your data.
Last verified: 28 August 2026
The AI step
Two AI companies. That is the whole list.
Understanding your emails and drafting replies, screenshots and attachments included, happens at Google and OpenAI. Nobody else sees your email content, and both work under business terms that forbid training on it.
Google
Gemini models on Google Cloud (Vertex AI), EU multi-region
🇪🇺 Processed in the EU
- Trains on your data: Never
- Keeps your data: ● Not stored
“Google will not use Customer Data to train or fine-tune any AI/ML models without Customer's prior permission or instruction.”
Read their terms →
OpenAI
GPT models on the OpenAI API
🇺🇸 Processed in the United States
- Trains on your data: Never
- Keeps your data: ● Abuse logs, deleted within 30 days
“Data sent to the OpenAI API is not used to train or improve OpenAI models (unless you explicitly opt in) … abuse monitoring logs … retained for up to 30 days.”
Read their policy →
Everything else
What we keep, and where
No AI company touches any of this.
Your emails, on our side 🇪🇺 Frankfurt · deleted after 14 days
Threads and the drafts we write sit on encrypted servers at Amazon Web Services in Frankfurt, Germany. We wipe them automatically after 14 days. What survives is the run's timeline: event types, timestamps, and a hash and byte count of each wiped payload, so you can still prove what ran and when. That timeline is kept for at most twelve months. Backups are encrypted, stay in Frankfurt and roll off after seven days. Your mail itself never leaves your own mailbox, and we never delete anything from it. Account and notification emails to you go out through AWS in Ireland, also the EU.
What ReplyPen learns 🇺🇸 Private GitHub repository
Your product answers, tone of voice and help-centre material live in a private repository we keep for as long as you are a customer. It is knowledge about your product, not a copy of your inbox. Ask us for access and you can read and edit it yourself. Ask us to delete it and we do, within 30 days, confirmed in writing. If GitHub in the United States is a problem for you, we can host this repository on a different git provider, including an EU-hosted one, on request.
Error monitoring 🇪🇺 PostHog EU cloud
So we hear about breakage before you do. It receives technical error details, what failed and where, and never your inbox.
Your choice
Only if you switch it on
Your mailbox provider is always involved, because that is the inbox we read. Gmail means Google, where Google's Limited Use rules bind us on top of everything else. Outlook and Microsoft 365 mean Microsoft. Intercom means Intercom. Any other mailbox over IMAP means your own email provider, so nobody new is added at all.
Anything you connect yourself, such as Shopify, Stripe or Slack, only receives data once you connect it, and only what that integration needs. One click in your workspace settings disconnects any of them. Two optional helpers sit in the United States: Loom, if you want video links in customer emails watched, and Firecrawl, if you want us to read your public website at sign-up. We never touch anything behind a login.