✦ Data residency

Where your data goes

ReplyPen reads your support inbox and writes draft replies, so real customer emails pass through real companies. Here is who they are, where their servers sit, and what they are allowed to do.

Last verified: August 2026

Never used to train AI

Every AI company we work with is contractually barred from training their models on your emails. No exception, no setting to remember.

Not kept on AI servers

Most store nothing at all. A few hold your text briefly to catch abuse of their own service, then delete it automatically — at most 30 days.

Home base: Frankfurt, EU

Everything ReplyPen stores lives in Frankfurt, Germany. The AI step itself may run on US or EU servers, under EU-approved safeguards.

✦ The path of one email

Five stops, nothing hidden in between

It arrives in your mailboxand stays there — we read a copy, we never move your mail.

Processed in Frankfurton our own EU servers, encrypted while stored and while travelling.

A draft is writtenwith help from the vetted AI companies listed below.

It waits for youas a draft in your inbox — nothing is sent until you say so.

After 14 days it is purgedfrom our systems. What stays is what we learned.

✦ Foundation

Where your data lives

The same for every customer, whatever you switch on.

Amazon Web Services 🇪🇺 Frankfurt, Germany

Our home base. Every thread, draft and setting we store sits on encrypted servers in Frankfurt. Account and notification emails to you go out through AWS in Ireland — also the EU.

Your emails, on our side ⏱ Deleted after 14 days

Threads and the drafts we write are automatically wiped from ReplyPen after 14 days. Your mail itself never leaves your own mailbox, and we never delete anything from it.

What ReplyPen learns — GitHub 🇺🇸 United States

Your product answers, tone of voice and help-centre material live in a private repository for as long as you are a customer. That is knowledge, not a copy of your inbox — ask for it, or ask us to delete it, any time.

PostHog 🇪🇺 EU cloud

Error monitoring, so we hear about breakage before you do. It receives technical error details — what failed and where — not your inbox.

✦ Always active

The AI companies we work with

Understanding your emails and drafting replies — screenshots and attachments included — is done with help from the companies below. We work with several so the service stays fast and reliable, and we deliberately do not tie any one of them to any one step.

Two rules apply to every single one: your data is never used to train their models, and it is either not stored at all or deleted automatically within at most 30 days.

Storage key: Not stored Auto-deleted within 30 days

Who handles your emails day to day

OpenRouter Routing layer — passes the request along

🇺🇸 United States
  • Trains on your data: Never
  • Keeps your data: Not stored
“OpenRouter does not store your prompts or responses, unless you opt in…” — an opt-in we never switch on.

Read their policy →

DigitalOcean AI processing

🇺🇸 United States
  • Trains on your data: Never
  • Keeps your data: Not stored
“We do not store inputs or outputs on DigitalOcean infrastructure for any models.”

Read their policy →

Cloudflare AI processing

🌍 Global network, incl. EU
  • Trains on your data: Never
  • Keeps your data: Not stored
“Cloudflare does not use your Customer Content to (1) train any AI models … or (2) improve any Cloudflare or third-party services.”

Read their policy →

Fireworks AI AI processing

🇺🇸 United States
  • Trains on your data: Never
  • Keeps your data: Not stored
“Fireworks does not log or store prompt or generation data for any open models, without explicit user opt-in.”

Read their policy →

Parasail AI processing

🇺🇸 United States
  • Trains on your data: Never
  • Keeps your data: Not stored
“We will not use your Input, or your Output … to train our own models or to improve the Platform or the Service.”

Read their policy →

OpenAI AI processing

🇺🇸 United States
  • Trains on your data: Never
  • Keeps your data: Abuse logs, deleted within 30 days
“Data sent to the OpenAI API is not used to train or improve OpenAI models.”

Read their policy →

Microsoft AI processing (Azure AI)

🇪🇺 EU first 🇺🇸 US fallback
  • Trains on your data: Never
  • Keeps your data: Abuse logs, deleted within 30 days
“Your prompts (inputs) and completions (outputs) … are NOT used to train any generative AI foundation models without your permission or instruction.”

Read their policy →

Google AI processing (Google Cloud)

🌍 Google Cloud regions
  • Trains on your data: Never
  • Keeps your data: Short-lived cache and abuse logging only
“Google will not use Customer Data to train or fine-tune any AI/ML models without Customer's prior permission or instruction.”

Read their policy →

Standby & occasional companies 2

Held to exactly the same bar as the companies above — never trained on, bounded retention — because an outage should never mean weaker rules.

Groq Standby — only if a usual route is unavailable

🇺🇸 United States
  • Trains on your data: Never
  • Keeps your data: Troubleshooting logs, deleted within 30 days
“By default, Groq does not retain customer data for inference requests.”

Read their policy →

Anthropic Occasional — limited internal quality checks

🇺🇸 United States
  • Trains on your data: Never
  • Keeps your data: Deleted within 30 days
“For Anthropic API users, we automatically delete inputs and outputs on our backend within 30 days of receipt or generation.”

Read their policy →

Honestly stated: everything ReplyPen stores stays in the EU (Frankfurt), but the AI step itself may run on servers in the United States or the EU. Where data leaves the EU, the transfer is covered by EU-approved safeguards — the European Commission's Standard Contractual Clauses or an equivalent approved framework — on top of the terms quoted above. Quotes are shortened from each company's own published policy; follow the links for the full text. In legal terms these companies act as our processors and sub-processors, and the written list is available on request.

✦ Your choice

Only if you use it

None of this happens unless you switch it on. Never connect Slack, and no data ever reaches Slack.

Your mailbox connection Always one of these

We have to read the inbox you point us at, so your mailbox provider is naturally involved. Gmail → Google, where we are additionally bound by Google's Limited Use rules. Outlook / Microsoft 365 → Microsoft. Intercom → Intercom (US, EU or Australia, depending on your Intercom account). Any other mailbox (IMAP) → your own email provider, so nobody new is added at all.

Video links in emails Loom

When a customer sends a Loom recording and you have this on, we fetch the video from Loom, Inc. (United States) and use Google to transcribe it, so the reply can address what is actually in it.

Integrations you connect You pick them

Shopify, Stripe, Slack and the rest only receive data if you connect them yourself, and only what that integration needs. The current list sits in your workspace settings, where one click disconnects any of them.

Website import at sign-up Firecrawl 🇺🇸

To give ReplyPen a head start we can read your public website — the pages any visitor can see — through Firecrawl (United States). Never anything behind a login.

✦ Retention

How long anything is kept

WhatWhere it sitsHow long
Email threads & the drafts we write ReplyPen, AWS Frankfurt (EU) Automatically deleted after 14 days
The emails themselves Your own mailbox Yours, untouched — we never delete your mail
Email text sent for AI processing The AI companies listed above Not stored, or auto-deleted within at most 30 days
What ReplyPen has learned Private GitHub repository Kept while you are a customer; deleted on request
Technical error reports PostHog, EU cloud Kept for troubleshooting; no inbox content

Can I get this in writing?

Yes. We sign a data processing agreement, and it comes with the full written list of the companies named here. Email us and we will send it over — no sales call required.

This page is written for people, not lawyers, and is accurate to the best of our knowledge as of the verification date above. Where it summarises another company's terms, that company's own policy — linked on every card — is the authoritative text. For legal bases, your rights and international transfers, see our Privacy Policy and Terms of Service.