OpenRouter Routing layer — passes the request along
🇺🇸 United States- Trains on your data: Never
- Keeps your data: Not stored
“OpenRouter does not store your prompts or responses, unless you opt in…” — an opt-in we never switch on.
ReplyPen reads your support inbox and writes draft replies, so real customer emails pass through real companies. Here is who they are, where their servers sit, and what they are allowed to do.
Every AI company we work with is contractually barred from training their models on your emails. No exception, no setting to remember.
Most store nothing at all. A few hold your text briefly to catch abuse of their own service, then delete it automatically — at most 30 days.
Everything ReplyPen stores lives in Frankfurt, Germany. The AI step itself may run on US or EU servers, under EU-approved safeguards.
It arrives in your mailboxand stays there — we read a copy, we never move your mail.
Processed in Frankfurton our own EU servers, encrypted while stored and while travelling.
A draft is writtenwith help from the vetted AI companies listed below.
It waits for youas a draft in your inbox — nothing is sent until you say so.
After 14 days it is purgedfrom our systems. What stays is what we learned.
The same for every customer, whatever you switch on.
Our home base. Every thread, draft and setting we store sits on encrypted servers in Frankfurt. Account and notification emails to you go out through AWS in Ireland — also the EU.
Threads and the drafts we write are automatically wiped from ReplyPen after 14 days. Your mail itself never leaves your own mailbox, and we never delete anything from it.
Your product answers, tone of voice and help-centre material live in a private repository for as long as you are a customer. That is knowledge, not a copy of your inbox — ask for it, or ask us to delete it, any time.
Error monitoring, so we hear about breakage before you do. It receives technical error details — what failed and where — not your inbox.
Understanding your emails and drafting replies — screenshots and attachments included — is done with help from the companies below. We work with several so the service stays fast and reliable, and we deliberately do not tie any one of them to any one step.
Two rules apply to every single one: your data is never used to train their models, and it is either not stored at all or deleted automatically within at most 30 days.
“OpenRouter does not store your prompts or responses, unless you opt in…” — an opt-in we never switch on.
“We do not store inputs or outputs on DigitalOcean infrastructure for any models.”
“Cloudflare does not use your Customer Content to (1) train any AI models … or (2) improve any Cloudflare or third-party services.”
“Fireworks does not log or store prompt or generation data for any open models, without explicit user opt-in.”
“We will not use your Input, or your Output … to train our own models or to improve the Platform or the Service.”
“Data sent to the OpenAI API is not used to train or improve OpenAI models.”
“Your prompts (inputs) and completions (outputs) … are NOT used to train any generative AI foundation models without your permission or instruction.”
“Google will not use Customer Data to train or fine-tune any AI/ML models without Customer's prior permission or instruction.”
Held to exactly the same bar as the companies above — never trained on, bounded retention — because an outage should never mean weaker rules.
“By default, Groq does not retain customer data for inference requests.”
“For Anthropic API users, we automatically delete inputs and outputs on our backend within 30 days of receipt or generation.”
Honestly stated: everything ReplyPen stores stays in the EU (Frankfurt), but the AI step itself may run on servers in the United States or the EU. Where data leaves the EU, the transfer is covered by EU-approved safeguards — the European Commission's Standard Contractual Clauses or an equivalent approved framework — on top of the terms quoted above. Quotes are shortened from each company's own published policy; follow the links for the full text. In legal terms these companies act as our processors and sub-processors, and the written list is available on request.
None of this happens unless you switch it on. Never connect Slack, and no data ever reaches Slack.
We have to read the inbox you point us at, so your mailbox provider is naturally involved. Gmail → Google, where we are additionally bound by Google's Limited Use rules. Outlook / Microsoft 365 → Microsoft. Intercom → Intercom (US, EU or Australia, depending on your Intercom account). Any other mailbox (IMAP) → your own email provider, so nobody new is added at all.
When a customer sends a Loom recording and you have this on, we fetch the video from Loom, Inc. (United States) and use Google to transcribe it, so the reply can address what is actually in it.
Shopify, Stripe, Slack and the rest only receive data if you connect them yourself, and only what that integration needs. The current list sits in your workspace settings, where one click disconnects any of them.
To give ReplyPen a head start we can read your public website — the pages any visitor can see — through Firecrawl (United States). Never anything behind a login.
| What | Where it sits | How long |
|---|---|---|
| Email threads & the drafts we write | ReplyPen, AWS Frankfurt (EU) | Automatically deleted after 14 days |
| The emails themselves | Your own mailbox | Yours, untouched — we never delete your mail |
| Email text sent for AI processing | The AI companies listed above | Not stored, or auto-deleted within at most 30 days |
| What ReplyPen has learned | Private GitHub repository | Kept while you are a customer; deleted on request |
| Technical error reports | PostHog, EU cloud | Kept for troubleshooting; no inbox content |
Yes. We sign a data processing agreement, and it comes with the full written list of the companies named here. Email us and we will send it over — no sales call required.
This page is written for people, not lawyers, and is accurate to the best of our knowledge as of the verification date above. Where it summarises another company's terms, that company's own policy — linked on every card — is the authoritative text. For legal bases, your rights and international transfers, see our Privacy Policy and Terms of Service.