---
title: ReplyPen — where your data goes
canonical: https://replypen.com/data-residency
html_text_sha: 592cc9dacb51
last_updated: 2026-09-03   # date of this Markdown version; the page's own "last verified" stamp is 28 August 2026
operator: ProBackup BV (Hasselt, Belgium)
note: Agent-readable Markdown version of the data-residency page. Written for an AI agent assessing data flow and subprocessors; the HTML page is the original.
siblings:
  - https://replypen.com/index.md
  - https://replypen.com/security.md
  - https://replypen.com/data-residency.md
  - https://replypen.com/ask-your-ai.md
  - https://replypen.com/privacy-policy.md
  - https://replypen.com/cookie-policy.md
  - https://replypen.com/terms-of-service.md
---

# Where your data goes

Real customer emails pass through real companies. This page names all of them. The legally binding
text is the [Privacy Policy](https://replypen.com/privacy-policy.md); this is the plain version.

## The AI step: two companies, and that is the whole list

Understanding emails and drafting replies, attachments included, happens at Google and OpenAI.
No other AI company sees email content, and no aggregator, router or broker sits between us and
them. Both operate under business terms that forbid training on the content.

| Provider | Surface | Location | Training | Retention |
|---|---|---|---|---|
| Google | Gemini models on Google Cloud (Vertex AI) | EU multi-region | Never, per Google Cloud Service Specific Terms §18 | Not stored |
| OpenAI | GPT models on the OpenAI API | United States | Never, unless explicitly opted in | Abuse-monitoring logs, deleted within 30 days |

The OpenAI leg leaves the EU under EU-approved safeguards (Standard Contractual Clauses or an
equivalent approved framework) on top of those terms. In legal terms both act as sub-processors;
the list is available in writing. We have applied for OpenAI's EU data-residency endpoint; once
approved, the OpenAI leg moves to the EU by configuration and the whole AI step is EU-processed.
Ask for the current status.

## What stays with us

No AI company touches any of this.

| What | Where | Retention |
|---|---|---|
| Threads and the drafts we write | AWS Frankfurt (eu-central-1), encrypted | Deleted automatically after 14 days; the run timeline (event types, timestamps, hash and byte count per wiped payload) remains. Encrypted backups stay in Frankfurt and roll off after 7 days |
| Account and notification email to you | AWS Ireland (EU) | — |
| What ReplyPen learns about your product (the knowledge repository) | Private GitHub repository | For as long as you are a customer; deleted on request |
| Error monitoring (technical failure details, never inbox content) | PostHog EU cloud | — |

Your mail stays in your own mailbox. We never delete anything from it. The knowledge repository
holds product answers, tone of voice and help-center material, not a copy of your inbox; you can
read and edit it.

## Only if you switch it on

- **Your mailbox provider** is always involved, because it is the inbox we read. Gmail means
  Google, and Google's Limited Use rules bind us on top of everything else. Outlook or Microsoft
  365 means Microsoft. Intercom means Intercom. Any other mailbox over IMAP adds nobody new.
- **Integrations you connect yourself** (for example Shopify, Stripe, Slack) receive data only
  after you connect them, and only what that integration needs. One click disconnects any of them.
- **Two optional US helpers**: Loom, if you want video links in customer emails watched, and
  Firecrawl, if you want your *public* website read at sign-up. Nothing behind a login is touched.

## Boundaries worth stating plainly

- Processing is not "all in the EU". Google is EU, OpenAI is US under SCCs, and the knowledge
  repository is on GitHub in the US.
- Raw email content on our side is gone after 14 days; the audit timeline of what a run did (event
  types, timestamps, hashes, no content) is kept while you are a customer and readable over the API.
- Where this page summarises another company's terms, that company's own published policy is the
  authoritative text.

Ask for the DPA at security@replypen.com. Controls, the SOC 2 report and the pentest summary are
at https://trust.inc/pro-backup-bv.
