Last updated: 6 September 2026
Effective date: 6 September 2026
This Privacy Policy explains how AppReply collects, uses, discloses and otherwise Processes Personal Data in connection with the AppReply website, Service, accounts, billing, sales, marketing, support, security, analytics and related business operations.
AppReply is provided by Rasliak Labs, a sole proprietorship registered in Norway under organisation number 935 367 352, with VAT number NO 935 367 352 MVA and registered address at Bøkkerveien 16A, 0579 Oslo, Norway (the “Provider”).
For Processing carried out for the Provider's own purposes as described in this Privacy Policy, the Provider acts as an independent Controller.
Where the Provider Processes Customer Personal Data on behalf of a Customer in connection with the Service, the Provider acts as Processor, or as a sub-processor where the Customer itself acts as a processor, as applicable. Such Processing is governed by the AppReply Data Processing Agreement (“DPA”), available at appreply.co/dpa.
This Privacy Policy applies to Personal Data collected when you use the AppReply website or Service, create or administer an account, communicate with us, request support, interact with our sales or marketing activities, or otherwise engage with AppReply.
Questions about this Privacy Policy or our Processing of Personal Data may be sent to help@appreply.co.
The Personal Data we collect depends on how you interact with AppReply and which features of the Service you use.
When you create or administer an AppReply account, contact us, request information, or interact with us in a business capacity, we may collect:
When you contact us by email, chat, contact form or through the Service, we may collect information such as:
We use third-party communication and support providers, including Crisp, to help us manage customer and website communications.
If you purchase the Service, we may Process billing and transaction information such as:
For purchases processed through a third-party Merchant of Record, currently including Lemon Squeezy, payment-card and other payment-instrument information is generally collected and processed directly by the applicable payment provider and is not stored by the Provider.
For customers invoiced directly by the Provider, billing and accounting information may also be Processed through our accounting provider, currently Fiken.
When you visit the AppReply website or use the Service, we and our service providers may automatically collect technical and usage information, including:
We do not intentionally collect precise device location through the AppReply website or Service unless a particular feature clearly requires and requests such information.
We use PostHog Cloud EU for product analytics and session replay to understand how the AppReply website and Service are used, identify usability and technical issues, evaluate features and improve the Service.
Session replay may record interactions such as navigation, clicks, scrolling and interface activity.
Session replay is not intended to collect passwords, payment-card information or other highly sensitive information.
Within the Service, an administrator of a Customer organisation may disable product analytics and session replay for that organisation through the organisation's settings. The privacy choices currently available are described in Section 12.
We use Umami for website analytics. Our Umami configuration does not use cookies and receives anonymised identifiers rather than directly identifying account information.
We use this information to understand website traffic and general usage patterns.
If you subscribe to marketing communications, request information from us, or otherwise interact with our marketing activities, we may Process:
We use Resend to deliver emails and Loops to manage contacts, communication preferences and event-based communications.
You may unsubscribe from marketing communications at any time using the unsubscribe mechanism provided in the communication or by contacting us.
The Service may Process Platform Data containing Personal Data, including app-store reviews and reviewer information, as well as Customer Content, prompts, instructions, knowledge-base materials, generated content, integration information and other Personal Data in connection with functionality used by a Customer.
Where the Provider Processes such Personal Data on behalf of a Customer, the Provider acts as Processor, or as a sub-processor as applicable. Such Processing is governed by the DPA and the Customer's documented instructions.
This Privacy Policy does not change the allocation of Controller and Processor responsibilities established by the DPA.
We Process Personal Data only where we have an appropriate legal basis under applicable data-protection law.
We Process Personal Data to create and manage accounts, authenticate users, provide Service functionality, administer Customer relationships and communicate important Service information.
Legal basis: performance of a contract where applicable and our legitimate interests in providing and operating the Service.
We Process Personal Data to administer subscriptions and payments, issue invoices, process refunds or credits, maintain accounting and tax records and manage related financial obligations.
Legal basis: performance of a contract where applicable, compliance with legal obligations and our legitimate interests in administering our business.
We Process Personal Data to respond to enquiries and support requests, troubleshoot issues, provide requested information and maintain relevant communications.
Legal basis: performance of a contract where applicable and our legitimate interests in supporting Customers, users and prospective customers.
We Process Personal Data where reasonably necessary to protect accounts and systems, detect and investigate fraud, abuse or security incidents, enforce our agreements, comply with legal requirements and establish, exercise or defend legal claims.
Legal basis: our legitimate interests in protecting AppReply and our business, compliance with legal obligations and, where necessary, the establishment, exercise or defence of legal claims.
We Process technical, usage and interaction information to understand how AppReply is used, measure performance, identify technical or usability issues, evaluate features and improve the Service.
This may include product analytics and session replay as described in Section 2.
Legal basis: our legitimate interests in analysing and improving the Service, or consent where required by applicable law.
We may Process business contact details and related information to send newsletters, product updates, offers and other marketing communications, respond to requests for information and manage marketing preferences.
We rely on consent where required by law and, where permitted, on our legitimate interests in promoting AppReply to existing or prospective business customers.
You may opt out of marketing communications at any time. Opting out does not affect transactional, billing, security, account or other non-marketing communications.
We may Process Personal Data where reasonably necessary for legal compliance, regulatory requirements, record keeping, business administration, or in connection with a proposed or completed incorporation, reorganisation, financing, merger, acquisition, sale or transfer of the AppReply business.
Legal basis: compliance with legal obligations and our legitimate interests in operating, protecting and reorganising our business.
We do not sell Personal Data.
We may disclose Personal Data where reasonably necessary for the purposes described in this Privacy Policy, including to:
Third-party providers that help us operate AppReply and our business, including hosting, infrastructure, authentication, communications, email delivery, billing, accounting, analytics, diagnostics, onboarding and integration providers.
Relevant providers are described in Section 5.
If you use AppReply on behalf of a company or other organisation, information associated with your account and use of the Service may be accessible to authorised administrators of that Customer's workspace.
Billing and transaction information may be disclosed to our Merchant of Record, payment providers, banks and accounting providers as necessary to administer subscriptions, payments, invoices, refunds and related financial obligations.
Payment-card information submitted through a Merchant of Record or payment provider is generally collected directly by that provider rather than by the Provider.
We may disclose Personal Data to professional advisers, courts, regulators, law-enforcement authorities or other competent parties where reasonably necessary to obtain advice, comply with legal requirements, protect our rights or investigate fraud, abuse or security incidents.
Personal Data may be disclosed or transferred in connection with a proposed or completed incorporation, reorganisation, financing, merger, acquisition, sale of assets or transfer of all or part of the AppReply business.
Where the Provider acts as Processor or sub-processor on behalf of a Customer, disclosures of Customer Personal Data to Subprocessors are governed by the DPA.
We use third-party service providers to operate AppReply and our business. The providers we use may change from time to time as our Service and business develop.
Depending on the relevant Processing activity, a service provider may Process Personal Data in more than one capacity. For example, a provider used for our own operational analytics or diagnostics may also act as a Subprocessor where it Processes Customer Personal Data on behalf of a Customer.
We currently use the following providers in connection with Processing for which the Provider acts as an independent Controller:
Crisp
Used for customer support, website chat and in-app communications. Crisp may Process contact information, account information, message content and related support or communication data.
Resend
Used to send transactional, service and marketing emails. Resend may Process names, email addresses, message delivery information and related email metadata.
Loops
Used to manage contacts, communication preferences and event-based lifecycle and marketing communications. Loops may Process names, email addresses, account identifiers, onboarding and usage events and related communication information.
PostHog Cloud EU
Used for product analytics, usage analytics and session replay to understand how the AppReply website and Service are used, identify technical or usability issues and improve the Service.
Umami
Used for website analytics. The Provider's current Umami configuration does not use cookies and uses anonymised identifiers. We use it to understand general website traffic and usage patterns.
Sentry
Used for application monitoring, error diagnostics, performance monitoring, troubleshooting and security-related technical analysis. The Provider uses Sentry's EU data region.
Frigade
Used for in-product onboarding, checklists and guidance within the Service. Frigade may Process account identifiers and onboarding or feature-usage events.
Mintlify
Used to host and operate the AppReply documentation website at docs.appreply.co. Mintlify may Process technical and usage information relating to visits to the documentation, including IP address, user-agent information, requested pages and related request or analytics data.
Lemon Squeezy
Currently used as a Merchant of Record for certain self-service purchases. Lemon Squeezy may independently Process billing, transaction, payment, tax, refund and related customer information in accordance with its own privacy practices. The Lemon Squeezy affiliate script may store an identifier in your browser to attribute referred purchases.
Fiken
Used for accounting, bookkeeping and direct customer invoicing. Fiken may Process business contact, invoice, payment, transaction and accounting information.
We also use technical providers to host, operate and provide the AppReply Service, including:
Where these providers Process Customer Personal Data on behalf of the Provider in its capacity as Processor or sub-processor, their Processing is governed by the DPA and applicable Subprocessor arrangements.
The Provider's current Subprocessors, including information about their purposes, Processing locations and applicable transfer safeguards, are listed in Annex 3 of the AppReply Data Processing Agreement.
Some third parties, including Merchant of Record, payment, accounting or other independent service providers, may act as separate Controllers for certain Processing they perform for their own legal, regulatory or operational purposes.
Where a third party acts as an independent Controller, its Processing is governed by its own privacy policy and applicable data-protection law.
The Provider does not control the independent Processing activities of third parties acting as separate Controllers.
The Service uses third-party artificial-intelligence providers, including OpenAI, Anthropic and OpenRouter, to provide AI-assisted functionality. OpenRouter is a routing provider: it forwards requests to the third-party model provider serving the selected model, which it engages as its own subprocessor.
Where a Customer's plan or trial includes analytics functionality, baseline analysis of app-store and other Platform Data ingested for that Customer, including classification, categorisation, embedding, sentiment-scoring and summarisation, occurs as an inherent part of the Service and does not require the Customer to enable a separate feature. Generation of suggested replies, and generation and publication of automated replies, depend on the functionality the Customer has enabled and the Customer's configuration.
Where Personal Data is Processed through these features on behalf of a Customer, the Provider acts as Processor, or as a sub-processor as applicable. Such Processing is governed by the DPA and the Customer's documented instructions.
The Provider does not use Customer Data, Customer Content or app-store review data Processed on behalf of Customers to train general-purpose artificial-intelligence models.
The Provider may generate anonymous or statistical information from data Processed through the Service where permitted under the DPA and the Customer's documented instructions. Once information has been rendered anonymous so that it no longer relates to an identified or identifiable individual under applicable data-protection law, the Provider may use that information for analytics, benchmarking, evaluation, research, product development and improvement of the Service.
Customer Personal Data may be transmitted to authorised AI Subprocessors only to the extent necessary for the relevant Service functionality. Current AI Subprocessors and information about relevant Processing locations and transfer safeguards are listed in Annex 3 of the DPA.
Additional terms governing AI Output, AI transparency and automated publication are set out in the AppReply Terms of Service.
AppReply supports email-based authentication, including email and password or magic-link authentication, and may support sign-in through third-party identity providers.
Authentication functionality is provided through Supabase.
When you authenticate, we may Process information such as your email address, name, provider-specific account identifier, authentication events, account status and technical information necessary to create, secure and access your account.
Where you use a third-party identity provider, the Provider receives information made available by that provider according to the authentication method and permissions used. The Provider does not receive your password for the third-party identity-provider account.
Third-party identity providers may independently Process information relating to their authentication services in accordance with their own privacy notices.
Legal basis: performance of a contract where applicable and our legitimate interests in providing secure account authentication.
The Provider is based in Norway and uses service providers located in the European Economic Area (“EEA”) and other jurisdictions, including the United States.
Where possible, we use European data regions for our primary application infrastructure and certain service providers.
Where Personal Data is transferred outside the EEA to a country that does not benefit from an applicable adequacy decision, we use appropriate safeguards where required by applicable data-protection law, such as Standard Contractual Clauses or another recognised lawful transfer mechanism.
We may also implement supplementary technical, contractual or organisational measures where appropriate.
Where the Provider acts as Processor or sub-processor on behalf of a Customer, international transfers of Customer Personal Data are governed by the DPA.
Information about the Processing locations and transfer safeguards applicable to current Subprocessors is provided in Annex 3 of the DPA.
We retain Personal Data only for as long as reasonably necessary for the purposes described in this Privacy Policy, including to provide and operate the Service, comply with legal obligations, maintain appropriate business records, resolve disputes, prevent fraud, protect security, enforce agreements and establish, exercise or defend legal claims.
Retention periods vary depending on the type of Personal Data, the purpose of the Processing and applicable legal requirements.
Personal Data Processed by the Provider as Controller is retained only for as long as reasonably necessary for the relevant purposes and may be deleted following account closure where it is no longer required.
Certain information may be retained where necessary for billing, accounting, tax, legal compliance, fraud prevention, security, dispute resolution or the establishment, exercise or defence of legal claims.
Where the Provider Processes Customer Personal Data as Processor or sub-processor, return, retrieval and deletion are governed by Section 12 of the DPA.
Data deleted from active application systems may remain temporarily in backups used for operational recovery and resilience.
The Provider's current backup lifecycle is generally up to seven (7) days. Backup data is deleted or overwritten through the normal backup rotation process and is not used for ordinary business purposes.
Support requests, chat messages and related communications may be retained for as long as reasonably necessary to provide support, maintain appropriate business records and resolve disputes.
Where communications are stored by providers such as Crisp, retention may also depend on the applicable provider plan, configuration and retention practices.
Analytics, session replay, error-monitoring and diagnostic information may be retained according to our configuration and the retention periods of the applicable providers, including PostHog and Sentry.
We may delete, aggregate or anonymise such information earlier where appropriate.
Billing, invoice, transaction, tax and accounting information may be retained for the periods required by applicable accounting, tax and other legal requirements.
Marketing contact information may be retained while you remain subscribed or where we otherwise have a lawful basis to retain it.
If you unsubscribe, we may retain limited information, such as your email address and opt-out status, where reasonably necessary to respect and demonstrate your marketing preference and prevent further unwanted marketing communications.
We implement and maintain technical and organisational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Personal Data.
Depending on the relevant system and Processing activity, these measures may include:
We review and may update our security measures as the Service, infrastructure, risks and applicable legal requirements evolve.
No method of electronic transmission, storage or Processing is completely secure. Accordingly, while we take measures designed to protect Personal Data, we cannot guarantee that a security incident, unauthorised access or Personal Data Breach will never occur.
Additional information about the technical and organisational measures applicable to Customer Personal Data is provided in Annex 2 of the DPA.
Depending on your location and applicable data-protection law, you may have certain rights in relation to your Personal Data.
These rights may include the right to:
These rights are not absolute and may be subject to conditions, limitations or exceptions under applicable data-protection law.
To exercise a privacy right, contact us at help@appreply.co.
We may request information reasonably necessary to verify your identity and determine the scope of your request before responding.
We will respond within the period required by applicable data-protection law.
In certain circumstances, we may refuse or limit a request where permitted by law, including where we cannot reasonably verify the requester, the request adversely affects the rights and freedoms of others, or retention of the relevant information is required or otherwise permitted by law.
If your request concerns Personal Data that the Provider Processes on behalf of one of our Customers, that Customer generally acts as the Controller responsible for responding to your request.
In such cases, we may direct you to the relevant Customer or forward your request to that Customer and provide reasonable assistance as required under the DPA and applicable data-protection law.
If you have concerns about our Processing of your Personal Data, you may contact us first at help@appreply.co.
You also have the right, where applicable, to lodge a complaint with the competent Supervisory Authority.
For Processing for which the Provider is established in Norway, the relevant authority is generally Datatilsynet, the Norwegian Data Protection Authority, at datatilsynet.no.
The AppReply website uses Umami, which does not use cookies and receives anonymised identifiers, and PostHog for product analytics and session replay, as described in Section 2.
Within the Service, an administrator of a Customer organisation may disable product analytics and session replay, the Crisp support chat and the Lemon Squeezy affiliate script for that organisation through the organisation's settings.
You may opt out of marketing communications at any time using the unsubscribe mechanism in the communication or by contacting help@appreply.co.
Technologies that are reasonably necessary for security, authentication, fraud prevention, core Service functionality or similar essential purposes operate independently of these choices where permitted by applicable law.
We may update this Privacy Policy from time to time to reflect changes in our Service, Processing activities, service providers, legal requirements or business operations.
When we update this Privacy Policy, we will revise the “Last updated” date at the top of the Policy.
Where required by applicable data-protection law, or where we make a material change that significantly affects how we Process Personal Data, we may provide additional notice through the Service, by email or by another appropriate method.
We encourage you to review this Privacy Policy periodically for current information about our privacy practices.
The Controller responsible for the Controller-side Processing described in this Privacy Policy is:
Rasliak Labs
Organisation number: 935 367 352
VAT number: NO 935 367 352 MVA
Bøkkerveien 16A
0579 Oslo
Norway
AppReply is a product and trading name operated by Rasliak Labs.
For questions, privacy requests or concerns relating to this Privacy Policy or our Processing of Personal Data, contact help@appreply.co.