Home/Privacy Policy

Privacy Policy

Effective date: August 3, 2026

This Privacy Policy explains how Vrizen ("we", "us") collects, uses, and shares information when you use Reply (the "Service"). It is intended to help you meet expectations under laws such as India's DPDP Act and, where applicable, GDPR-style obligations for your own end users.

1. Who this covers

  • Account holders — people who sign up, invite teammates, or administer chatbots
  • End users — visitors who chat with a customer's widget or connected channel (processed on behalf of that customer)

2. Data we collect

  • Account data: name, email, phone, company details, billing identifiers, authentication tokens
  • Customer Content: uploaded documents, crawled pages, FAQs, forms, branding assets, and configuration
  • Conversation data: messages, session metadata, channel identifiers, and related usage events
  • Technical data: IP address, user agent, logs, and diagnostics needed to operate and secure the Service

3. How we use data

  • Provide, secure, and support the Service
  • Index and retrieve Customer Content for chatbot answers (RAG)
  • Bill subscriptions and prevent abuse (rate limits, quotas)
  • Send transactional email (verification, password reset, billing notices)
  • Improve reliability and quality (aggregated metrics, error tracking)

4. AI providers and subprocessors

To generate embeddings and answers we send prompts and retrieved context to third-party model providers (for example Groq and Together AI). Vector indexes may be stored with Pinecone. Files may be stored on Cloudflare R2. Databases and caches run on infrastructure we operate or host. These parties process data under contract to provide the Service.

5. Where data is stored

Primary application data is stored in PostgreSQL and Redis we operate. Document blobs are stored in Cloudflare R2. Vector embeddings are stored in Pinecone (region configured for the deployment, commonly a US cloud region unless we notify otherwise). Model providers process requests in the regions they operate.

6. Retention

We retain account and Customer Content while your account is active. Chat messages are moved from active storage to an archive after a configured period, and aged archives, operational activity logs, and metering events are deleted on a schedule we configure for the deployment (defaults are on the order of months to years). After account deletion we delete or anonymize Customer Content and owned chatbot data from our primary stores (including vectors and object storage) within a commercially reasonable period, except where we must retain records for legal, tax, or security reasons (for example billing history or abuse logs).

7. Your rights and choices

  • Access or export your account data from the product (account export)
  • Correct profile information in settings
  • Delete your account (subject to transferring shared chatbots you own)
  • Contact us to exercise other rights available under applicable law

If you are an end user of a customer's chatbot, contact that customer first; they are the controller of that conversation data.

8. Security

We use encryption in transit, access controls, tenant isolation controls, and operational monitoring. No method of transmission or storage is fully secure; please protect your API keys and invite only trusted teammates.

9. Children

The Service is not directed to children under 16. We do not knowingly collect personal data from children.

10. Changes and contact

We may update this Policy; the effective date above will change when we do. Contact: support@vrizen.com.