AI.Reply is built on a foundation of strict data minimization and user privacy. This document explains exactly what data is accessed, how it flows, and what is never stored — in plain language.
AI.Reply only accesses email text on the active browser tab when the user explicitly interacts with the generation toolbar buttons. The extension is entirely dormant and performs zero background scanning, indexing, or passive data collection at any other time. Nothing is read unless you click a button.
When you click a generation button, AI.Reply reads the text content of the currently open Gmail email thread — specifically the latest incoming message and prior thread context visible in your browser tab. It also reads your Gmail display name solely to personalize the reply signature (e.g., "Best regards, AI.Reply"). No other browser data, cookies, history, or account credentials are ever accessed.
All processed data is transmitted securely via encrypted HTTPS/TLS 1.2+ protocols to our privacy-compliant proxy endpoint hosted on Vercel. The proxy appends the LLM API key server-side (stored as an environment variable, never in the extension) and forwards only the prompt payload to OpenAI. No data travels over unencrypted channels at any stage.
AI.Reply's email-generation pipeline is fully stateless. Email content, thread history, sender names, your display name, and any generated reply text are processed entirely in real-time and permanently discarded the moment a response is returned. This email data is never logged, cached, stored in a database, or retained on any server. Each generation request is independent and leaves no trace. (Settings you choose — such as your sign-off signature and your usage counter — are saved only in your own browser's local storage and never leave your device, except as described in the Subscriptions section below.)
Email text context is passed exclusively to OpenAI's API for real-time inference to generate your reply. This is strictly governed by OpenAI's Privacy Policy. For subscription payments, we use Razorpay as our payment processor; any payment information you enter is handled directly by Razorpay under Razorpay's Privacy Policy, and AI.Reply never sees or stores your card, bank, or UPI credentials. AI.Reply does not share user data with advertisers, analytics platforms, data brokers, or any other third parties. Email content is never used to train AI models.
activeTab — Allows reading the text content of the currently active Gmail tab when you click a button. Cannot access any other tabs, windows, or browser history.
host_permissions: mail.google.com — Required to inject the AI.Reply toolbar UI into the Gmail interface. No other websites are accessed or modified.
host_permissions: aireply-backend.vercel.app — Required for the background service worker to securely transmit prompts to our proxy endpoint. No other external URLs are contacted.
AI.Reply includes a 30-day free trial (50 AI replies per day). After the trial, continued use requires an AI.Reply Pro subscription (500 replies per day), available for ₹199/month or ₹1,499/year.
How payment works: Subscriptions are processed by Razorpay, our payment provider, which supports UPI, cards and other methods. You enter your payment details directly on Razorpay's secure page — AI.Reply never sees or stores your card, bank, or UPI credentials. As part of checkout you provide your email address; Razorpay shares the successful payment confirmation and that email with our server so we can activate your subscription.
Automatic activation: To unlock Pro automatically, the extension reads the Gmail address you are signed in to and checks it against the email used for payment. We store only your email, plan type, and subscription expiry date on our server (via our hosted database) for the purpose of providing and renewing your subscription. We do not sell this information or use it for advertising. You may request deletion of your subscription record at any time by contacting support.
To keep the service running well and within fair-use limits, AI.Reply sends a small, anonymous signal when you generate a reply: a randomly generated device identifier (created on install) and a count of replies generated. This contains no email content. Separately, to check and activate your Pro subscription, the extension sends your Gmail address to our server to match it against your payment (see Subscriptions above). If you choose to use the in-extension "Report a problem" button, the message you type is sent to us along with the anonymous identifier and your browser type so we can diagnose the issue. We use all of this only to operate, support, and improve AI.Reply — never for advertising, and never sold to third parties.
AI.Reply does not require account creation, email registration, or sign-in to use. There is no user accounts database. Aside from the optional, user-initiated payment verification described above, the extension works entirely within your local browser session.
AI.Reply is not directed at children under the age of 13. We do not knowingly process data from children. If you believe a child has used this extension, please contact us immediately.
We may update this Privacy Policy periodically. The "Effective" date at the top reflects the most recent version. Continued use of AI.Reply after changes are published constitutes acceptance of the updated terms.
For privacy questions, data deletion requests, or concerns, contact us at: support.ai.reply@gmail.com