ReplyAI Privacy Policy
A Kognora product · Last updated 19 July 2026
ReplyAI is an AI reply-assistant that helps professional practices (such as Chartered Accountants) manage their client conversations on WhatsApp. This policy explains what we collect, why, and your choices. It covers our use of the WhatsApp Business Platform (Cloud API) provided by Meta.
Who our users are
Our customer is the professional/practice (“the Business”) who signs up to use ReplyAI. We process the Business’s WhatsApp conversations with their clients on the Business’s behalf and under their instruction.
What we collect
- WhatsApp messages to and from the Business’s number: live inbound messages, messages the Business sends from the WhatsApp Business App (mirrored via Coexistence “echo” events), and—only if the Business explicitly opts in during onboarding—up to the last 6 months of chat history synced by Meta.
- Contact details of the Business’s clients that appear in those chats (name, WhatsApp number) and contacts the Business chooses to sync.
- Message content and attachments (text, and metadata for media).
- AI-derived data: a per-client “memory profile” (a structured summary of the relationship) and draft reply suggestions, generated to assist the Business.
- Account data: the Business’s name, login, and configuration.
We do not collect messages from group chats, and we do not access anyone’s personal WhatsApp chats other than the Business’s own client threads.
Why we use it
Solely to provide the service to the Business: reconstruct the conversation timeline, build the memory profile, and generate draft replies that the Business reviews and approves before anything is sent. ReplyAI never sends a message without explicit human approval, and never invents figures, dates, or deadlines—unverified values are flagged for the human.
AI processing and sub-processors
To generate summaries and drafts we send the relevant conversation context to large-language-model providers acting as our sub-processors: Anthropic and Google (Gemini). They process the data to return a result and do not use it to train their models under our API terms. We host application data on Google Cloud. We do not sell personal data and do not use it for advertising.
Retention
We retain conversation and profile data while the Business’s account is active, so the assistant stays useful. The Business can delete individual clients, threads, or the entire account at any time.
Data deletion
- Self-service: a Business can delete any client, conversation, or its whole account from the ReplyAI dashboard; deletion removes the associated messages and AI profiles from our systems.
- On request: email privacy@kognora.com with the account and data to delete. We action verified requests within 30 days and confirm by email.
- Offboarding a WhatsApp number from Coexistence stops all further syncing; we delete the synced history for that number on request.
This section also serves as our data deletion instructions.
Your rights
Clients of a Business may contact that Business (the data controller) to access or delete their data; we assist the Business in fulfilling such requests. You can also contact us directly at privacy@kognora.com.
Security
Access tokens and secrets are stored server-side and never exposed to clients. Transport is encrypted (HTTPS/TLS). Access to production data is restricted.
Changes
We’ll update this page and revise the “Last updated” date for material changes.