Skip to main content

Privacy notice

Privacy, without the fog.

ReplyTidy stores enough data to moderate replies and explain its decisions, then removes sensitive content from old resolved history by default.

privacy / current

What is stored

The installation stores account and session data, Threads account credentials, reply text and identifiers, usernames, moderation evidence, review actions, settings, rule history, and Stripe customer and subscription identifiers, plan, status, and billing-period dates when billing is enabled. This data is stored in PostgreSQL.

What leaves the installation

Meta acts as the connected-account and Threads API processor for authorization, new-reply delivery, and hide or unhide actions. OpenAI acts as the moderation processor for eligible reply text and AI-rule evaluation. When you use a paid plan, Stripe processes hosted checkout, payment details, recurring charges, invoices, and billing-account management; ReplyTidy does not receive your full card number. Each provider processes data under its own terms and retention controls. The web interface currently loads its typefaces from Google Fonts.

Control and retention

By default, resolved reply text, usernames, detailed moderation evidence, AI reasoning, and matched keywords are removed after 90 days. After 365 days, already-redacted allowed and skipped detail is reduced to compact identifiers, decisions, review metadata, timestamps, and analytics facts. Hidden and otherwise actionable rows remain available for unhide or review. Account deletion removes active application records as described on the Data deletion page, but Stripe and the operator may retain invoices and limited transaction records for tax, accounting, fraud prevention, dispute, and legal obligations. Encrypted database backups age out under the operator’s backup-retention schedule and are not selectively rewritten. Data retained by OpenAI, Meta, or Stripe follows their separate policies.

Operator and effective date

This notice is effective July 17, 2026. The data controller and installation operator is Brian Sunter, reachable at [email protected]. Material changes to collected data, processors, or retention will be reflected here before deployment.