Skip to content

Trust & security

Controls you can verify, not just claims

ReplyTune publishes to your Google profile on your behalf, so how it handles access, your content and your data matters. Here is exactly what is in place today, with the source document for each control.

Security controls at a glance

Each control names its current status and the document you can read to verify it.

ReplyTune security controls, their status and evidence
ControlStatusEvidence
Google authorizationEnforcedRead and publish only through the official Google Business Profile API over OAuth 2.0. We never see your Google password, and you can revoke access from your Google account at any time.View document
Configurable approval rulesUnder your controlYou choose what publishes automatically, per location: Full Auto across every rating, an approval exception that holds replies the AI flags as negative, or approval for every reply.
AI processingNo model trainingSentiment analysis and reply drafting run through the OpenAI business API. Submitted review and brand content is not used to train models.View document
EncryptionIn placeData is encrypted in transit with TLS and encrypted at rest by the managed hosting and database infrastructure.
Data residency & transfersRegional (US / EEA)Primary hosting region is set at deployment. Cross-border transfers are covered by Standard Contractual Clauses and the UK Addendum.View document
Retention & deletion30-day windowDelete your workspace at any time. Personal data is purged within 30 days of cancellation; replies already published to Google remain yours.View document
Sub-processorsDocumentedA full inventory of every third party that processes personal data, with at least 30 days' notice before any change.View document
Breach notification72 hoursIn the event of a confirmed personal-data breach, affected customers are notified without undue delay and within 72 hours.View document
Access & audit trailLoggedEvery reply is timestamped and logged with its status. Workspace data is scoped to the owning account.
Responsible disclosureOpenGood-faith security research is welcomed. Report suspected issues and we will investigate and respond.

Controls reflect the platform as of July 10, 2026.

How Google access works

ReplyTune connects to your Google Business Profile through Google's official API using OAuth 2.0. You grant a specific, revocable scope: reading your reviews and locations, and publishing replies you or the system approve. We never receive or store your Google password.

You can review and revoke ReplyTune's access from your Google account's security settings at any time. Revoking access stops new reads and publishes immediately.

How AI processes your content

To analyze sentiment and draft replies, review text and the brand context you provide are sent to the OpenAI business API. Under that agreement, your content is not used to train models. It is processed only to produce the output for your workspace.

The full list of parties that process personal data on our behalf is maintained on the sub-processors page.

Human approval and publishing

You choose the publishing mode per location: Full Auto, where replies publish to Google automatically, or Approval Mode, where every reply waits for you. In Full Auto you can also enable an optional approval exception that holds replies the AI flags as negative for a human check before publishing.

Every reply, automatic or approved, is timestamped and logged with its status so you always have a record of what was published and when.

Data, privacy and retention

Data is encrypted in transit and at rest. Your primary hosting region is configurable, and cross-border transfers are protected by Standard Contractual Clauses and the UK International Data Transfer Addendum.

You can delete your workspace at any time. Personal data is purged within 30 days of cancellation. Our full handling of personal data is described in the Privacy Policy and the Data Processing Agreement.

Availability and reliability

ReplyTune runs on managed cloud infrastructure with redundant, backed-up storage. If a reply fails to publish to Google, it is marked failed rather than lost, so nothing disappears silently and you can retry.

Responsible disclosure

We welcome good-faith security research. If you believe you have found a vulnerability, email security@primanza.com with enough detail to reproduce it. Please give us reasonable time to investigate and remediate before any public disclosure.