Effective Date: January 1, 2025
Last Updated: July 11, 2026
Key Points Summary:
- This Privacy Policy is GDPR-compliant and applies to EU/EEA users
- Data Controller: helpful bits GmbH, Munich, Germany
- Captured messages, your stated intent, and drafted replies are processed transiently and are not persisted in the ReplyContext application database
- The ReplyContext application backend and database are hosted in Germany (EU) for all users; each reply travels through that server directly to Google’s Gemini API
- Optional server-side memory contains only numeric style signals (reply length, line breaks, and terminal punctuation) learned from replies you edited and accepted; the app lets you inspect and delete them and disable learning and retrieval
- We process personal data with your consent (Art. 6(1)(a) GDPR) and for contract performance (Art. 6(1)(b) GDPR)
- You have comprehensive GDPR rights: access, rectification, erasure, portability, restriction, objection
- EU Supervisory Authority: Bavarian State Office for Data Protection Supervision (BayLDA)
1. Introduction and Scope
helpful bits GmbH ("ReplyContext," "we," "us," or "our") is committed to protecting your privacy and ensuring transparent data processing practices in full compliance with the General Data Protection Regulation (GDPR) and German data protection laws.
This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you use the ReplyContext mobile applications, their share and text-selection extensions, the website, and related services (collectively, the "Service").
By using the Service, you acknowledge that you have read and understood this Privacy Policy.
2. Data Controller
The data controller responsible for your personal data is:
As the data controller, helpful bits GmbH determines the purposes and means of processing your personal data and is responsible for ensuring compliance with applicable data protection laws.
3. Where Your Data Is Processed
This Privacy Policy applies to people protected by EU or EEA data-protection law. ReplyContext's application backend and database are hosted in Germany, in the European Union, for all users; there is no separate U.S. application or database region. ReplyContext does not request precise device location and does not select where your account data is stored based on your location. AI model processing can involve transfers outside the EU/EEA, as described in Section 10 and on our sub-processors page.
4. GDPR Definitions
For purposes of this Privacy Policy:
- "Personal Data" means any information relating to an identified or identifiable natural person ("Data Subject"), as defined in Article 4(1) GDPR.
- "Processing" means any operation performed on personal data, including collection, recording, storage, use, disclosure, erasure, or destruction, as defined in Article 4(2) GDPR.
- "Controller" means the entity that determines the purposes and means of processing personal data (Article 4(7) GDPR) - in this case, helpful bits GmbH.
- "Processor" means an entity that processes personal data on behalf of the Controller (Article 4(8) GDPR).
- "Consent" means any freely given, specific, informed, and unambiguous indication of the Data Subject's wishes (Article 4(11) GDPR).
- "Data Subject" means an identified or identifiable natural person to whom personal data relates.
5. Categories of Personal Data We Collect
5.1 Account and Authentication Data
- Email address: For account creation, authentication, and communications
- Authentication tokens: ReplyContext access tokens and hashed refresh-token records used to keep you signed in
- Device identifier: An app-provided identifier used to bind and revoke authenticated sessions
- Authentication state: Temporary session data for OAuth flows
5.2 Usage and Service Data
- Memory records: Per-user numeric structural style signals the Service may use for future replies: a reply-length ratio, a line-break tendency, and a terminal-punctuation tendency, each derived when you accept a reply you edited. Memory records contain only these numeric values - no captured messages, reply text, or other text.
- Reply operation records: For each reply request we retain operational metadata: request identifiers, timestamps, token counts, credit charges, and a cryptographic hash (fingerprint) of the drafted reply used to verify feedback. These records do not contain the captured message, your intent, or the reply text.
- Usage statistics: Credit consumption and API call counts
- Purchase and subscription data: Subscription plan, billing status, and subscription period (payment processed by Apple); credit balance; and, if you buy a reply credit pack where one is offered in the app, store transaction data: transaction confirmation and status from Apple, and - for a Google Play purchase - the product id, purchase token, purchase state, and an obfuscated account identifier (payment processed by Google)
5.3 Content and Input Data (Processed Transiently)
- Captured messages: Text or screenshots of messages you share or paste into the Service, which typically include content written by third parties
- Your stated intent: The short instruction describing what you want your reply to say, and any revision instructions
- Drafted replies: The reply text generated for you, and - when you accept an edited reply - the final edited text used to derive numeric structural style signals
This content is transmitted through the ReplyContext server in Germany (EU) directly to Google’s Gemini API. It is not persisted in the ReplyContext application database after the request completes; only the operational metadata described in Section 5.2 is retained. An accepted edited reply is used transiently to compute numeric structural style signals and is not itself persisted as memory; accepting a reply without editing it produces no style signals.
5.4 Technical and Device Data
- Request information: IP address and security-relevant request metadata used for rate limiting, authentication auditing, and abuse prevention
- Operational logs: Server errors and request outcomes needed to run and secure the Service; OAuth codes, access tokens, refresh tokens, captured messages, and reply text are excluded from application logs
5.5 No Third-Party Product Analytics
The current ReplyContext mobile apps do not include a third-party analytics or crash-reporting SDK. Server-side reply operation records are limited to the billing, reliability, and security fields described above.
5.6 Communication Data
- Support correspondence: Email communications with customer support
- Reply feedback: Whether you accepted or dismissed a reply and, for accepted replies, cryptographic hashes used to verify the feedback without storing the text
6. Legal Basis for Processing (Article 6 GDPR)
We process your personal data only when we have a valid legal basis under Article 6(1) GDPR:
6.1 Consent (Article 6(1)(a) GDPR)
We process certain data based on your explicit consent, including:
- Numeric structural style learning when you accept a reply you edited
You may disable memory learning and retrieval together, or delete style signals individually or all at once, in the app. You may also contact us to withdraw consent. Withdrawal does not affect processing that was lawful before withdrawal.
6.2 Contract Performance (Article 6(1)(b) GDPR)
Processing is necessary to perform our contract with you (Terms of Service), including:
- Account creation and authentication
- Generating and revising replies from the content you submit, including transmission to our AI processing infrastructure
- Retaining reply operation records for idempotent billing and abuse prevention
- Processing subscription payments
- Providing customer support
6.3 Legitimate Interests (Article 6(1)(f) GDPR)
Processing is necessary for our legitimate interests, provided these interests do not override your fundamental rights:
- Security and fraud prevention: Detecting and preventing unauthorized access, abuse, or fraudulent activity
- Service reliability: Reviewing aggregate reply counts, token use, latency, and error outcomes
- Technical operations: Maintaining, troubleshooting, and optimizing the Service
You have the right to object to processing based on legitimate interests. See Section 15 for details.
6.4 Legal Obligations (Article 6(1)(c) GDPR)
Processing is necessary to comply with legal obligations, including:
- Tax and accounting requirements
- Response to lawful requests from authorities
- Data breach notification obligations
- Retention of data as required by law
7. Mobile Application Privacy
7.1 Ephemeral Captured Content
ReplyContext is designed so that message content stays transient:
- Captured messages and screenshots: The app may keep a local working copy under its storage controls; a request copy is processed transiently and is not persisted in the ReplyContext application database
- Drafted and edited replies: The app may keep them locally for your review and history controls; the server does not persist their text (a cryptographic hash is retained to verify feedback)
- Authentication tokens: Securely stored in the platform keystore (iOS Keychain or Android Keystore)
7.2 Capture Surfaces
The app receives content only when you explicitly hand it over:
- iOS: The share extension receives what you share to it and can draft the reply in place; content you paste is used only for the current reply
- Android: The system share sheet and the text-selection Process Text action pass only the items you select to the app
- Dictation: When you tap the microphone, the main app asks for microphone permission and records up to 60 seconds. It sends the recording through the ReplyContext server to Google Gemini for transcription. Temporary audio is deleted after upload, cancellation, or interruption; neither audio nor transcript is stored in the ReplyContext application database. The editable transcript stays in your local draft under its retention controls.
- No background collection: ReplyContext does not read your notifications, keyboard input, or screen content, and does not request privileged access such as notification listeners or accessibility services
7.3 Server-Side Memory
The following data is stored per user on our EU-based servers so that future replies can match your writing structure:
- Numeric structural style signals derived when you accept a reply you edited: a reply-length ratio, a line-break tendency, and a terminal-punctuation tendency
Memory is optional: the Service works without it from the first reply. The app lists the current signals, lets you delete one or all of them, and lets you disable learning and retrieval together with one setting; deleting all signals preserves that setting. There is no free-form memory-creation screen and no text memory. Style signals are isolated per user and are never shared with other users; there is no community or public content in the Service.
7.4 No Recipient Profiling
Memory is not scoped to a conversation or contact. We do not infer or store the identity of the people you are replying to, and screenshots are not used to identify recipients.
9. Third-Party AI Processing
9.1 AI Processing and Data Flow
When you request a reply, the captured message (text or screenshot), your stated intent, any revision instruction, and any retrieved style signals travel from the ReplyContext server in Germany (EU) directly to Google’s Gemini API, which is identified on our sub-processors page. Each generation or revision involves exactly one model call. This processing is based on contract performance (Article 6(1)(b) GDPR).
9.2 Third-Party Message Content
Captured messages typically contain personal data of the people who wrote them. This content is processed solely to draft your reply, is treated as data rather than instructions, and is not persisted in the ReplyContext application database after the request. Google handles the request under the terms disclosed on our sub-processors page.
9.3 No Model Choice or First-Party Model Training
The Service does not offer a choice of AI providers or models; the model used is determined server-side. ReplyContext does not use your content to develop or train its own AI models. The processors currently involved in AI processing, including their locations and applicable data-use terms, are listed on our sub-processors page. Their handling of API data is governed by our data processing agreements with them and their published terms.
10. International Data Transfers
10.1 Transfers to Third Countries
Where the AI processing infrastructure we use is located outside the EU/EEA (see the sub-processors page for current locations), your personal data is transferred to countries that may not provide an equivalent level of data protection to the EU.
10.2 Transfer Mechanisms
We ensure appropriate safeguards for international transfers as required by Chapter V GDPR:
- Standard Contractual Clauses (SCCs): We use the European Commission's Standard Contractual Clauses (Decision 2021/914) with all processors outside the EU/EEA
- Adequacy Decisions: We transfer data to countries with adequacy decisions where available
- Supplementary Measures: We implement additional technical and organizational measures (encryption, data minimization, access controls) as recommended by the European Data Protection Board (EDPB)
10.3 U.S. Data Privacy Framework
Some of our processors participate in the EU-U.S. Data Privacy Framework. We verify framework participation and compliance for applicable processors.
10.4 Your Rights Regarding International Transfers
You have the right to:
- Request information about international transfers of your data
- Obtain a copy of the appropriate safeguards (SCCs) we use
- Object to specific international transfers (subject to contract performance requirements)
To exercise these rights, contact us at Email.
11. Data Retention Periods
We retain personal data only as long as necessary for the purposes for which it was collected or as required by law (Article 5(1)(e) GDPR - storage limitation principle).
| Data Category | Retention Rule | Legal Basis |
|---|---|---|
| Account data (email, profile) | While needed to operate the account, then only as required for legal or dispute purposes | Contract performance |
| Authentication tokens | Until logout, revocation, replacement, or configured token expiry | Contract performance |
| Memory records (numeric style signals) | Until you delete them (individually or all at once) or the account is cleaned up, subject to legal obligations. Deleting all signals preserves your learning on/off setting. | Consent |
| Usage statistics | Only while needed for billing, service operation, security, and aggregate analysis | Legitimate interest |
| Captured messages, intent, and reply text | Processed transiently and not persisted in the ReplyContext application database | Contract performance |
| Reply operation records (identifiers, token counts, reply hash) | While needed for billing integrity, feedback verification, security, and legal obligations | Contract performance / legitimate interest |
| Support correspondence | While needed to resolve the request and meet legal or dispute obligations | Legitimate interest |
| Subscription/billing records | For the period required by applicable tax and accounting law | Legal obligation |
| Server error and security logs | Only while needed to diagnose reliability or security issues | Legitimate interest |
| Marketing consent records | Only while needed to document consent and withdrawal obligations | Legal obligation |
When a retention purpose ends and no legal obligation applies, the relevant personal data is deleted or anonymized. We do not publish fixed product-retention periods unless they are enforced by the deployed system.
12. Security Measures
12.1 Technical and Organizational Measures
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, as required by Article 32 GDPR:
Technical Measures
- Encryption in transit: TLS 1.3 for all data transmission
- Encryption at rest: AES-256 encryption for stored data
- Secure authentication: OAuth 2.0 with PKCE, token rotation, and secure token storage
- Access controls: Role-based access control (RBAC) for backend systems
- Network security: Firewalls, intrusion detection, and DDoS protection
- Secure development: Code reviews, security testing, and vulnerability scanning
- Data minimization: Local-first architecture minimizes server-side data storage
Organizational Measures
- Data protection by design: Privacy considerations integrated into product development
- Data protection by default: Privacy-friendly default settings
- Staff training: Regular data protection training for employees
- Confidentiality agreements: All employees sign confidentiality and data protection agreements
- Incident response plan: Documented procedures for data breach response
- Regular audits: Periodic security audits and assessments
- Vendor management: Due diligence on all processors and subprocessors
12.2 Your Security Responsibilities
You are responsible for:
- Maintaining the confidentiality of your account credentials
- Protecting access to the account you use to sign in
- Keeping your iOS device and app updated
- Reporting any security concerns or unauthorized access
13. Your GDPR Rights
As a data subject under GDPR, you have the following rights regarding your personal data:
13.1 Right of Access (Article 15 GDPR)
You have the right to obtain confirmation as to whether we process your personal data and, if so, access to the data and information about the processing, including:
- Purposes of processing
- Categories of personal data
- Recipients or categories of recipients
- Retention periods
- Your other GDPR rights
- The source of data not collected from you
- Existence of automated decision-making, including profiling
You can request a copy of your data in the app settings or by contacting Email.
13.2 Right to Rectification (Article 16 GDPR)
You have the right to obtain correction of inaccurate personal data and to have incomplete personal data completed. You can update your account information directly in the app settings.
13.3 Right to Erasure / "Right to be Forgotten" (Article 17 GDPR)
You have the right to request deletion of your personal data when:
- The data is no longer necessary for the purposes for which it was collected
- You withdraw consent and there is no other legal basis for processing
- You object to processing and there are no overriding legitimate grounds
- The data has been unlawfully processed
- Erasure is required to comply with a legal obligation
You can delete your account and associated data in the app settings. Note that we may retain certain data as required by law (e.g., tax records).
13.4 Right to Restriction of Processing (Article 18 GDPR)
You have the right to request restriction of processing when:
- You contest the accuracy of the data (during verification)
- Processing is unlawful and you oppose erasure
- We no longer need the data but you need it for legal claims
- You have objected to processing (pending verification of legitimate grounds)
13.5 Right to Data Portability (Article 20 GDPR)
You have the right to receive your personal data in a structured, commonly used, machine-readable format (JSON) and to transmit it to another controller when:
- Processing is based on consent or contract performance
- Processing is carried out by automated means
You can review your memory records in the app and request an export of your stored personal data by contacting us.
13.6 Right to Object (Article 21 GDPR)
You have the right to object to processing based on legitimate interests or for direct marketing purposes. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests.
For direct marketing, you have an absolute right to object at any time.
13.7 Right Not to be Subject to Automated Decision-Making (Article 22 GDPR)
We do not engage in automated decision-making or profiling that produces legal effects or similarly significantly affects you. AI processing is conducted at your explicit request for specific tasks.
13.8 Right to Withdraw Consent (Article 7(3) GDPR)
Where processing is based on consent, you have the right to withdraw consent at any time through the app settings. Withdrawal does not affect the lawfulness of processing before withdrawal.
13.9 How to Exercise Your Rights
To exercise any of these rights, you may:
- Use the privacy controls and export features in the app settings
- Email us at Email
- Send a written request to helpful bits GmbH, Munich, Germany
We will respond to your request within one month. In complex cases, we may extend this by two additional months, and we will inform you of any such extension.
We may request additional information to verify your identity before fulfilling your request. Requests are generally free of charge, but we may charge a reasonable fee for manifestly unfounded or excessive requests.
15. Detailed Legal Basis for Processing Activities
This table provides a detailed overview of our processing activities and their legal basis:
| Processing Activity | Data Categories | Legal Basis (Art. 6 GDPR) | Purpose |
|---|---|---|---|
| Account creation and authentication | Email, ReplyContext authentication records, device ID | 6(1)(b) Contract | Provide access to Service |
| Reply generation and revision | Captured messages, screenshots, stated intent, drafted replies (transient) | 6(1)(b) Contract | Draft the reply you requested |
| Memory records | Numeric style signals derived from accepted edits | 6(1)(a) Consent | Match your writing style in future replies |
| Reply operation records | Request identifiers, token counts, reply hash | 6(1)(b) Contract 6(1)(f) Legitimate interest | Idempotent billing, feedback verification, abuse prevention |
| Subscription and purchase processing | Subscription status, plan type, credit balance, store transaction identifiers | 6(1)(b) Contract | Manage subscriptions, credit purchases, and access |
| Reply usage accounting | API calls, token counts, credits | 6(1)(f) Legitimate interest | Billing verification and service reliability |
| Error logging and diagnostics | Server errors and request outcomes | 6(1)(f) Legitimate interest | Troubleshooting, quality assurance |
| Customer support | Email, support correspondence | 6(1)(b) Contract 6(1)(f) Legitimate interest | Respond to inquiries, resolve issues |
| Security and fraud prevention | IP address, device ID, access logs | 6(1)(f) Legitimate interest | Protect Service and users from abuse |
| Legal compliance (tax records) | Billing records, invoices | 6(1)(c) Legal obligation | Comply with tax law (AO §147) |
17. Children's Privacy
The Service is not directed to children under the age of 16. We do not knowingly collect personal data from children under 16 without parental consent.
Users aged 16-17 may use the Service with parental consent and supervision. Parents or legal guardians may exercise GDPR rights on behalf of minors.
If we become aware that we have collected personal data from a child under 16 without proper parental consent, we will take steps to delete such information promptly.
18. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or the Service. We will notify you of material changes by:
- Posting the updated Privacy Policy on our website and in the app
- Sending an email notification to your registered email address
- Displaying an in-app notification upon next login
For material changes that require consent under GDPR (e.g., new processing purposes), we will obtain your explicit consent before implementing the changes.
The "Last Updated" date at the top of this policy indicates when it was last revised. We encourage you to review this Privacy Policy periodically.
19. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data processing practices, please contact us:
helpful bits GmbH
Munich, Germany
Privacy Inquiries: Email
Data Protection Officer: Email
General Contact: Email
Website: replycontext.com
We aim to respond to all privacy inquiries within one month. In complex cases, we may extend this period by two additional months and will inform you of any such extension.
20. Data Breach Notification
20.1 Notification to Supervisory Authority
In the event of a personal data breach, we will notify the competent supervisory authority (BayLDA) within 72 hours of becoming aware of the breach, as required by Article 33 GDPR, unless the breach is unlikely to result in a risk to your rights and freedoms.
20.2 Notification to Data Subjects
If a data breach is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay, as required by Article 34 GDPR. The notification will include:
- The nature of the personal data breach
- The likely consequences of the breach
- Measures taken or proposed to address the breach
- Contact information for further inquiries
20.3 Breach Response Measures
We maintain an incident response plan that includes:
- Immediate containment and mitigation procedures
- Forensic investigation to determine breach scope and impact
- Notification to affected parties and authorities
- Implementation of remedial measures to prevent recurrence
- Documentation of all breach-related activities
21. California Privacy Rights (CPRA) - For California Residents
Note: This section applies only to California residents who may be using the Service. EU/EEA residents should refer to the GDPR provisions above.
21.1 CPRA Rights
If you are a California resident, you have the following rights under the California Privacy Rights Act (CPRA):
- Right to Know: Request information about categories and specific pieces of personal information we collect
- Right to Delete: Request deletion of your personal information
- Right to Correct: Request correction of inaccurate personal information
- Right to Opt-Out: Opt out of sale or sharing of personal information (we do not sell personal information)
- Right to Limit Use of Sensitive Personal Information: Limit use of sensitive personal information
- Right to Non-Discrimination: Not receive discriminatory treatment for exercising CPRA rights
21.2 Notice of Collection
We collect the categories of personal information described in Section 5 of this Privacy Policy for the purposes described in Section 6 and Section 15.
21.3 No Sale or Sharing
We do not sell or share (for cross-context behavioral advertising) personal information as defined by the CPRA.
21.4 Exercising CPRA Rights
To exercise your CPRA rights, contact us at Email or use the privacy controls in the app settings.
22. Additional Provisions
22.1 Data Protection Officer
We have appointed a Data Protection Officer (DPO) who can be reached at Email.
22.2 Third-Party Links
Our Service may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies.
22.3 Business Transfers
In the event of a merger, acquisition, or sale of assets, your personal data may be transferred to the acquiring entity. We will notify you of any such transfer and any choices you may have regarding your data.
22.4 Legal Disclosures
We may disclose personal data when required by law, court order, or legal process, or to protect our rights, property, or safety, or the rights, property, or safety of others.
22.5 Data Protection Impact Assessments
We conduct Data Protection Impact Assessments (DPIAs) as required by Article 35 GDPR for processing activities that are likely to result in high risks to your rights and freedoms.
23. Effective Date and Governing Version
This Privacy Policy is effective as of January 1, 2025. If there are any conflicts between different language versions of this Privacy Policy, the English version shall prevail to the extent permitted by law.
Previous versions of this Privacy Policy are available upon request by contacting Email.
This Privacy Policy complies with:
- General Data Protection Regulation (GDPR) - Regulation (EU) 2016/679
- German Federal Data Protection Act (BDSG)
- German Telecommunications-Telemedia Data Protection Act (TDDDG)
- California Privacy Rights Act (CPRA) - for California residents
Last updated: July 11, 2026 | Effective: January 1, 2025
© 2026 helpful bits GmbH. All rights reserved.