← Back to Replia

Privacy Policy

Effective Date: April 2, 2026 · Last Updated: April 2, 2026

Summary: Replia collects only what's needed to provide the service. We don't sell your data. We don't use your content to train AI models. You can delete everything at any time.

1. Data Controller

The data controller for information processed through Replia is:

Arve Tech FZC - LLC
Free Zone Company — Limited Liability
United Arab Emirates
Email: privacy@replia.net
Data Protection Contact: dpo@replia.net

2. Scope of This Policy

This Privacy Policy applies to all personal data processed through:

This policy does not apply to third-party services we integrate with (Meta Threads, Anthropic). Please review their respective privacy policies separately.

3. Categories of Personal Data We Collect

3.1 Data You Provide Directly

CategoryDataPurpose
AccountEmail address, password hashAuthentication
ProfileDisplay name, avatarPersonalization
PreferencesTheme, AI voice tone, niches, notification settingsService configuration
ContentPost drafts, custom AI prompts, edited repliesContent creation

3.2 Data Collected from Third Parties

SourceDataPurpose
Meta Threads APIUsername, profile picture, follower count, published posts, post metrics (views, likes, replies, reposts), public mentionsAnalytics, reply queue, publishing
Meta OAuthAuthorization tokensAPI access on your behalf

3.3 Data Collected Automatically

CategoryDataPurpose
UsageFeature usage, AI generation count, posts/replies sent per day, streak dataService limits, gamification
DeviceDevice type, OS version, app version, IP addressTechnical support, security
PerformanceCrash reports, API response timesService reliability

4. Legal Bases for Processing (GDPR)

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, we process your data under the following legal bases:

Processing ActivityLegal Basis
Account creation and authenticationContract performance (Art. 6(1)(b))
Publishing posts and replies on ThreadsContract performance (Art. 6(1)(b))
AI content generationContract performance (Art. 6(1)(b))
Analytics and performance trackingContract performance (Art. 6(1)(b))
Usage tracking and rate limitingLegitimate interest (Art. 6(1)(f))
Crash reporting and diagnosticsLegitimate interest (Art. 6(1)(f))
Marketing communicationsConsent (Art. 6(1)(a))

5. How We Use Your Data

6. Data Sharing and Sub-Processors

We do not sell, rent, or trade your personal data.

We share data with the following categories of service providers ("sub-processors"), solely to operate the Service:

Sub-ProcessorPurposeData SharedLocation
Meta Platforms, Inc.Threads API (publish, read, analytics)OAuth tokens, post content, API requestsUnited States
Anthropic PBCAI content generationText prompts, tone preferencesUnited States
Supabase, Inc. (AWS)Database, authentication, file storageAll account and usage dataUnited States (us-east-1)
Stripe, Inc. / Apple / GooglePayment processingEmail, subscription statusUnited States
Cloudflare, Inc.CDN, DNS, website hosting, DDoS protectionIP address, page views, request metadataGlobal (edge network)

We may also disclose data if required by law, court order, or to protect the safety of our users or the public.

7. Threads OAuth and Access Tokens

When you connect your Threads account via Meta's OAuth 2.0 flow:

Requested Threads API permissions: threads_basic, threads_content_publish, threads_manage_insights, threads_manage_replies, threads_read_replies, threads_keyword_search

8. AI Processing Details

Replia uses Anthropic's Claude API (specifically Claude Haiku) for content generation. Important details:

9. Data Retention

Data CategoryRetention PeriodDeletion Trigger
Account data (email, password)Duration of accountAccount deletion
Threads access tokenDuration of connectionDisconnect or account deletion
AI generation historyDuration of accountAccount deletion
Analytics dataDuration of subscriptionAccount deletion or 12 months after subscription end
Daily usage / streaksDuration of accountAccount deletion
Payment records7 years (legal requirement)Retained for tax/audit compliance
Server logs90 daysAutomatic rotation

Upon account deletion, all personal data is permanently removed from our systems within 30 days, except where retention is required by law.

10. Your Rights

10.1 All Users

10.2 EEA/UK/Swiss Users (GDPR)

Under the General Data Protection Regulation, you additionally have the right to:

To exercise any right, contact dpo@replia.net. We respond within 30 days.

10.3 California Users (CCPA/CPRA)

Under the California Consumer Privacy Act and California Privacy Rights Act:

To submit a verifiable consumer request, email privacy@replia.net.

10.4 Brazilian Users (LGPD)

Under the Lei Geral de Proteção de Dados, you have rights to access, correction, anonymization, portability, deletion, and information about sharing. Contact dpo@replia.net.

11. International Data Transfers

Your data is transferred to and processed in the United States (where our infrastructure providers are located). For transfers from the EEA/UK, we rely on:

12. Data Security

We implement the following technical and organizational measures:

13. Cookies and Tracking

The Replia website (replia.net) uses:

The Replia mobile app does not use cookies.

14. Children's Privacy

Replia is not directed at individuals under 16 years of age (or 13 in jurisdictions where that is the applicable age of digital consent). We do not knowingly collect personal data from children. If we learn that we have collected data from a child, we will delete it promptly. If you believe a child has provided us with personal data, please contact privacy@replia.net.

15. Do Not Track

We honor Do Not Track (DNT) browser signals. When DNT is enabled, we do not collect website analytics data.

16. Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices, technology, legal requirements, or for other operational reasons. For material changes:

17. Contact

For privacy inquiries, data requests, or complaints:

Arve Tech FZC - LLC
United Arab Emirates

General Privacy: privacy@replia.net
Data Protection Officer: dpo@replia.net
Legal: legal@replia.net

We aim to respond to all requests within 30 days.