Privacy Policy

Last Updated: October 6, 2026

Our Commitment to Your Privacy

SmartReply, operated by Incharge Marketing LLC ("SmartReply," "we," "us," or "our"), is dedicated to protecting your privacy and handling your personal information with care. This policy covers our website at smartreply.io, our web and mobile services, the SmartReply extension for Google Chrome, SmartReply apps, plugins, and connectors used through ChatGPT, Claude, Meta Muse, and Grok where available and enabled, and connected services, including Google APIs where enabled. It explains the information we collect, why we use it, who receives it, retention, and your choices. For privacy questions or requests, contact support at smartreply dot io.

1. Information Collection Practices

Data You Provide to Us

We collect personal information that you choose to share with us through various interactions, including:

  • Creating an account on our platform
  • Signing up for newsletters or email communications
  • Completing and submitting online forms
  • Reaching out to our support team
  • Authorizing access to your Google account or enabled Google integrations
  • Choosing Sign in with Apple to create or access your account
  • Taking a photo or choosing an image to submit through a feature you initiate in the mobile app

This information may include:

  • Full name, email address, phone number, company name, and mailing address
  • If you use Sign in with Apple, the name and email address Apple provides to us. If you choose Apple's Hide My Email option, we receive Apple's private relay email address instead of your personal email address.
  • Photos or images you choose to capture or upload, along with information contained in those images
  • Google data you authorize through the OAuth consent screen, such as Gmail messages and labels, Gmail send access, Google Drive files selected for enabled features, Google Business Profile review data, YouTube channel and comment data, Google Ads reporting data, and basic Google profile information such as name and email address.
  • Any additional information you choose to provide

Connected Services and Customer Content

Depending on the services and features you enable, we process social media comments, direct messages, email conversations, reviews, posts, and associated names, usernames, contact details, account identifiers, timestamps, and attachments. We also process business information you supply, such as product details, policies, brand instructions, and example replies, to provide relevant responses.

Connected commerce and reporting features may provide customer profiles, orders, purchases, product interests, engagement events, and campaign performance. We use these records to show customer history, answer customer questions, and provide the reporting or actions you enable. Draft replies, generated content, conversation history, and action results are also service data and may contain personal information. Only connect accounts and submit customer information you are authorized to use.

Automatically Collected Data

When you visit SmartReply.io, our systems automatically gather certain technical information, including:

  • IP address, browser type and version, and operating system details
  • Pages visited, entry and exit points, timestamps, and clickstream patterns
  • Internet service provider information

This data helps us analyze usage trends, maintain our website, and enhance overall performance.

Google Chrome Extension

This section applies when you install or use the SmartReply extension for Google Chrome. The extension brings information from your authorized SmartReply workspace into your browser to help you manage appeals and reimbursement claims on supported platforms, prepare supporting information, and keep track of support tickets. It requires a SmartReply account and access to the matching account on the platform you use. Available platforms and features depend on the version of the extension and the connections you enable. The data needed depends on the feature you use and the access you grant. The restrictions in this section apply to extension user data and take precedence over broader uses or sharing described elsewhere in this policy.

Information and Permissions

  • Account and authentication information: The extension uses your existing SmartReply and connected platform sign in sessions. It processes your user, company, agent, and shop identifiers and relevant account details to check access and keep records associated with the correct workspace and shop. It does not collect your passwords or read session cookies or API tokens.
  • Appeal and ticket information: The extension processes suggested appeals and claim drafts from SmartReply, your edits, order and conversation references, reimbursement details, and selected supporting images or documents. It also reads relevant appeal and support ticket identifiers, statuses, and platform replies to help you track progress and sync updates to SmartReply. These records and evidence may contain customer names, contact information, delivery details, or other personal information.
  • Website context: The extension checks relevant SmartReply and supported platform page addresses and reads the page information needed to identify the workspace, shop, claim form, or ticket. SmartReply administration, Horizon, and login pages cannot be connected as workspace tabs. Navigating a connected workspace tab to one of those pages clears the connection. Browsing activity is collected or transmitted only as necessary for a feature prominently described in the extension's listing and interface. It is not used to track your browsing for advertising.
  • Settings and operational data: The extension keeps session state and a submission history to help prevent duplicate claims. Support diagnostics may include account identifiers, the extension version, an incident identifier, and technical error details. For example, an unexpected sign out during an action can be reported to SmartReply so we can investigate the interruption.

Browser permissions allow the extension to display its side panel, store session and submission records, and read or fill relevant information in connected SmartReply and supported platform tabs. Access to additional supported platform sites or evidence download hosts is requested when needed. We limit access and data use to the extension's disclosed purpose. You can review or restrict website access and disable or remove the extension in Chrome's extension settings. Restricting access can prevent a feature from working. If a feature requires collection or use of personal information beyond what users would reasonably expect, we provide a prominent explanation and obtain consent before that collection or use begins.

Use, Sharing, and Limited Use

SmartReply's collection, use, and transfer of Chrome extension user data complies with the Chrome Web Store User Data Policy, including its Limited Use requirements. These restrictions also apply to aggregated, anonymized, and derived data.

We use extension user data only to provide or improve the extension's disclosed purpose, including the operation, security, performance, and reliability of those features. SmartReply receives the ticket updates and action results you sync to your workspace. If you request an appeal assessment or draft through SmartReply, the relevant content may be processed by the AI providers described in Section 7, including OpenAI. Hosting, storage, and security providers process information needed to operate these features. When you choose to submit a reviewed claim, individually or as part of a reviewed group, the connected platform receives the claim details and selected supporting evidence. The extension helps with preparation and submission following your review and confirmation.

We do not sell extension user data, transfer it to data brokers or advertising platforms, use it for personalized advertising, or use it to determine creditworthiness or eligibility for lending. Extension user data is not used to train general purpose AI models. Website marketing and tracking described in Section 6 do not authorize use of extension user data for those purposes.

We transfer extension user data only as necessary to provide or improve its disclosed purpose, comply with applicable law, protect against malware, spam, phishing, fraud, or abuse, or as part of a merger, acquisition, or asset sale after obtaining your explicit prior consent. We do not allow people to read extension user data unless you explicitly consent to access to specific data, access is necessary for security or legal compliance, or the data is aggregated and anonymized for internal operations in accordance with applicable law.

Storage, Security, and Deletion

Session information, loaded claims, and prepared drafts are kept in Chrome's extension session storage. Submission history and pending support diagnostics are kept in local extension storage and can remain across extension reloads. Access to submission history is limited to the matching signed in SmartReply account context. Losing SmartReply authentication clears session drafts and hides claims and history until access is restored. Data sent to SmartReply is processed by SmartReply and the service providers described above, with encryption in transit and access controls. Server records, including appeal information, evidence, and synced ticket updates, follow the retention and deletion practices in Section 4. We retain extension user data only as long as needed for the disclosed feature and permitted operational or legal purposes.

You can stop extension access by disabling or uninstalling it in Chrome. You can also revoke connected service authorizations through the relevant service's settings. Removing the extension does not delete data already stored by SmartReply or claims and evidence already submitted to a connected platform. Records held by that platform remain subject to its retention practices and account controls. To request access, correction, export, or deletion of extension data held by SmartReply, contact support at smartreply dot io and identify your account and the data concerned. We may verify your authority and respond within 30 days, as described in Section 4.

AI Apps, Plugins, and Connectors

This section covers SmartReply connections used through ChatGPT, Claude, Meta Muse, and Grok where available and enabled. Information passes between your chosen AI service and SmartReply when the service calls a SmartReply tool or API. These disclosures apply to the information exchanged, whether the connection is called an app, plugin, connector, or MCP server. Availability and supported actions depend on the connection you use; naming a service here does not mean a listing has been approved.

Information Received and Its Purpose

  • Tool inputs: We process the instructions, text, selected content, record references, and other fields that your chosen AI service sends to a SmartReply tool to carry out your request. These inputs can contain personal information if it is included in the content you share.
  • Connected account data: When a feature requires a connected SmartReply account or service, we use the account authorization and relevant records to identify the account, check access, and perform the requested operation.
  • Tool outputs: The result returned to your chosen AI service can include requested records, summaries, generated content, and the outcome of an action, depending on the tool used. Personal information contained in those results is shared with that service so it can present the result and use it to complete your task.

Content included in a tool request is shared with SmartReply. Connecting a service does not by itself give SmartReply access to every conversation in your AI account. Share only information needed for the task. Do not include passwords, API keys, payment card details, government identifiers, or protected health information in tool inputs.

Recipients and Your Choices

  • ChatGPT: When you use SmartReply through ChatGPT, OpenAI receives the tool results. See the OpenAI Privacy Policy.
  • Claude: When you use SmartReply through Claude, Anthropic receives the tool results. See the Anthropic Privacy Policy.
  • Meta Muse: When you use SmartReply through Muse, Meta's Muse service receives the connector results. See the Muse Privacy Policy, which may require signing in.
  • Grok: When you use SmartReply through Grok, the provider of your Grok service receives the connector results. See the Grok provider Privacy Policy. If you access Grok through X, consult the X Privacy Policy for that service.

Using one of these connections does not by itself send your information to all the other AI services listed here. The service you choose receives the results of its requests. This is separate from SmartReply's use of AI providers to generate content, described in Section 7. The providers' policies describe their own handling of information and do not replace SmartReply's obligations under this policy.

The AI service you use receives tool results. SmartReply and the service providers described in Section 7 process the information needed to fulfill the request. If you request an action that sends or publishes content through a connected service, that service and the intended recipients receive the content. Public replies can be visible to anyone who can view the original post or review.

You can stop using the connection or remove it through the AI service's app or connector controls, where available. If your organization manages connections, contact its administrator to revoke access. You can also contact SmartReply for help revoking a connection. Disconnecting does not itself delete data already stored by SmartReply, delete your AI conversations, or remove content already sent to another service. To request access, correction, export, or deletion of information held by SmartReply, contact support at smartreply dot io. Manage conversations, saved content, and other data held by the AI service separately through that service's privacy controls or support channels. Its retention, model improvement practices, and available controls depend on its policies, your plan, and your settings. Revoking a connection and requesting deletion are separate actions.

2. Mobile App Permissions and Account Sign In

Camera and Photos

SmartReply requests camera access only when you choose to take a photo within the mobile app. For example, you may use the camera to capture an image and attach it to content you submit through a SmartReply feature. We process the photo to provide the feature you requested. SmartReply does not access the camera continuously or take photos without your action. You can deny or later revoke camera permission in your device settings, although features that require the camera will then be unavailable.

Sign in with Apple

If you choose Sign in with Apple, Apple provides SmartReply with an account identifier and, depending on your choices, your name and email address. You may use Apple's Hide My Email option so that SmartReply receives a private relay address instead of your personal email address. We use this information only to create, authenticate, secure, and support your SmartReply account. We do not use data from Sign in with Apple or your interactions with the app for advertising purposes.

3. How Your Information Is Used

The information we collect serves multiple essential purposes:

First and foremost, we use your data to deliver and maintain the SmartReply platform, ensuring all core features operate smoothly and reliably. We process Google API data only to provide the specific SmartReply features you enable or request, such as syncing conversations, labeling processed messages, generating suggested replies, sending approved replies, retrieving authorized Drive files, managing reviews, moderating comments, or showing authorized reporting data. Through analysis of aggregated usage patterns that do not identify Google user content, we continuously refine platform performance, introduce new features, and personalize your user experience.

We also leverage your contact information to keep you informed about product enhancements, company news, and relevant marketing communications (all of which you can opt out of whenever you wish). Payment information is processed to handle billing, subscription management, and invoice generation. When you contact our support team, we use your data to address your inquiries and resolve technical issues efficiently.

Additionally, we monitor and evaluate data to identify, investigate, and prevent fraudulent activities or security threats, protecting both you and our platform. Finally, we may process your information to uphold our Terms of Service, meet legal obligations, and comply with applicable regulatory requirements.

4. Data Retention and Deletion

We maintain personal information only for as long as necessary to fulfill the purposes outlined in this policy or as mandated by applicable laws. Google API data is retained exclusively for the duration needed to deliver SmartReply services and satisfy contractual or legal requirements.

This applies to account information, connected service records, customer content, and personal information in app tool inputs and outputs. Retention depends on whether information is needed for an active account or enabled feature, an unresolved support request, security investigation, or a legal recordkeeping obligation. Disconnecting an integration stops its authorized access but is separate from requesting deletion of previously collected information.

Once retention periods conclude (or upon receiving a verified deletion request from you), we securely delete or anonymize your data, except where continued retention is required by law, security, fraud prevention, dispute resolution, or backup restoration practices.

You can request deletion of your account or specified data by emailing support at smartreply dot io. Identify the account and information concerned without sending passwords or authentication secrets. We may verify your authority before acting. Our response time for privacy requests is 30 days; this is not a promise that every backup or record held by another provider is erased within that period. Copies in ChatGPT, Claude, Meta Muse, Grok, exported files, and content sent to connected platforms are subject to the controls and retention practices of the service or person holding them.

5. Google API Integration

When you connect a Google account, SmartReply only accesses the Google data you authorize through the OAuth consent screen. Depending on the Google integration you enable, this may include Gmail messages and labels, Gmail send access, Google Drive files selected for enabled features, Google Business Profile review data, YouTube channel and comment data, Google Ads reporting data, and basic Google profile information such as name and email address.

We use Google user data only to provide and improve the specific features you enable, such as syncing Gmail conversations, labeling processed messages, generating suggested replies, sending approved replies, retrieving authorized Drive files, managing Google Business Profile reviews, moderating YouTube comments, or displaying authorized Google Ads reporting data.

SmartReply does not sell Google user data. SmartReply does not use Google user data to train general purpose AI or machine learning models. SmartReply does not train AI or machine learning models specific to a customer on Google user data unless separately agreed and permitted by applicable law, Google policies, and your explicit authorization.

SmartReply does not transfer Google user data to third parties except as necessary to provide or secure the SmartReply service, comply with law, or with your explicit direction. Service providers, including AI service providers used to generate replies or other outputs requested by users, may process Google user data only to provide the enabled SmartReply feature, under contractual restrictions, and not to train their models.

SmartReply's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

You may disconnect Google integrations at any time from your SmartReply account settings or by revoking access at https://myaccount.google.com/permissions. You may request deletion of Google user data by contacting support at smartreply dot io.

6. Cookies and Tracking Technologies

SmartReply employs cookies and similar tracking technologies to enhance your browsing experience:

  • Essential Cookies: Required for basic website functionality
  • Performance Cookies: Help us measure and optimize site performance
  • Functional Cookies: Remember your preferences and settings
  • Targeting Cookies: Enable relevant advertising and marketing for our website visitors. We do not use Google API user data for targeted advertising.

You can manage cookie preferences through your browser settings. Please note that disabling certain cookies may affect the functionality of some features.

Our website loads Google Tag Manager to manage website tags, FirstPromoter for referral attribution, Klaviyo for marketing interactions, and SmartReply's website tracking script for page visits and sessions. These services can receive browser and device information, page URLs, referral information, and interaction events when their scripts run. Browser tracking protection and cookie controls can limit this collection. You can unsubscribe from marketing emails using the link in those emails.

7. Information Sharing and Disclosure

We share your information only in the following limited circumstances:

  • Hosting and Operations: Infrastructure, storage, security, and support providers process information needed to host records, operate features, troubleshoot problems, and protect the service.
  • AI Services: AI providers, including OpenAI, process the content and relevant business context needed to generate requested replies, summaries, and other outputs. Our providers may process information only as needed to provide or secure SmartReply, under contractual restrictions, and may not use Google user data to train their AI models.
  • Connected Platforms and Message Recipients: Services you connect receive requests needed to perform enabled features. Messages and published replies are shared with their recipients or the audience of the relevant channel.
  • Account Users: People with authorized access to your SmartReply workspace can access service data according to their permissions.
  • Billing and Website Services: Payment providers process billing information for subscriptions. Website analytics, referral, and marketing providers receive the website information described in Section 6.
  • Legal Compliance: We may disclose information when required by law, court order, subpoena, or valid government request
  • Business Transfers: In the event of a merger, acquisition, or asset sale, your data may be transferred, but will continue to be protected under this Privacy Policy

We Never Sell Your Data: We do not and will not sell, rent, or trade your personal information to third parties for their marketing purposes.

8. Security Measures

We implement industry standard security practices to protect your information, including:

  • Encryption in transit and at rest
  • Secure, access controlled cloud hosting infrastructure
  • Network and application layer protections
  • Strict access controls and authentication protocols
  • Regular security audits and vulnerability assessments

While we employ robust security measures, please understand that no method of internet transmission or electronic storage can be guaranteed to be 100% secure.

9. Your Privacy Rights

For Users in the European Economic Area (GDPR)

If you reside in the EEA, you have the following rights:

  • Right to access your personal data
  • Right to rectify inaccurate information
  • Right to request deletion of your data
  • Right to restrict or object to processing
  • Right to data portability

For California Residents (CCPA)

California users have the right to:

  • Know what personal information is collected
  • Request deletion of personal information
  • Opt out of the sale of personal data (note: we do not sell personal information)

To exercise any of these rights, please contact us at support at smartreply dot io. We may need to verify your identity before processing your request and will respond within 30 days.

10. Children's Privacy Protection

SmartReply is not intended for use by individuals under the age of 13. We do not knowingly collect personal information from children. If we become aware that we have inadvertently gathered data from a child under 13, we will take immediate steps to delete such information.

11. Third Party Websites

Our website may contain links to external websites that we do not operate or control. We encourage you to review the privacy policies of these third party sites, as we are not responsible for their privacy practices or content.

12. International Data Transfers

Your information may be transferred to and processed in countries outside of your jurisdiction, including the United States, where data protection laws may differ from those in your country. By using SmartReply, you consent to such international transfers of your information.

13. Privacy Policy Updates

We reserve the right to modify this Privacy Policy from time to time. Any changes will be posted on this page with an updated "Last Updated" date. Your continued use of SmartReply after such modifications constitutes your acceptance of the revised policy.

14. Contact Information

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please don't hesitate to contact us:

Mailing Address
Incharge Marketing LLC
Chicago, IL 60610
United States

This Privacy Policy was last updated on October 6, 2026 and is effective immediately.