Effective Date: March 17, 2026 | Last Updated: September 21, 2026
Throughout this Privacy Policy:
| Data Type | What We Collect | Purpose |
|---|---|---|
| Account Information | Name, email address, profile picture, organization name | Account creation and management via WorkOS AuthKit |
| Authentication Data | Authentication ID, session tokens | Secure login and session management |
| Chatbot Configuration | Bot name, persona, instructions, model preferences, appearance settings (icon, color, welcome message) | Chatbot creation and customization |
| Training Data | Uploaded documents (PDF, DOCX, CSV, text files), website URLs, YouTube URLs, sitemaps | AI training and RAG (Retrieval-Augmented Generation) for chatbot responses |
| Custom Responses | Question-and-answer pairs, knowledge snippets | Customizing chatbot behavior and responses |
| Domain Configuration | Allowed domains and domain patterns | Widget embedding restrictions and security |
| Integration Credentials | Facebook Page access tokens, Page IDs, Instagram account IDs | Messenger and Instagram integration functionality |
| Team Information | Member email addresses, roles (admin/member), invitation tokens | Collaborative chatbot management |
| Data Type | What We Collect | Purpose |
|---|---|---|
| Chat Messages | Messages sent to and received from chatbots | Providing chatbot responses, conversation history |
| Conversation Metadata | Conversation timestamps, source channel (widget, Messenger, Instagram) | Conversation management and analytics |
| Lead Information | Name, email, phone number, message (voluntarily provided through lead capture forms or AI-assisted capture) | Lead generation for Bot Owners |
| Technical Data | IP address (for rate limiting only, not stored persistently), referring domain | Rate limiting, domain validation, abuse prevention |
| Platform Identifiers | Facebook Page-Scoped User ID (PSID), Instagram-Scoped User ID (IGSID), profile name, profile picture URL | Messenger/Instagram conversation management |
Replia offers free audit tools at replia.ph that anyone may use without an account: a website scan, where you submit a URL, and a Facebook Page audit, where you upload screenshots of your own Facebook Page Insights. Both return a recommended plan. This is what those tools take in:
| Data Type | What We Collect | Purpose |
|---|---|---|
| Website URL | The address you submit for a website scan. We fetch that site's publicly accessible pages, sitemap, and help/FAQ content the way a search engine crawler would. | Estimating page count, common question topics, and likely chat volume in order to recommend a plan |
| Facebook Page Insights screenshots | Images you upload of your own Facebook Page Insights (Engagement, Audience, and Content views). These typically show reach, views, interactions, comments and replies, reactions, follows and follower counts, and aggregate audience breakdowns by age range, gender, and top location. | Reading the metrics visible in the images so we can recommend a plan that matches your inquiry volume |
| Extracted metrics | The numbers and aggregate audience figures read from those screenshots | Generating the audit result displayed in your browser |
| Audit usage events | The URL submitted, whether the audit succeeded or failed, and which plan was recommended or clicked | Product analytics (see Section 5) |
Retention. Audit inputs are transient. Screenshots you upload are held only for the duration of the request, passed inline to the AI provider that reads them, and discarded when the audit returns — they are never written to our database or file storage, and we cannot retrieve them afterwards. The same applies to the URL you scan, the pages we fetch from it, and the metrics extracted from your screenshots: the result is rendered in your browser and is not saved to any account. The one exception is the audit usage events described above, which record the URL submitted and the audit outcome — never the screenshots or their contents.
Third-party processing. To read your screenshots, the images are sent to our AI provider — Google AI (Gemini) where configured, otherwise OpenAI — which returns the visible numbers. These providers do not use the images to train their models, and neither do we. The website scan involves no AI provider. Screenshots are never shared with Meta, and you do not need to connect a Facebook Page to run the audit. Please upload only screenshots of Pages you manage, and crop out anything you would rather not have processed — images are sent to the provider as they are.
Legal basis. Consent. You choose which URL to submit and which screenshots to upload, and the audit tools are optional (see Section 4).
We process personal information based on the following legal grounds:
Replia uses the following third-party services to operate:
| Service | Purpose | Data Shared |
|---|---|---|
| Convex | Backend database, real-time sync, file storage | All platform data (stored and processed on Convex infrastructure) |
| WorkOS AuthKit | Authentication and user management | Email, name, profile picture, authentication events |
| OpenAI | AI chat responses (GPT-5, GPT-5 Mini), text embeddings, and reading Page Insights screenshots for the free audit | Chat messages, Training Data text chunks, conversation context, and audit screenshots (only when OpenAI is the configured vision provider) |
| Google AI (Gemini) | Alternative AI chat responses (Gemini 3) and reading Page Insights screenshots for the free audit | Chat messages and conversation context (only when selected as bot model); audit screenshots (when Gemini is the configured vision provider) |
| Google Cloud Vision | PDF document OCR processing | PDF documents uploaded for training (temporarily stored during processing) |
| Meta Platform | Messenger and Instagram DM integrations | Messages, user profile data, page access tokens |
| PostHog | Product analytics and error reporting on replia.ph | Page views, feature usage events (including URLs submitted to the free audit), browser and device metadata, and — for signed-in Bot Owners — account ID, name, and email |
Replia uses AI to provide chatbot responses through Retrieval-Augmented Generation (RAG):
When enabled by the Bot Owner, the chatbot may use AI to identify opportunities to collect lead information during conversations. The chatbot will ask the End User for their name, email, or phone number when contextually appropriate. End Users are never required to provide this information.
| Data Type | Retention Period |
|---|---|
| Account data (Bot Owners) | Retained while account is active; deleted upon account deletion request |
| Chatbot configurations | Retained while the chatbot exists; deleted when bot is deleted (cascade deletion) |
| Training Data (documents, embeddings) | Retained while associated resource exists; deleted when resource is removed |
| Conversation history and messages | Retained while the chatbot exists; Bot Owners may delete individual conversations |
| Lead information | Retained until deleted by Bot Owner |
| PDF processing jobs | Temporary; cleaned up after processing completes or fails |
| IP addresses (rate limiting) | Not stored persistently; used only for in-memory rate limit calculations |
| Platform integration tokens | Retained while integration is active; deleted when disconnected |
| Audit inputs (submitted URLs, Page Insights screenshots) | Not stored; processed in memory for the duration of the audit and discarded when the result is returned |
| Audit results and extracted metrics | Not stored; rendered in your browser only |
| Product analytics events | Retained by PostHog for as long as needed for product analytics; contains no screenshot images or their contents |
When a Bot Owner deletes a chatbot, all associated data is cascade-deleted, including: conversations, messages, leads, resources, documents, embeddings, custom responses, knowledge snippets, appearance settings, allowed domains, and platform integrations.
We do not sell, rent, or trade personal information. We share data only in these circumstances:
We implement appropriate technical and organizational measures to protect personal data, including:
While we strive to protect your information, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security.
You have the right to:
You have the right to:
For users in the Philippines, you are entitled to the following rights under the Data Privacy Act of 2012:
To exercise any of these rights, contact us at the details provided in Section 15. We will respond to requests within 30 days.
The Widget does not use cookies, third-party trackers, or analytics scripts.
Replia is not directed at individuals under the age of 16. We do not knowingly collect personal information from children under 16. If we learn that we have collected personal information from a child under 16, we will take steps to delete such information promptly. If you believe a child has provided us with personal data, please contact us.
Replia's infrastructure and third-party processors may store and process data in locations outside the Philippines, including the United States (Convex, OpenAI, WorkOS, Google Cloud). By using the Platform or interacting with a Replia-powered chatbot, you acknowledge that your data may be transferred to and processed in these jurisdictions.
We ensure that any international data transfer is conducted with appropriate safeguards, including the use of processor agreements with our third-party service providers.
We may update this Privacy Policy from time to time. When we make material changes, we will:
Continued use of the Platform after changes take effect constitutes acceptance of the updated Privacy Policy.
Elevatech
Data Privacy Inquiries
Email: privacy@replia.ph
Website: replia.ph
For complaints regarding your personal data, you may also contact the National Privacy Commission (NPC) of the Philippines at privacy.gov.ph.