Last updated: 2026-05-26

Privacy Policy.

How InRepply collects, uses, and protects your data — in plain language.

01 Introduction

InRepply is a job-application tracking service operated by [COMPANY_LEGAL_NAME], registered in Lublin, Poland. In this policy, 'we', 'us' and 'InRepply' mean that company. 'You' means anyone who uses InRepply on the web, iOS or Android.

This document explains what personal data we collect when you use InRepply, why we collect it, how long we keep it, and what rights you have under the EU General Data Protection Regulation (GDPR) and Polish law implementing it.

We try to write this in plain language. If anything is unclear, email us and we'll explain.

02 What data we collect

Account data: your email address, display name, and a hashed and salted version of your password. We never store passwords in plain text.

Job application data you put into InRepply: company names, role titles, salary ranges, application stages and dates, notes, contact details for recruiters, CV / résumé files, cover letters, screenshots of job listings, tags and reminders. This data is yours. We process it to give you the service and for nothing else.

Usage data:

  • Pages and screens visited within InRepply and the features you used.
  • Device and browser information: OS, browser type and version, screen size, language.
  • Your IP address. We anonymize the last octet after 30 days.

Payment data: payments are processed by Apple App Store, Google Play Billing, and Stripe, with subscription management by RevenueCat. We never see or store your card number, CVC or full bank details. We receive only the information we need to fulfil and account for the order.

03 How we use your data

We use your personal data for the following purposes:

  • Providing the servicestoring and syncing your applications, running AI features you trigger, generating statistics and reminders.
  • Improving the productanalysing aggregated, non-identifying usage patterns to decide what to build next, fix bugs, and improve performance.
  • Transactional emailsaccount confirmation, password resets, renewal reminders (sent 7 days before any subscription renewal), invoices, and security alerts.
  • Marketing emailsproduct updates and tips. Only if you've opted in, and only until you opt out.
  • Processing paymentsbilling, refunds, fraud prevention, accounting.
  • Complying with the lawkeeping accounting records, responding to lawful requests from authorities, defending legal claims.

04 AI processing with Google Gemini

InRepply's AI features (screenshot-to-application, smart suggestions, Gemini integration on Android) are powered by Google's Gemini API.

When you use one of these features, the relevant content — for example the screenshot of a job listing you paste in, the section of your CV being matched, or the question you ask Gemini — is sent to Google's Gemini API over an encrypted connection to be processed.

Under Google's Gemini API terms, Google does not use API request content to train its models and does not retain your request data beyond the time needed to serve the request (plus short-lived caches for abuse detection).

We do not send your contact list, your full job-search history or any other unrelated data to the Gemini API — only the specific content needed for the feature you triggered. Every AI action is opt-in and can be disabled in your settings.

06 Data sharing

We share personal data only with the processors we need to run InRepply. We do not sell your data. We do not share it with advertising networks. We do not share it with recruiters or employers.

Our processors are:

  • Google Cloud (US / EU regions)Gemini API for AI features.
  • Google Firebase (US / EU regions)authentication and transactional emails.
  • Apple App Store, Google Play Billing, Stripe, RevenueCatpayment processing and subscription management.
  • Google Firebase Analytics, Cloudflare Web Analyticsproduct analytics. Only when you consent to analytics cookies.

We may also share data with our accountants and lawyers when needed to run the company, and with public authorities if a valid legal request requires it.

07 Data retention

  • Account datakept until you delete your account.
  • Application datakept until you delete it inside InRepply, or until you delete your account.
  • Backupsretained for 30 days after deletion, then permanently destroyed.
  • Server logskept for 90 days for security and debugging.
  • Billing and accounting recordskept for 5 years from the end of the relevant tax year, as required by Polish tax law.
  • Anonymized analyticskept indefinitely; cannot be linked back to you.

08 Your rights under GDPR

You have the following rights over your personal data:

  • Right of accessget a copy of the data we hold about you.
  • Right to rectificationcorrect anything that's wrong.
  • Right to erasurehave your data deleted ('right to be forgotten').
  • Right to data portabilityreceive your data in a machine-readable format and move it elsewhere.
  • Right to restrictionask us to stop using your data while a dispute is sorted out.
  • Right to objectobject to processing based on legitimate interest, or to direct marketing.
  • Right to withdraw consentfor anything that relies on consent, you can take it back at any time.

To exercise any of these, email us from the address on your account. We respond within 30 days.

You also have the right to lodge a complaint with the Polish data protection authority (UODO, uodo.gov.pl) or the supervisory authority in your country of residence.

09 Data transfers outside the EU

Some of our processors are based in the United States (notably Google, Stripe, RevenueCat and Cloudflare). When your data is transferred outside the European Economic Area, we rely on the European Commission's Standard Contractual Clauses (and, where applicable, the EU-US Data Privacy Framework) to guarantee an equivalent level of protection.

You can request a copy of the safeguards in place by emailing us.

10 Security measures

  • All connections to InRepply use TLS 1.2 or higher.
  • Data at rest is encrypted using AES-256.
  • Passwords are hashed with a modern key-derivation function (Argon2 / bcrypt).
  • Access to production systems is limited to a small number of engineers, secured with hardware-key two-factor authentication, and audit-logged.
  • We run automated backups daily and test restores regularly.
  • In the event of a personal-data breach likely to result in a risk to your rights, we will notify the supervisory authority within 72 hours and notify you without undue delay where required.

11 Children's data

InRepply is not intended for users under the age of 16, and we do not knowingly collect data from anyone in that age group. If you believe a child has created an account, please contact us and we will delete the account and any associated data.

12 Changes to this policy

We may update this Privacy Policy from time to time. For any material change — a new processor, a new purpose for processing, or a significant change to your rights — we will email you at least 30 days before the change takes effect.

Smaller, clarifying edits are reflected by updating the 'Last updated' date at the top of this page.

13 Contact

For any privacy question, complaint, or data-rights request: email our privacy team. We read every message and respond within a few business days.

Controller: [COMPANY_LEGAL_NAME], registered office at [COMPANY_ADDRESS], Lublin, Poland.