ReviewReply Chrome Extension Privacy Policy

Last updated: 10 April 2026

1. Introduction

ReviewReply ("we", "us", "our") operates the ReviewReply Chrome browser extension. This privacy policy explains how we collect, use, store, and share your data when you use our extension.

Contact email: supportreviewreply@gmail.com

2. Data We Collect

The ReviewReply extension collects the following user data:

  • Email address — collected via Google OAuth sign-in to create and authenticate your account.
  • Google review text — the text content of reviews displayed on your Google Business Profile reviews page, read from the page when you click "Generate Reply".
  • Reviewer names — the names of reviewers as displayed on your Google Business Profile reviews page.
  • Star ratings — the star rating (1-5) of each review.
  • Authentication tokens — access and refresh tokens stored locally to maintain your signed-in session.

3. How We Use Your Data

  • Review text, reviewer names, and star ratings are sent to our server at reviewreply.uk, which forwards them to the Anthropic Claude API to generate a personalised reply suggestion. This is the core functionality of the extension.
  • Email address is used to create your account, authenticate API requests, and send service-related communications.
  • Generated replies are saved to your account so you can view your reply history in the web dashboard.
  • Authentication tokens are used solely to verify your identity when making API requests to our server.

4. Data Storage

  • Authentication tokens are stored locally on your device using Chrome's chrome.storage.local API. This data never leaves your device except as an authorisation header in API requests to our server.
  • Account data, review text, and generated replies are stored on our server infrastructure provided by Supabase (PostgreSQL database hosted on cloud infrastructure). Data is encrypted in transit (TLS) and at rest.

5. Data Sharing

We share user data with the following third-party services, solely to provide the extension's functionality:

  • Anthropic (AI provider) — review text and reviewer names are sent to Anthropic's Claude API to generate reply suggestions. Anthropic processes this data according to their API terms and does not use it for model training.
  • Supabase (database and authentication provider) — account data and generated replies are stored in Supabase-hosted databases.
  • Stripe (payment processor) — if you subscribe to a paid plan, your payment information is handled entirely by Stripe. We do not store credit card details.

We do not sell, trade, rent, or otherwise transfer your personal data to any other third parties. We do not use your data for advertising purposes.

6. Data Retention

  • Generated replies and review data are retained in your account until you delete them individually or request account deletion.
  • Authentication tokens are refreshed periodically and can be cleared at any time by signing out of the extension.
  • Upon account deletion, all associated data (profile, replies, subscription records) is permanently removed from our servers within 30 days.

7. User Rights

You have the right to:

  • Access your personal data by viewing your account and reply history in the web dashboard.
  • Correct your personal data by updating your profile settings.
  • Delete your personal data by deleting individual replies or requesting full account deletion.
  • Withdraw consent by signing out and uninstalling the extension.

To exercise any of these rights, contact us at supportreviewreply@gmail.com.

8. Security

We implement appropriate technical and organisational measures to protect your data, including HTTPS encryption for all data in transit, row-level security policies in our database, and secure authentication via OAuth 2.0. However, no method of electronic transmission or storage is 100% secure, and we cannot guarantee absolute security.

9. Scope of Data Access

The extension only activates on business.google.com/reviews pages. It does not collect data from any other websites, does not track your browsing history, and does not run in the background on other pages.

10. Changes to This Policy

We may update this privacy policy from time to time. We will notify users of material changes by updating the "Last updated" date at the top of this page. Continued use of the extension after changes constitutes acceptance of the updated policy.

11. Contact

If you have questions about this privacy policy or our data practices, contact us at supportreviewreply@gmail.com.