Legal
Privacy policy
What Human Reply collects, why, who can see it, where it is kept and what you can ask us to do with it. Every section opens with the same thing in plain words.
Human Reply is a live chat for websites, answered by the site's own team from Telegram. Running it means holding conversations between our customers and their visitors, so this policy is mostly about those conversations: what we keep, who can see them, and how little we touch them.
1Who we are
In plain words
Human Reply is made by Hella Fast, LLC, a company in Delaware, United States. Our servers are in Frankfurt, Germany. Write to hello@send.humanreply.app with any question about this policy.
Human Reply is a service of Hella Fast, LLC, 131 Continental Dr, Suite 305, Newark, DE 19713, United States ("we", "us"). This policy covers the website at humanreply.app, the Human Reply plugin for Framer, the chat bubble our customers put on their websites, and the emails we send. It does not cover Telegram, Framer, Stripe or any other company's service, each of which has its own policy.
2Customers and visitors
In plain words
If you run a website with Human Reply on it, you are our customer. If you chat in a bubble on someone's website, you are a visitor: the site you chatted with decides what happens to that conversation, and we keep it on their behalf.
Two kinds of people meet in Human Reply, and the law treats them differently.
- Customers are the people and organisations with a Human Reply account, together with the team members who answer from their Telegram group. For a customer's own data, such as the account email and the billing details, we decide what is collected and why: we are the controller.
- Visitors are the people who chat in a bubble on a customer's website. The conversation, and everything in it, belongs to the customer. We store it and carry it on the customer's instructions and for nothing else: for visitors' data we are the processor, and the customer is the controller. Section 7 of our Terms of service is the agreement that binds us to that.
If you are a visitor with a question about a conversation, please ask the website you chatted with first. If they need our help to answer you, we help them.
3What we collect
In plain words
The least we can. From customers, an email address and what Stripe needs to bill them. From their team, the Telegram names and photos that visitors see. From visitors, the conversation itself and what they were looking at when they wrote. On our own website, Google Analytics counts visits and sets its cookies there. There are no advertising trackers anywhere, and no cookies on our customers' websites.
From customers
- Your email address. It creates the account and is where sign-in codes go. There is no password.
- Your site. The name of your Framer project and the address of the published site, which the plugin reports, and the settings you choose: colour, wording, business hours, your logo.
- Your bot. The token of the Telegram bot you create for the service, stored encrypted.
- Billing. Stripe takes your card and keeps it. We keep only the Stripe customer and subscription identifiers, the card's brand and last four digits, the billing email and the state of the plan.
From your team
- For each person who answers from your Telegram group: their Telegram user id, first name and username, their profile photo, which we copy so that visitors can see who is answering, their availability on the Desk board, and the replies they write.
From visitors
- The conversation: the messages and files sent in both directions, the name a visitor chooses to give, the contact they leave when they want the reply elsewhere (an email address, a phone number or a username), and a rating, if they give one.
- The context the team sees: the page the visitor is on (its address and title, and the item on it when the page is about one), the site that sent them there, how many times they have visited, their browser's language and the kind of device they are on.
- A token in the browser. The bubble keeps a random token in the browser's local storage so that the visitor finds their conversation again on the next page. It identifies the conversation, not the person, it is not a cookie, and nothing follows the visitor to other websites.
Automatically
- Our hosting provider keeps standard server logs, which include IP addresses, for a short time, to keep the service secure and to find faults. We do not build profiles from them.
- On humanreply.app, one cookie signs you in for 30 days and one lasts 15 minutes while a sign-in code is on its way. We use no advertising cookies.
- We also use Google Analytics to count visits to humanreply.app and to see which pages and buttons lead people to the plugin. It sets its own cookies on humanreply.app and records the pages you view, your approximate location from your IP address, and your browser and device; Google keeps that event data for two months. It runs only on our marketing, setup and sign-in pages: never on the dashboard, never in the plugin, and never in the bubble on our customers' websites. We use none of Google's advertising features. You can opt out with Google's browser add-on at tools.google.com/dlpage/gaoptout.
4What we use it for
In plain words
To run the service you asked for, to bill you, to write to you about your account and to fix problems. Nothing is sold, nothing is used for advertising, and no conversation is used to train anything.
We use the data above to:
- carry conversations between the bubble on your site and your Telegram group, keep their history and show them on your dashboard;
- show visitors who is answering and whether their message has been seen, when you switch those on;
- sign you in and keep your account;
- charge the plan and send receipts, through Stripe;
- send service emails: sign-in codes and notices about your account, your plan and changes to the service;
- keep the service running and secure, and find and fix faults;
- answer your questions and support requests;
- meet our legal obligations.
We do not sell or rent personal data, we do not use it for advertising, we do not profile visitors, and we do not use conversations to train any model or product.
5Who can see the conversations
In plain words
Your team, in your Telegram group and on your dashboard. We look only when the service needs it or you ask us to, we look at the least we need, and not for long.
A conversation is visible to the customer's team in their Telegram group and on their dashboard, and to the visitor in the bubble. Telegram carries the team's side of it under Telegram's own terms.
The people who run Human Reply can technically reach the database. We access conversations only to keep the service running, to investigate a problem you have asked us about, or when the law requires it. That access is limited to the minimum necessary and is temporary. Conversations are never read for any other reason and never used for anything else.
7Where it is kept, and for how long
In plain words
In Frankfurt, for as long as your account exists. Write to us and we delete it within 30 days.
All data is stored in Frankfurt, Germany, in the European Union. Conversations, settings and the team's details are kept for as long as the account exists, so that history stays available to the team and a returning visitor is recognised. When you ask us to delete your account, we delete its data within 30 days, and it leaves our backups within 30 days after that. Invoices and payment records stay with Stripe for as long as tax and accounting law require.
Server logs are kept for a short time and then discarded. The token the bubble keeps in a visitor's browser stays there until the visitor clears their browser data.
8The EU and the United States
In plain words
The data stays on servers in the European Union. The company is in the United States, so the little access we make from there is covered by the EU's standard contractual clauses, which are part of our terms.
Hella Fast, LLC is a United States company. Data is stored in the European Union, and the limited, temporary access described in section 5 can be made from the United States. For customers in the European Economic Area, the United Kingdom and Switzerland, that access is covered by the European Commission's standard contractual clauses, with the UK addendum and the Swiss adjustments where they apply. They are incorporated into section 7 of our Terms of service. Resend and Stripe process data in the United States under their own safeguards.
9Your rights
In plain words
Ask us what we hold about you, have it corrected, get a copy, or have it deleted. Email us and we answer within 30 days. In the EU and the UK you can also complain to your data protection authority.
Wherever you are, you can ask us to tell you what personal data we hold about you, to correct it, to give you a copy, or to delete it, and you can object to a use of it. Write to hello@send.humanreply.app. We may need to confirm it is you, and we answer within 30 days.
If you are in the European Economic Area, the United Kingdom or Switzerland, you have these rights under the GDPR and its equivalents, including the right to restrict processing, to data portability, and to lodge a complaint with your supervisory authority. If you are in California, you have the right to know, to delete and to correct, and to not be discriminated against for exercising them; we do not sell or share personal information as the CCPA defines those terms.
If you are a visitor, the site you chatted with is the controller of the conversation, so please ask them first; we help them answer, and if you write to us we tell them.
10Security
In plain words
Everything travels encrypted, bot tokens are encrypted at rest, and there are no passwords to leak: signing in is a one-time code sent to your email.
Every connection to Human Reply is encrypted. Bot tokens are encrypted at rest with a key kept outside the database. Signing in is a six-digit code sent to your email and valid for ten minutes, so there is no password to steal or reuse. Card details are entered on Stripe's pages and never touch our servers. Access to production is limited to the people who run the service.
No service can promise perfect security. If we learn of a breach that affects your data, we tell you without undue delay, and we tell our customers about any breach affecting their visitors so they can meet their own obligations.
11Children
In plain words
Human Reply is for businesses, not children.
Human Reply is a business tool and is not directed at children under 16. We do not knowingly collect personal data from a child. If you believe a child has given us data, write to us and we delete it.
12Changes to this policy
In plain words
When this policy changes, the new version is posted here with its date, and customers hear about any change that matters by email.
We update this policy when the service or the law changes. The current version is always at this address with its effective date. We email customers about changes that affect them at least 30 days before they take effect, unless the law requires a change sooner.
13Contact
In plain words
Email is fastest.
Hella Fast, LLC
131 Continental Dr, Suite 305
Newark, DE 19713, United States
hello@send.humanreply.app