repryntt

legal

Privacy Policy

Last updated: 2026-09-25

What we collect

Account information you provide directly (name, email), authentication metadata from Clerk (sign-in method, OAuth provider used), and Stripe payment metadata (billing email, subscription status, last 4 of card). We do not store full card numbers.

When you connect LLM provider API keys (OpenAI, Anthropic, etc.), we store them encrypted at rest. We never log or transmit keys in plaintext.

Usage telemetry: agent jobs you submit, model used, token counts (for your own usage dashboard). The inputs and outputs of each job, and the working memory your employees build for your company, are stored with your account so you can review, export and reuse the work. They are never used to train models.

Connected apps (Google, Microsoft, Meta, Intuit)

Connecting your own accounts is optional and one app at a time. When you connect one, you sign in on that provider's own page: we never see, ask for, or store your password. The access token is held by our integration provider, Nango, encrypted and filed against your repryntt account, so every request is scoped to your own connection.

What we request, and why:

  • Google Calendar (https://www.googleapis.com/auth/calendar.events) — to see when you are free and to create or move the appointments your AI books for you. Events only: we do not read or change calendar settings, sharing, or other calendars.
  • Google Business Profile (https://www.googleapis.com/auth/business.manage) — to read the reviews and questions left on your listing, reply to them as you, and update the hours and posts you ask us to keep current.
  • Microsoft 365 (offline_access, User.Read, Mail.Read, Mail.Send, Calendars.ReadWrite) — to read the thread an employee is replying to, send that reply from your own address, and book the meeting it agrees to. Reading is read-only: we do not edit or delete your mail. offline_access is what lets the work happen overnight without you signing in again.
  • Facebook and Instagram (pages_show_list, pages_read_engagement, pages_manage_posts, instagram_basic, instagram_content_publish) — to list the Pages you manage so you can choose one, publish the posts you approved to that Page and its linked Instagram business account. Meta asks for the engagement permission alongside posting; we do not collect your engagement data. We do not access your personal profile or your friends.
  • QuickBooks Online (com.intuit.quickbooks.accounting) — to read invoices, customers, payments and receivables aging so reminders go to the right customer for the right amount, and to send an invoice you already raised as that reminder. We do not create or alter ledger entries. No payroll or banking scopes are requested.

We do not sell data from connected apps, share it for advertising, or use it to train machine-learning models. It is used only to perform the work you asked for. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

You can disconnect at any time, directly from the provider (for example myaccount.google.com/permissions), without telling us — access stops immediately. A disconnect button in your repryntt dashboard is coming; until it ships, email hello@ai158z.com and we will disconnect the app for you. Data already pulled to do your work is deleted within 30 days of your asking us to delete it, and within 30 days of closing your account. The plain-language version of this section, app by app, is at repryntt.com/connected-apps.

Connected accounting platforms

When you connect an accounts system such as QuickBooks Online, we access only the records needed to operate the features you enable: invoices, customers, payments, and accounts-receivable aging reports. We use this data solely to prepare and send payment reminders on your behalf, and to report your receivables back to you inside Repryntt.

We do not sell it, share it for advertising, or use it to train machine-learning models. Access tokens are stored encrypted at rest. When you disconnect repryntt from inside the connected platform (in QuickBooks: Settings → Manage connected apps → Disconnect), the platform tells us and we revoke the token with them and delete our copy at once. You can also email hello@ai158z.com and we will disconnect it for you.

To draft a payment reminder we send the minimum necessary context to your connected language-model provider: the invoice number, amount, due date and age, the customer's business name, and prior correspondence about that invoice. We do not send full ledgers, bank details, or tax identifiers.

What we do NOT collect

We do not train models on your prompts, your employees' outputs, or the memory they build for your company, and we do not sell or share any of it. Those records exist so you can see and export the work; they are deleted with your account (see Data retention).

How we use it

To provide and operate the Service: authenticate you, run your agent jobs, deliver results, process payments, send transactional emails (billing receipts, account notifications).

To improve the Service: anonymous aggregate usage statistics (e.g., how many agent jobs ran today across all users).

LLM providers

How your prompts reach a model depends on how you run Repryntt. If you connected your own API key, we send your prompt to that provider using your credentials and nowhere else, and that data is governed by their privacy policy. On the included plan the intelligence is ours to provide: we send your prompts, and the connected-app content your employees work on, to OpenRouter, which routes them to the models we select. Today those are made by Z.ai (GLM), DeepSeek and Alibaba (Qwen), with Anthropic and xAI as fallbacks, which we call directly rather than through OpenRouter. We do not train models on your data.

Every request we send through OpenRouter carries two conditions of ours: zero data retention, so it can go only to a host that does not keep it after answering, and no data collection, so it never goes to a host that may store it or train on it.

OpenRouter sends each request to a company that hosts the model, which is not always the company that made it, and for everything we send on your behalf the hosts are ours to choose: only companies based in the United States or the European Union. For GLM-5.3 Flash — the plan's standard model, and the only one the Bot download's included AI uses — the request names its hosts, currently Sail Research, Novita, Baseten, Parasail, NextBit and Inceptron, tried in that order, and if none of them is available, OpenRouter does not send it to any other host. For any other model, only these companies may serve it: Amazon Bedrock, Azure, Baseten, DeepInfra, Fireworks, Google Vertex, Inceptron, NextBit, Novita, Parasail, Sail Research and Together. A model that none of them serves with zero data retention is not used for your requests. Z.ai, DeepSeek and Alibaba make models we use, but your requests never go to them.

Anthropic and xAI are not reached through OpenRouter, so the conditions above do not govern them: what we send them directly is handled under their own API terms, linked in the table below.

Custom employee faces. If you ask for a custom face for one of your employees, the description you type — a few words about how the person looks, at most 160 characters — is checked by our AI model, through OpenRouter as above, and then sent to xAI's image model, which draws the portrait. That request goes to xAI directly, under xAI's API terms. The portrait is kept with your company.

The plan's included AI on the Bot download

On the repryntt plan, the Bot you run on your own computer can think on the plan's included hours. When it does, the text of each request it sends the model goes from your computer to our API (api.repryntt.com), which passes it to OpenRouter and on to the model — today Z.ai's GLM, with no fallback to another model — and returns the answer. The Bot's memory, files and logins stay on your computer, not with us; what passes through is the text the Bot puts into a request, which can quote from them.

For each request we log the usage, never the content: your account, the device, the model, the token counts, the cost and how long it took — the figures your hours are billed from. The text of a request and of its answer is not logged or stored. The one exception is brief: so that a request the Bot has to resend is answered and billed once, its answer is held for ten minutes, sealed under a key only your Bot holds, and then it expires.

Those usage records are kept with your account's billing history while the account is open — they are what your hours meter reads — and are deleted with the rest of your account's data within 30 days of closing it (see Data retention).

If your Bot thinks on your own AI key, a model on your computer or a coding subscription instead, those requests go from your computer to that provider, or stay on it, and never pass through us.

Subprocessors

Where your data is processed: in the United States and the European Union. Every company below is based in one or the other — for the AI hosts, that is the rule that admits them.

These are the companies that process your data for us: what each one handles, where it is based, and its own privacy policy and, where it publishes one, its data processing agreement (DPA).

Subprocessors: each company, what it processes, where it is based, and its terms
Running the service
ClerkSign-in and account management: your name, email address and how you sign in.Based in United StatesPrivacy policy · DPA
StripePayments: your billing email, subscription and card details. We do not store full card numbers.Based in United StatesPrivacy policy · DPA
DigitalOceanOur API servers, database and file storage: your account, your companies and the work your employees do for them.Based in United StatesPrivacy policy · DPA
VercelHosts this website and your dashboard, and passes what you do in the dashboard on to our API.Based in United StatesPrivacy notice · DPA
ResendEmail: your licence and account notices, and the emails your employees send in your name.Based in United StatesPrivacy policy · DPA
TwilioPhone calls and text messages: it carries your employee's calls, turning the caller's speech into text for your employee and its replies back into speech, and its texts.Based in United StatesPrivacy policy · DPA
NangoConnected apps: holds the access tokens for the apps you connect, encrypted, and carries your employees' requests to them.Based in United StatesPrivacy policy · Terms and DPA
SentryError reports from our API: what failed and where. Request bodies are never included.Based in United StatesPrivacy policy · DPA
AI requests
OpenRouterRoutes the plan's AI requests, the text of each prompt and its answer, to the hosts below, under zero data retention and no data collection.Based in United StatesPrivacy policy · Terms
Sail ResearchHosts GLM-5.3 Flash, the plan's standard model: first in the order. May also serve other models.Based in United StatesPrivacy policy
NovitaHosts GLM-5.3 Flash: second in the order. May also serve other models.Based in United StatesPrivacy policy
BasetenHosts GLM-5.3 Flash: third in the order. May also serve other models.Based in United StatesPrivacy policy
ParasailHosts GLM-5.3 Flash: fourth in the order. May also serve other models.Based in United StatesPrivacy policy
NextBitHosts GLM-5.3 Flash: fifth in the order. May also serve other models.Based in SpainPrivacy policy
InceptronHosts GLM-5.3 Flash: sixth in the order. May also serve other models. Its data centre is in Finland.Based in SwedenPrivacy policy
Amazon BedrockAmazon Web Services' model hosting: may serve a model other than GLM-5.3 Flash.Based in United StatesPrivacy notice
AzureMicrosoft's model hosting: may serve a model other than GLM-5.3 Flash.Based in United StatesPrivacy statement
DeepInfraModel hosting: may serve a model other than GLM-5.3 Flash.Based in United StatesPrivacy policy
FireworksModel hosting: may serve a model other than GLM-5.3 Flash.Based in United StatesPrivacy policy
Google VertexGoogle Cloud's model hosting: may serve a model other than GLM-5.3 Flash.Based in United StatesPrivacy notice
TogetherModel hosting: may serve a model other than GLM-5.3 Flash.Based in United StatesPrivacy policy
AnthropicAI requests we send directly, not through OpenRouter, under Anthropic's API terms.Based in United StatesPrivacy policy · Commercial terms
xAIAI requests we send directly, not through OpenRouter, under xAI's API terms, including the description you type for a custom employee face, which its image model draws.Based in United StatesPrivacy policy

Data retention

We retain account data for as long as your account is active. Data pulled from connected platforms is retained for up to 90 days to support the workflows you have enabled, and is deleted when you disconnect the platform or close your account.

On account closure, personal and connected-platform data is deleted within 30 days, except where we are required to retain billing records for tax and accounting purposes. We retain upload audit records where abuse-reporting law requires it. You may request deletion at any time by emailing hello@ai158z.com; we close the account and delete its data within 30 days.

Your rights

From the dashboard you can revoke the API keys you connected. To get a copy of your account data, correct it, or have it deleted, email us and we will do it for you.

For any of these requests, email hello@ai158z.com. We'll respond within 30 days.

If you are a California resident, you have rights under the CCPA. If you are in the EU/EEA, you have rights under the GDPR. Same email handles those requests.

Cookies

We use strictly necessary cookies for authentication and session management. We do not use third-party tracking cookies for advertising.

Children

The Service is not directed to individuals under 16. We do not knowingly collect data from children.

Changes

What changed on 25 September 2026

  • A new section, The plan's included AI on the Bot download, on what passes through us when the Bot on your own computer thinks on the plan's included hours.
  • Every AI request we send through OpenRouter now requires zero data retention and no data collection, and goes only to hosts based in the United States or the European Union (see LLM providers).
  • Subprocessors is now a table of every company that processes your data for us: what each one handles, where it is based, and its privacy terms.

We will notify subscribers by email of material changes to this policy at least 30 days before they take effect.

Text messaging (SMS)

If you text our business number, or provide your phone number with consent on a booking or contact form, we may send you SMS messages: replies to your questions from our AI assistant (always identified as an AI, with human oversight) and appointment confirmations or reminders you requested. Message frequency varies with your conversation and appointments — typically a few messages per interaction, never recurring bulk messaging. Message and data rates may apply.

Mobile phone numbers and SMS opt-in data are never sold, rented, or shared with third parties or affiliates for marketing purposes. Reply STOP at any time to stop receiving messages, or HELP for assistance.

repryntt Link (Chrome extension)

repryntt Link lets your own repryntt use browser tabs you choose to share. While a tab is shared, the page's content and your actions in it are sent only to your own repryntt. That is on your own computer, or on a machine you connect over your private network. It doesn't go to repryntt's servers.

The extension never reads your cookies, saved passwords, or the contents of password and card fields. It never sees tabs you haven't shared. It stores one pairing token on your computer so it can reconnect, and "Unpair this browser" deletes it. We don't sell or share any of this, and we don't use it for advertising.

The full note for the extension — what it can do, what it cannot, and how to remove it — is at repryntt.com/extension, which is the privacy policy URL on its Chrome Web Store listing.

Contact

Privacy questions: hello@ai158z.com