Privacy Policy
Last updated: October 05, 2026
1. Who we are
Reputee AI (reputee.ai) helps teams monitor how AI answers mention and recommend their companies and products. This policy explains how we handle personal data when you visit our website, contact us or use the application.
The data controller is Jakub Różycki, Łokietka 5, 30-010 Kraków, Poland. NIP: 6772461810; VAT-EU: PL6772461810; REGON: 388353367. For privacy questions or rights requests, email [email protected].
2. Information we process
- Account and authentication data: email address, name, GitHub account identifiers and profile information made available during sign-in, authentication tokens and session records.
- Organisation data: organisation names, memberships, roles and invitations, including invited users' email addresses.
- Monitoring inputs and evidence: company profiles, names, domains, aliases, competitor information, personas, saved questions, provider responses, citations, analysis results, run history and usage records. Business information can include personal data, particularly for sole traders or where a question or response names an individual.
- Enquiries and support: your name, email, company website, message and subsequent correspondence.
- Technical data: connection and request information, such as IP addresses, browser information and security logs, where recorded by our infrastructure.
- Billing data: subscription status, payment references, contact and invoice details. Stripe processes payment-card details; we do not need to store your full card number to manage your subscription.
- Website analytics: visits, page interactions, device/browser information and identifiers collected by Google Analytics.
We receive account information from GitHub when you sign in, information from you and your organisation's authorised users, and responses from AI providers when checks run. Do not submit sensitive personal data, credentials or confidential third-party information in monitoring inputs.
3. Purposes and legal bases
We process data under the GDPR on the following bases:
- Contract performance (Article 6(1)(b)): creating and managing your account, delivering monitoring and analysis, handling your service requests and administering subscriptions where you are the contracting individual.
- Legitimate interests (Article 6(1)(f)): providing the service to an organisation's authorised users, responding to business enquiries, protecting accounts and infrastructure, preventing abuse, resolving disputes and maintaining the service. We balance these interests against your rights.
- Legal obligations (Article 6(1)(c)): tax, accounting and other statutory requirements.
- Consent (Article 6(1)(a)), where required: optional tracking and promotional communications. Reading this policy, signing in or agreeing to our Terms is not consent to optional tracking or marketing.
Submitting an enquiry does not subscribe you to a mailing list. Information needed for account creation and service delivery is necessary to provide those functions; optional enquiry fields can be left blank.
4. Cookies and Google Analytics
The application uses essential authentication and security cookies to keep you signed in and protect sessions. Blocking these may prevent sign-in or other essential functionality.
The landing page uses Google Analytics to measure website visits and interactions. Google may process device information, identifiers and usage events and use analytics cookies. The current landing-page integration loads Google Analytics without an on-site opt-in banner or preference centre. We do not represent continued browsing as consent or claim that an opt-in control is available.
You can block cookies through your browser or use Google's Analytics opt-out add-on. These controls do not replace any consent we are legally required to obtain. Google's processing is also explained in Google's Privacy Policy.
We do not currently use Microsoft Clarity or advertise a session-recording integration.
5. Service providers and recipients
We disclose information as needed to provide the service, not by selling account information:
- OVHcloud: hosting and infrastructure, which may process application data and connection information.
- Google Analytics: landing-page analytics, including usage and device information and identifiers.
- FormSubmit: delivery of website enquiries, including the name, email, website and message you submit, together with technical information handled by that service.
- Stripe: Pro subscription payments, payment references, billing and invoicing information, and payment details supplied to Stripe.
Authentication and AI processing are separate from website analytics:
- GitHub: authenticates users and exchanges the account information and authentication data needed for sign-in. Signing in does not itself grant Reputee access to your repositories.
- OpenAI and Anthropic: receive saved questions and any context included in a monitoring or question-generation request. The information sent depends on the selected provider and feature.
- TypeSafe: receives recorded responses and relevant company and question context when recommendation analysis is enabled. This is used for recommendation and sentiment interpretation, not website analytics.
We do not send account email addresses or billing records to AI providers as part of ordinary monitoring requests. However, prompts, company context or provider responses may themselves contain personal data. Avoid including such information unless you have authority and a lawful basis for its processing. Provider-side data use and retention depend on the applicable service terms and configuration; we do not promise that every provider has zero retention or excludes every request from training.
Authorised people within your organisation can access its shared workspace data. We may also disclose information to advisers or authorities where necessary to comply with law, protect legal rights or resolve disputes. We use appropriate contractual arrangements where required; some recipients act as independent controllers for their own purposes.
6. International transfers
Some providers may process data outside the European Economic Area, including in the United States. We do not promise that all processing or backups are EU-only. Where a restricted transfer requires safeguards, the applicable mechanism must be an adequacy decision, a valid certification under an applicable adequacy framework, or appropriate safeguards such as Standard Contractual Clauses. Contact us for information about the safeguards applicable to your data.
7. Retention and deletion
- Account and monitoring data: kept while needed for your active account and service history. Following a verified deletion request, we delete the relevant data from active systems within 30 days, except for justified legal retention. An individual user cannot authorise deletion of another customer's organisation data.
- Enquiries: retained for up to 12 months after the last substantive contact, unless needed for an ongoing customer relationship or a legal obligation or claim.
- Server logs: retained for up to 30 days, unless a specific security incident or legal requirement justifies longer retention.
- Backups: deleted data can remain in backups for up to 90 days before expiry. Backup copies are not used for ordinary service delivery; if restored, applicable deletion requests must be reapplied.
- Accounting and legal records: retained for the periods required by applicable law, or as necessary to establish, exercise or defend legal claims.
Cancelling Pro does not automatically delete your account or organisation. Email us to request deletion. External providers' own records and independently controlled data may be subject to their own lawful retention rules; contact us for assistance with requests concerning data we control.
8. Your rights
Subject to the conditions in the GDPR, you may request access, correction, erasure, restriction and data portability. You may object to processing based on legitimate interests, and withdraw consent at any time where processing is based on consent. Withdrawal does not affect processing that was lawful before withdrawal.
Email [email protected] to exercise your rights. We may need proportionate identity verification. We normally respond within one month; where the GDPR permits an extension, we will explain it within that month. Statutory requests are generally free, subject to the GDPR's exceptions for manifestly unfounded or excessive requests.
You may complain to the Polish supervisory authority, UODO (Urząd Ochrony Danych Osobowych), or another competent supervisory authority. Current contact details are available at uodo.gov.pl.
9. Security and incidents
We use technical and organisational safeguards appropriate to the risks, including encrypted connections, account authentication and access controls. No online service is completely secure.
Where required by GDPR Article 33, we notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of a personal-data breach. Where Article 34 requires notification to affected individuals, we notify them without undue delay. These are distinct obligations with different thresholds.
10. AI analysis and automated decisions
The service analyses AI responses about companies and products. It is not intended to make decisions about individuals that have legal or similarly significant effects within Article 22 GDPR. AI-generated sentiment or recommendation analysis is interpretation, not a verified fact about a person or company.
11. Age and changes
The service is intended for adults aged 18 or older. If you believe a child has provided personal data, contact us.
We may update this policy as our practices or legal requirements change. Material changes will be communicated through the service or email as appropriate. An update does not create consent where separate consent is required.
12. Contact
Jakub Różycki, Łokietka 5, 30-010 Kraków, Poland. Email: [email protected].
See also our Terms of Service.