Privacy Policy
Last updated: 2026-07-27
1. Who we are
ReviewWise AI ("we", "us") provides an AI reply-assistant product consisting of a web dashboard and a browser extension. This policy explains what data we collect, why, and how you can control it. Contact: [support@yourcompany.com].
2. What we collect
- Account data: email address, hashed password, workspace name, language preference.
- Business content you provide: business profile, tone/rules, imported documents, pasted text, crawled web pages, and knowledge items you approve.
- Usage data: login timestamps, generated/accepted replies, and basic audit logs (which action happened, when, for which workspace).
- Browser extension data: the visible text of a page you are actively replying to, sent only to generate a reply suggestion, only on domains you explicitly allow.
3. How we use it
- To authenticate you and keep your workspace separate from other customers'.
- To generate on-brand reply suggestions using only the knowledge you have approved.
- To operate billing/plan limits and prevent abuse (e.g. rate limiting).
- To send you account-related email (password reset, security notices) — see Section 6.
We do not sell your data. We do not use your business content to train models shared with other customers.
4. Data storage & retention
Data is stored in [MongoDB / vector database — describe hosting location and provider]. You may configure data-residency options (bring-your-own database) where available. You can request deletion of your account and associated data at any time (Section 7).
5. Sharing with third parties
We use the following categories of subprocessors: cloud database hosting, and (only if you enable them) a large-language-model provider and a payment processor. List your actual vendors here, e.g. [MongoDB Atlas], [OpenAI], [Stripe].
6. Email communications
We send transactional email (password reset, security alerts) necessary to operate your account. You cannot opt out of these while your account is active. Marketing email, if any, will always include an unsubscribe link.
7. Your rights
Depending on your location, you may have the right to access, correct, export, or delete your personal data. To request this, contact [support@yourcompany.com]. We aim to respond within [30] days.
8. Security
Passwords are stored using salted bcrypt hashing. Session tokens are stored as one-way hashes; only you hold the raw token. We apply rate limiting to authentication endpoints and restrict cross-workspace data access.
9. Changes to this policy
We will post updates here and adjust the "Last updated" date above. Material changes will be communicated by email or an in-app notice where required by law.