Privacy Policy

Last updated: 20 July 2026

This Privacy Policy explains how Replova Labs Private Limited ("Replova Labs", "we", "us", "our"), operating the OutreachAI platform (accessible via the Replov PaaS), collects, uses, stores, and protects your personal and business data in compliance with the Digital Personal Data Protection Act, 2023 (DPDP Act) and other applicable Indian laws.

1. Information We Collect

1.1 Account Information

When you create an account via Replov, we receive your name, email address, and authentication credentials (OAuth tokens from Google or GitHub). We do not store passwords directly — authentication is handled by Replov's identity service.

1.2 Workspace & Business Data

You provide your company name, description, products/services, and target audience to configure outreach campaigns. This data is stored in your workspace and used solely to personalize your AI-generated outreach content.

1.3 Lead Data

Lead information is sourced from publicly available business directories (Google Places API) or uploaded by you via CSV/Excel files. This may include business names, phone numbers, email addresses, websites, and addresses. For bulk calling, you provide contact phone numbers and optional metadata (name, company).

1.4 Communication Data

When you use OutreachAI to send emails, SMS, WhatsApp messages, or make voice calls, we store:

  • Message content, templates, and scripts you create
  • Delivery status and engagement metrics (opens, replies, call duration)
  • Call recordings and transcripts (for AI voice calls via Bolna AI)
  • Extracted data and summaries from AI voice conversations

1.5 Usage & Billing Data

We track feature usage (searches, emails sent, calls made, SMS count) for billing purposes. Transaction records are maintained for your Replov wallet charges.

1.6 Technical Data

Standard server logs including IP addresses, browser type, access timestamps, and API request metadata.

2. How We Use Your Data

  • Service delivery: Running outreach campaigns, making AI voice calls, sending emails/SMS/WhatsApp
  • AI personalization: Using your company profile to generate tailored outreach scripts and messages
  • Billing: Tracking usage against plan quotas and deducting from your Replov wallet
  • Analytics: Providing campaign performance dashboards and call analytics
  • Service improvement: Debugging errors, monitoring system health, and improving features
  • Legal compliance: Responding to lawful requests from authorities, maintaining audit trails

3. Third-Party Data Sharing

We share data with third-party service providers strictly for service delivery:

ProviderPurposeData Shared
Bolna AIAI voice calls & batch callingPhone numbers, call scripts, voice config
PlivoTelephony infrastructurePhone numbers, call routing
Google (Places API)Lead discoverySearch queries, location data
ZeptoMail / User SMTPEmail deliveryRecipient emails, message content
MSG91SMS deliveryPhone numbers, message content
Meta (WhatsApp Cloud API)WhatsApp messagingPhone numbers, message content
Anthropic (Claude)AI segmentation & classificationLead data for scoring, reply classification
SupabaseDatabase hostingAll application data (encrypted at rest)

We do not sell, rent, or trade your personal data to any third party for marketing purposes.

4. Data Storage & Security

  • All data is stored in encrypted databases (AES-256 at rest) hosted on Supabase infrastructure
  • API keys and sensitive credentials are encrypted using application-level encryption before storage
  • All data transmissions use TLS 1.2+ encryption
  • Row-Level Security (RLS) policies ensure workspace-level data isolation
  • Access to production systems is restricted to authorized personnel only

5. Data Retention

  • Account data: Retained while your account is active, deleted within 90 days of account closure
  • Lead data: Retained while your workspace is active; you can delete individual leads or campaigns at any time
  • Call recordings: Stored for 90 days unless you delete them sooner
  • Billing records: Retained for 7 years as required by Indian tax and accounting regulations
  • Server logs: Retained for 30 days

6. Your Rights Under DPDP Act 2023

As a Data Principal under the DPDP Act, you have the right to:

  • Access: Request a summary of your personal data and how it is processed
  • Correction: Request correction of inaccurate or incomplete personal data
  • Erasure: Request deletion of your personal data (subject to legal retention requirements)
  • Grievance redressal: File a complaint with our Data Protection Officer
  • Nominate: Nominate another person to exercise your rights in case of death or incapacity

7. Children's Data

OutreachAI is a B2B platform intended for business use. We do not knowingly collect personal data from individuals under 18 years of age. If you believe a minor's data has been submitted, contact us immediately.

8. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be notified via email or an in-app notification at least 15 days before they take effect.

9. Contact Us

For privacy-related queries, data access requests, or to exercise your DPDP rights:

  • Data Protection Officer: Replova Labs Private Limited
  • Email: privacy@replov.com
  • Address: Replova Labs Private Limited, India