RawReplyopen the app →

Privacy

Last updated June 11, 2026

RawReply has two sides: a chat product, and the Caption & Roast tools (where you drop a screenshot and get captions or comebacks). They handle your data differently — the chat is account-based, the photo tools are anonymous and disposable. Both are covered below. It's short.

What we collect

  1. Your email address and name, from Google when you sign in. We never see or store your Google password — the sign-in happens between your browser and Google. We get back an email + display name and that's it. We don't request access to Gmail, Drive, Contacts, or anything else.
  2. The messages you send and the responses you get back. Stored on our server so you can come back to a chat later and so we can hand the conversation to the AI on your next turn. Not used for anything else. Not sold. Not used to train any model.
  3. Usage events — page views, button clicks, whether a response failed, how long it took. Used to figure out what's broken and what people use. Not tied to your chat content. Your email is hashed (irreversibly) before any of this leaves our backend, so the analytics tool sees a pseudonym, not you.
  4. Memory — facts the system extracts from your chats. When you mention something the assistant should remember (your role, your project, a preference, a decision), a small reflection step writes that fact to a memory store so the next chat can use it. You can see every fact, edit it, and delete it from /settings/memory. Memory is per-account; nobody else sees it. Old facts auto-decay after 90 days of no use. Sensitive facts you don't want remembered: delete them from the memory page, or just don't mention them — memory only stores what you bring up in conversation.
  5. Projects — folders for related chats. If you create a project, the project name, your custom instructions, and per-project memory facts live alongside the chats inside it. Projects are private to your account. Delete the project to remove everything inside (chats move back to the main list; project memory + instructions are wiped).
  6. Files you upload to a project. Used to ground replies inside that project (a kind of long-term context the assistant reads when relevant). Your file is chunked + embedded so the assistant can search it; the original file is kept so you can re-download it. Files are per-project — deleted when the project is deleted, or individually via the project view. Not shared, not used for training.
  7. Locale signals from your request — your IP-derived country (from Cloudflare, which routes our traffic) and your browser language preference. We use these to decide whether the Caption & Roast tools should lean into Hindi/Hinglish humor or stay in American/British English by default. The signals are read on each request, not stored alongside your account, and aren't shared with anyone outside the providers below.

Where it goes

To make the product work, the things above are shared with:

  • Anthropic — the company that makes Claude, the AI model that writes the replies. Your messages are sent to Anthropic to generate the response. Anthropic's policy: anthropic.com/legal/privacy.
  • AWS Bedrock — used as a backup model when Anthropic is rate-limited. Same situation as above, just a different provider. AWS's policy: aws.amazon.com/privacy.
  • PostHog — receives the hashed usage events. Does not receive your chat content. Their policy: posthog.com/privacy.
  • Sentry — receives error reports when the site crashes. Email is hashed before it gets sent. Their policy: sentry.io/privacy.

Photos you upload (Caption & Roast)

The Caption and Roast tools work differently from the chat product — no account needed, and we treat your uploads as disposable.

  • Your photo is sent to AWS Bedrock's vision model to read the image and generate captions or roasts. It is NOT used to train any model. Most photos are compressed in your browser before they ever reach our server.
  • If you don't tap “share,” the photo isn't stored. It exists only for the few seconds it takes to generate your options, then it's gone.
  • If you DO tap “share,” we store that one photo plus the caption so the share link works. Shared cards auto-delete after 7 days — like a story.
  • Shared cards are public. Anyone with the link can view the card, and unlike shared chats, card pages CAN be indexed by search engines (the share loop is a discovery surface by design). Don't put anything on a card you wouldn't want public. They expire after 7 days regardless.
  • Comments on cards are anonymous and disappear with the card. No accounts, no usernames. Hard-blocked content is stopped server-side; anything else can be reported.
  • About other people in your screenshots: if a screenshot contains someone else's messages, face, or personal info, that goes through the same pipeline. Only upload screenshots you're comfortable processing — and think twice before making a card public with someone else's info in it.

What we don't do

  • We don't sell your data to anyone. There's no ad network, no resale partnership, no data broker — just the four providers above, all of which need your data to do their job.
  • We don't use your chats or photos to train any model. RawReply doesn't train its own LLM, and the providers above don't use your messages for their model training either when accessed through their APIs (you can verify this in their policies).
  • We don't track you across the rest of the web. PostHog is configured for first-party analytics on rawreply.com only.

How to delete your data

Self-serve options:

  • One chat: hover any chat in the sidebar → the kebab (⋮) menu has Delete.
  • A project (and everything inside it — instructions, files, project-scoped memory): open the project, kebab menu → Delete. Chats inside move back to the main list; memory + files are wiped.
  • Memory facts: visit /settings/memory to see every fact the system has stored about you, edit individual entries, or delete them one-by-one.

For full account deletion (removes your email + every chat, project, file, and memory fact), email privacy@rawreply.com and we'll do it within 48 hours. A self-serve account delete button is on the roadmap.

Sharing your chats

When you click “share” on a chat, we mint an opaque URL like rawreply.com/s/<random-token>. Anyone with that URL can view the chat. If you delete the chat, the share link breaks. The shared URLs aren't listed in our sitemap and are excluded from search-engine indexing — they spread only through links you share yourself.

Cookies

One httpOnly session cookie called ember_session, set after Google sign-in, so the next page load knows you're signed in. No third-party cookies. No advertising cookies.

Children

RawReply isn't intended for users under 13. If we find out an account belongs to someone under 13 we'll delete it. The Caption & Roast tools don't require an account, so we can't verify age there — but the same rule applies: it's not built for under-13s, and we'll remove any reported card that involves a minor.

Changes

If we change what we collect or where it goes, we'll update the date at the top of this page and post a note in the notes. Material changes that affect existing accounts get an email too.

Contact

privacy@rawreply.com. If you don't hear back within a couple of days, assume the email got stuck and try again — there's a real person on the other end.

Privacy — RawReply