SECURITY
Security
StarReply has user accounts. What it stores, who processes it, and what it will never do with it.
What it stores
- Your account: the email address you sign in with, and the locations and review profiles you connect
- The reviews the agent reads, the replies it drafts and every decision you make on them — approved, edited, killed — because that record is what makes the kill window provable rather than asserted
- Your voice profile: what the agent learned about how you write, built from the replies you approved
- Anonymous usage analytics — page views and clicks. Form inputs are masked in session recordings
Who processes it
- Supabase authentication and the database holding your locations, reviews and reply history. https://supabase.com/privacy
- Stripe takes the payment for a paid plan and holds the card details — no card number ever reaches StarReply. https://stripe.com/privacy
- Google Business Profile where your reviews are read from and your approved replies are posted, under the access you granted. https://policies.google.com/privacy
- PostHog anonymous product analytics, proxied through this domain. https://posthog.com/privacy
- Vercel serves this site and holds its access logs. https://vercel.com/legal/privacy-policy
What is true of this product in particular
- The agent never posts a reply to a low-rated review on its own, in any mode. That branch runs before the mode is read, so it cannot be configured away.
- An approved reply is STAGED, not sent. The publisher will not pick it up before the kill window has elapsed, so a killed reply was never published — not published and then deleted.
- There is no password on this product. Sign-in is a link to your email address, so there is nothing to reuse or leak.
- The plans are PRO at $5/month and CHAIN at $15/month. There is no free plan and no trial. The live demo is open with no account and no card. Payment is Stripe Checkout — the card is entered on Stripe's own page and no card number ever reaches StarReply. A build gate fails this page if it names no payment processor while the repository has a checkout route.
Reporting a vulnerability
Write to security at the address on the contact route and a person answers. There is no bounty programme and no queue.