Privacy Policy
ReplyTide is an independently operated YouTube comment automation service operated by Radhe Software Solutions ("we", "us"). This policy explains what data we collect, why, how long we keep it, and the rights you have over it — whether you are a creator using ReplyTide or a viewer who received a link through a creator's campaign. We've tried to write it in plain language, because a privacy policy you can't understand protects nobody.
1. Who this covers
Availability and localization focus: ReplyTide intends worldwide paid availability with no operator-selected country block. Its initial localized commercial outreach and support focus on Japan and South Korea. Public resource links and online service features are accessible globally while operated from Ontario, Canada, and dedicated localized support and operations may expand to other regions over time.
- Creators — people who sign in with Google and connect a YouTube channel.
- Resource visitors — people who open a creator's public resource page. They may optionally submit an email for a requested delivery copy. Opening the page does not require a comment, like, subscription, or email address. For any optional delivery email, the creator generally determines the delivery purpose and we process it on the creator's behalf.
2. YouTube API Services & Google user data
ReplyTide uses YouTube API Services. By using ReplyTide you also agree to the YouTube Terms of Service, and Google's handling of your data is described in the Google Privacy Policy.
- What we access: your basic Google account email address via the Google OAuth scope, and your YouTube channel details (channel ID, channel display name, avatar image), the list of videos on your channel, and comments on your videos via the YouTube Data API. Display names and avatars stored in ReplyTide come from your connected YouTube channel profile rather than a general Google profile name scope.
- What we store: your channel details, OAuth access and refresh tokens (encrypted at rest), and limited comment data needed to evaluate and record authorized replies. YouTube API-derived comment data is refreshed or deleted within 30 days and is scheduled for cleanup when authorization is revoked.
- What we do with it: authenticate your account, operate the YouTube features you configured, and send essential account notices. We do not use Google or YouTube API data—including the Google profile email or channel name—as our promotional contact list, we do not sell it, and no humans read restricted API data except for security, legal compliance, or with your explicit consent.
- Revoking access: you can disconnect ReplyTide at any time from your Google security settings or by deleting your account in the dashboard, which also revokes our token.
Limited Use disclosure: ReplyTide's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
3. Information we collect
- Creator account data: name, Google account email, YouTube channel ID/name/avatar, contact email (if provided), subscription tier, lifecycle-email delivery status, and optional SMTP settings you configure for lead delivery (SMTP passwords are encrypted at rest).
- Optional marketing contact: a preferred name and email address that you enter separately, plus the opt-in request, email-confirmation, consent, and unsubscribe timestamps and notice version. We do not activate marketing from a prefilled Google profile address.
- Campaign data: your keywords, reply templates, uploaded files or links, and campaign settings.
- Resource-access data (processed for the creator): the requested campaign and timestamps, plus an email address and delivery status only when a visitor asks for an email copy. An optional address is purpose-limited to that requested delivery and does not create marketing consent. Historical YouTube identifiers/comment text may remain briefly in legacy or reply-audit records until the YouTube-data retention sweep removes them.
- Technical data: IP address, browser type, and dashboard activity logs, used for security, fraud prevention, and platform health.
- Website usage measurement: aggregate, cookieless statistics about our public marketing pages — page path, referring site, and which calls to action are used. These events are collected by our own server, not by a script in your browser, and are forwarded to our analytics provider. Your IP address and browser user-agent are used only in transit, to derive a rotating daily counter that distinguishes one visit from another; neither is stored by us or by the provider, no cookie or advertising identifier is set, and the result cannot be traced back to you or joined to your ReplyTide account.
We do not collect passwords (sign-in is Google OAuth only), payment card numbers, CVCs, or advertising identifiers. Paid checkout is hosted by Stripe. To provide and reconcile subscriptions, we store Stripe customer/subscription identifiers, checkout-session, price, and event identifiers; plan, status, cancellation setting, billing-period dates, and the date paid access first began. Stripe, not ReplyTide, processes card details.
4. Why we process it (legal bases)
- To perform our contract with you — operating campaigns, posting replies, storing leads, and sending essential welcome, security, billing, and account-status notices (GDPR Art. 6(1)(b)).
- Legitimate interests — securing the platform, preventing abuse, improving the product, and measuring aggregate website usage so we can tell which pages help people and which do not (Art. 6(1)(f)). We chose a cookieless method that creates no persistent identifier, which is why this measurement needs no consent banner.
- Consent — marketing emails to creators begin only after a separately entered address confirms the emailed double-opt-in link; we record the request and confirmation, and consent can be withdrawn anytime in Settings or from any marketing message (Art. 6(1)(a)). A resource visitor's optional email submission requests one delivery copy only; it is not consent to future marketing by the platform or creator.
- Legal obligations — responding to lawful requests (Art. 6(1)(c)).
5. Sharing — and what we never do
We do not sell or share personal information for advertising, in the meaning of the California Consumer Privacy Act (CCPA/CPRA), and we never have. We disclose data only to: (a) infrastructure providers that host the service, bound by data-processing obligations; (b) Stripe, which processes paid checkout, subscriptions, invoices, and fraud prevention under its own privacy terms; (c) our contracted platform email-delivery provider for account and consent-based marketing messages; (d) a provider you configure for your own lead delivery; (e) our analytics provider, which receives only the aggregate, cookieless page events described above and is contractually barred from using them for advertising or from building a profile of any visitor; and (f) authorities, when legally compelled, and only to the extent required.
6. Retention & deletion
- Creator account, campaign, billing-reference, and delivery-contact data is retained while the account is active, subject to deletion requests and legal obligations described here.
- YouTube API-derived comment/viewer data is refreshed or deleted within 30 days. Failed or unprocessed records also have a bounded cleanup deadline rather than being retained indefinitely.
- Lifecycle-email records retain message type, delivery state, timestamps, and errors for reliability and compliance; email content is generated when sent rather than stored in the outbox.
- Delete your account: an account-deletion request removes the ReplyTide account data used to operate your profile, channels, campaigns, leads, comments, and sessions. Google revocation, uploaded-object deletion, and Stripe cancellation are then tracked in a privacy-minimized cleanup job with automatic retries. That job keeps only the information needed to complete or evidence the cleanup (such as an internal request reference, processor-cleanup status, and encrypted processor reference while it is pending). Stripe may retain transaction and invoice records where legally required. We may also retain limited security, fraud-prevention, or legal-compliance evidence where applicable law permits or requires it.
- Export everything: the dashboard provides a full export of your campaigns, leads, and activity logs at any time.
- Viewers may request deletion of optional resource-delivery lead data through our verified self-service flow, or contact us or the creator who ran the campaign for other privacy requests.
7. Your rights
European Union / UK (GDPR): where applicable under local law, you have the right to access, rectify, erase, restrict, or object to processing of your personal data, the right to data portability, the right to withdraw consent at any time, and the right to lodge a complaint with your local supervisory authority.
California (CCPA/CPRA): where applicable under local law, you have the right to know what personal information we collect, to delete it, to correct it, and to opt out of sale or sharing (we do neither). We will never discriminate against you for exercising these rights.
Canada (PIPEDA): you may access and correct your personal information and withdraw consent, subject to legal or contractual restrictions. Marketing email is sent only with express consent, per CASL, and every message includes an unsubscribe mechanism.
Japan and South Korea: as the initial localization-focus countries, we handle personal information in accordance with this policy and applicable privacy requirements, including requests for access, correction, deletion, and withdrawal of consent through the channels below. The Japanese Personal Information Protection Commission identifies the APPI as the framework it supervises; local-language legal guidance may be required for particular processing activities.
Where these specific regional statutes do not apply, we voluntarily honor equivalent requests for data access, correction, deletion, and consent withdrawal where reasonably practicable. To exercise any right: use the in-dashboard export/delete tools, use the viewer deletion request for optional resource-delivery lead data, or email privacy@replytide.co. We respond within the period required by applicable law.
8. International transfers
ReplyTide is operated from Ontario, Canada. Personal information may be processed outside your country or region by the service operator and by the providers used to host the service, process payments, deliver email, store uploads, and protect the service. Before worldwide paid production processing begins, this policy must be updated with the actual provider name, recipient country or region, processing purpose, categories of information, applicable safeguards, and retention information for each relevant transfer. Do not rely on the service for a production personal-data transfer until that publication is complete.
9. Security
OAuth tokens and SMTP credentials are encrypted at rest. Production browser sessions use server-backed opaque random tokens (HttpOnly, SameSite=Lax, Secure), while short-lived workflow tokens use signed payloads. A production deployment must serve personal-data traffic over HTTPS; non-production environments must not be used for real personal data. Access to production data is limited to the operator. No system is perfectly secure — if a breach affects your data, we will assess, contain, document, and notify affected people and authorities when applicable law requires.
10. Children
ReplyTide is not directed at children. You must be at least 18 years old to create an account. We do not knowingly collect data from children; if you believe a child has provided us data, contact us and we will delete it.
11. Changes to this policy
If we change this policy materially, we'll update the date above and notify active creators by email or an in-dashboard notice before the change takes effect. Continued use after notice means acceptance.
12. Contact
Privacy questions, rights requests, or complaints: Privacy Officer, Radhe Software Solutions (privacy@replytide.co · +1 (249) 564-0044). The service operator is Radhe Software Solutions. Postal notices may be sent to: Radhe Software Solutions (ReplyTide), 118 David Drive, Ottawa, ON K2G 2N8, Canada. If you're in the EU/UK and unsatisfied with our response, you may complain to your local data protection authority.