Privacy and security
This page summarises how Review Reply - Smart AI Responses handles data. It matches the published privacy policy of Reputation Review Reply, published by Shrikrishna Gavhane through Reputation Systems.
The extension stays disconnected until you start the RR sign-in and pairing flow. It has one purpose, and it handles data only to provide that purpose.
Data
What does Review Reply send, and when?
When you invoke an RR action, click a recognized review, deliberately select review text, or paste review text into the extension's own panel and ask for a draft, the extension sends a request to the Reputation Systems API. That request contains the review content you deliberately chose, the displayed or typed reviewer name and rating, your selected reply settings (the reply language and tone, plus an optional manager name and title), and a platform label.
The platform label is the review hostname, or the fixed label manual for a pasted review. On the pasted-review path the extension reads no page address at all. The extension does not collect your general browsing history. Its content script runs on the approved review hosts so it can identify a supported hotel-review surface, but review information is transmitted only after a deliberate user action.
Authentication and operational information — the session identifier, request time, model identifier, usage amount, cost attribution, response status, and network information such as an IP address that may appear in security logs — is used to validate access, enforce session expiry and rate limits, prevent abuse, secure the service, and diagnose failures.
Transfer and storage
Where is review data sent and stored?
Review information and reply settings are sent over HTTPS to rr-api.reputationsystems.ai only to generate the response you requested. The private extension-session credential, its session identifier, the connection time, and your reply settings are stored in chrome.storage.local inside your Chrome profile, and access is restricted to trusted extension contexts. Short-lived pairing state is stored in chrome.storage.session and expires after ten minutes.
The private credential is never made available to webpages and is sent only by the extension's background service worker. The RR website receives only the SHA-256 hash of the private credential, not the credential itself. On the server, the RR service stores a one-way SHA-256 hash of the credential together with the account identifier, extension identifier, session status, and session times. Expired session records are removed by an automated cleanup process.
The RR application does not intentionally store review text, reviewer names, manager signature fields, or generated replies in its database after a generation request completes. Chrome profile-local extension storage is not a hardware-backed secret vault, so protect access to your browser profile and disconnect the extension if you believe the credential or profile has been compromised.
Lifecycle
What happens when you disconnect?
An extension session expires after 30 days and can be renewed through the same pairing flow. Disconnecting asks the RR service to revoke the session and then removes the locally stored credential and connection data. An expired, revoked, or unauthorized session is also removed when detected, and the next request is rejected.
Uninstalling the extension removes its profile-local extension storage through Chrome. You can always change reply settings in the extension panel, disconnect to revoke the current session, or uninstall to remove local data.
Providers
Who processes the data?
Reputation Systems uses contracted hosting, network, database, security, and model-inference providers to operate the service. Current providers include Amazon Web Services for application infrastructure and Salad Technologies, Inc. (SaladCloud) for model inference. Groq, Inc. may process the same request when configured as the fallback model provider. Review information is provided to model-inference infrastructure solely to generate the requested reply.
These providers may process information only on behalf of Reputation Systems and for the service purpose. Information may also be disclosed when required by law, when necessary to protect users or the service from fraud, malware, or abuse, or as part of a merger, acquisition, or sale of assets subject to applicable notice and consent requirements. Employees and contractors are not permitted to read review content except with your specific consent for support, for security or abuse investigation, when required by law, or after the data has been aggregated and anonymised.
Commitments
What Review Reply will never do
- No selling. Reputation Systems does not sell extension user data and does not transfer it to advertising platforms, data brokers, or information resellers.
- No advertising or lending use. Information is not used for personalised advertising, retargeting, creditworthiness, or lending.
- No posting without you. Generated replies stay editable, and supported native posting workflows require your explicit final action before a reply is submitted.
- Limited Use. Use and transfer of information received through the extension complies with the Chrome Web Store User Data Policy, including the Limited Use requirements. Extension data is used only to provide or improve the extension's single user-facing purpose and related security, reliability, and operational functions.
Full policy
Where can you read the full policy?
The binding policy is the published Reputation Review Reply privacy policy. Read it at rr.reputationsystems.ai/privacy.html. This page is a summary and does not replace it. For privacy questions or account-related data requests, email contact@multisystems.ai.
The published policy may be updated only when the extension's data practices, service providers, or applicable requirements change. The effective date above identifies the latest version.
Get started
Reply with Review Reply, on your terms
Install the extension, connect your RR account, and keep the final click in your hands.