Last updated: 2026-08-31
This Privacy Policy explains how Replai (“we”, “the App”) handles your information. Replai is an AI-assisted email client. We designed it to keep as much of your data on your device as possible; some features require sending data to the cloud, as described below.
| Category | What | Why |
|---|---|---|
| Email account credentials | IMAP/SMTP passwords or OAuth tokens for Google/Microsoft accounts you connect | To connect to your mailbox and send/receive email, and to deliver new-mail push notifications while the App is closed. Stored in the device Keychain. To power server-side new-mail detection: for password-based accounts, the app-specific mail password is also stored on our backend encrypted with AES-256-GCM; for Google/Microsoft accounts, short-lived OAuth access tokens are sent to our backend to maintain mail-notification subscriptions (we never receive your Google/Microsoft account password). Server-side credentials are erased automatically when you remove the account, sign out, or unregister your last device. |
| Email content | Message text, subjects, recipients, attachments of accounts you connect | Cached locally to display your mail. For cloud AI features you trigger (reply, summary, cloud translation, compose, form fill), the relevant content is sent to our AI processing provider to generate the result. |
| Subscription identity | A user identifier and, where available, name/email from Sign in with Apple, Google, or WeChat | To identify your subscription/entitlement and track usage across platforms. |
| Purchase & usage data | Subscription status, credit balance, and usage counts | To provide and meter paid features. Payment card details are handled by Apple; we never receive them. |
| Device & diagnostic data | Device push token, app version, coarse network reachability, sanitized error logs | To deliver push notifications and diagnose backend connectivity. Sensitive content is redacted from logs. |
| Contacts (optional) | Contact suggestions you allow | To help address emails and fill forms. Used on-device; only granted when you permit. |
| Voice input (optional) | Speech you dictate | Converted to text using Apple’s Speech framework (on-device where supported, otherwise Apple’s speech service). We do not store your audio. |
When you use a cloud AI feature, the content needed for that feature (e.g., the email you are replying to) is transmitted over an encrypted connection to the AI model provider that powers Replai, solely to generate your requested result. Local-only features (local translation, on-device speech, memory stored on device) do not transmit your content for AI processing. Cached AI results are stored on your device.
We share information only as needed to run the App:
We do not sell your personal information or use your email content for advertising.
| SDK | Provider & purpose | Data it may access |
|---|---|---|
| WeChat Open SDK | Shenzhen Tencent Computer Systems Co., Ltd. — used only to start WeChat sign-in and receive the authorization result. It is not initialized unless WeChat sign-in is configured in the build. | Device identifiers, network status, and whether WeChat is installed. See open.weixin.qq.com for Tencent’s developer terms and privacy documentation. |
Locally stored data remains until you delete it, remove the account, or uninstall the App. Content sent for cloud AI processing is used to generate your result and is not retained by us for other purposes. Push tokens and configuration data are retained while your installation is active. Server-side mail credentials (Section 1) are retained only while the account is connected on at least one of your devices, and are erased automatically when you remove the account, sign out, or unregister your last device.
Credentials are stored in the device Keychain; network traffic uses TLS. Mail credentials stored on our backend for push delivery are encrypted at rest with AES-256-GCM, with encryption keys held in a separate secret store; plaintext exists only transiently in memory to establish mailbox connections and is never written to logs. Configuration delivered by our backend is signed. No method of transmission or storage is 100% secure, but we take reasonable measures to protect your data.
Replai is not directed to children under 13 (or the minimum age in your jurisdiction). We do not knowingly collect data from children.
Your data may be processed in countries other than your own (including where our AI provider and cloud infrastructure operate). We rely on encryption and appropriate safeguards for such transfers.
We may update this Policy; material changes are reflected in the “Last updated” date.
Privacy questions or requests: hello@replai.email
最后更新:2026-08-31
本隐私政策说明 Replai(“我们”“本应用”)如何处理你的信息。Replai 是一款 AI 辅助邮件客户端,我们尽量将数据保留在你的设备本地;部分功能需将数据发送至云端,详见下文。
| 类别 | 内容 | 用途 |
|---|---|---|
| 邮箱账号凭证 | 你连接的账号的 IMAP/SMTP 密码,或 Google/Microsoft 的 OAuth 令牌 | 用于连接你的邮箱、收发邮件,并在应用未运行时投递新邮件推送。凭证存储于设备钥匙串(Keychain)。为实现服务端新邮件检测:口令类邮箱的专用密码会以 AES-256-GCM 加密后存储于我们的后端;Google/Microsoft 账号则向后端发送短期有效的 OAuth 访问令牌以维持邮件通知订阅(我们不会收到你的 Google/Microsoft 账号密码)。当你移除账号、登出或注销最后一台设备时,服务端凭证将自动抹除。 |
| 邮件内容 | 你连接账号的邮件正文、主题、收件人、附件 | 本地缓存用于显示邮件。当你主动触发云端 AI 功能(回复、总结、云端翻译、撰写、表单填充)时,相关内容会发送至为 Replai 提供支持的 AI 处理方以生成结果。 |
| 订阅身份 | 来自 Apple、Google 或微信登录的用户标识,以及(如有)姓名/邮箱 | 用于识别你的订阅/权益并跨平台统计用量。 |
| 购买与用量数据 | 订阅状态、credit 余额、使用次数 | 用于提供并计量付费功能。支付卡信息由 Apple 处理,我们不会接触。 |
| 设备与诊断数据 | 推送令牌、App 版本、粗粒度网络可达性、脱敏后的错误日志 | 用于推送通知与后端连通性诊断。日志中的敏感内容已脱敏。 |
| 通讯录(可选) | 你授权的联系人建议 | 用于填写收件人和表单,仅在你授权时于设备本地使用。 |
| 语音输入(可选) | 你口述的语音 | 通过 Apple 语音框架转为文字(支持时在设备本地,否则使用 Apple 的语音服务)。我们不存储你的音频。 |
当你使用云端 AI 功能时,该功能所需的内容(如你正在回复的邮件)会通过加密连接传输至为 Replai 提供支持的 AI 模型方,仅用于生成你请求的结果。纯本地功能(本地翻译、设备端语音、存于本地的“记忆”)不会为 AI 处理而传输你的内容。AI 结果缓存存储于你的设备。
我们仅在运行应用所必需时共享信息:
我们不会出售你的个人信息,也不会将你的邮件内容用于广告。
| SDK 名称 | 提供方与用途 | 可能获取的信息 |
|---|---|---|
| 微信开放平台 SDK(WeChat Open SDK) | 深圳市腾讯计算机系统有限公司——仅用于发起微信登录并接收授权结果;未配置微信登录的构建不会初始化该 SDK。 | 设备标识信息、网络状态、是否安装微信。腾讯的开发者条款与隐私说明见 open.weixin.qq.com。 |
本地存储的数据在你删除、移除账号或卸载应用前一直保留。发送给云端 AI 处理的内容仅用于生成结果,我们不为其他目的留存。推送令牌与配置数据在你的安装有效期内保留。服务端邮箱凭证(见第 1 节)仅在该账号仍连接于你的至少一台设备期间保留,当你移除账号、登出或注销最后一台设备时自动抹除。
凭证存储于设备钥匙串;网络传输使用 TLS。为推送而存储于后端的邮箱凭证以 AES-256-GCM 静态加密,密钥保存在独立的密钥管理服务中;明文仅在建立邮箱连接时短暂存在于内存,绝不写入日志。后端下发的配置经过签名。没有任何传输或存储方式是 100% 安全的,但我们采取合理措施保护你的数据。
Replai 不面向 13 岁以下(或你所在司法辖区的最低年龄)儿童。我们不会有意收集儿童数据。
你的数据可能在你所在地以外的国家/地区处理(包括我们的 AI 提供方与云基础设施所在地)。我们对此类传输采用加密及适当保障措施。
我们可能更新本政策;重大变更将体现在“最后更新”日期。
隐私相关问题或请求:hello@replai.email