Trust
What ReplyCircuit can touch — and what it can't
You are about to let software write to your CRM. That deserves a straight answer rather than a badge wall. Here is exactly what reaches us, where it is held, and what stays permanently out of reach.
What we always do
- Receive only the replies you forward to your private processing address
- Hold your HubSpot tokens server-side, never in the browser
- Write CRM changes into your own HubSpot portal, where they stay
- Keep an audit log of every action, so you can see exactly what changed and when
- Start every reply type in suggest mode, so nothing changes until you approve it
- Stop everything the moment you disconnect HubSpot or delete the workspace
What we never do
- Sign in to your inbox, or hold any mailbox credential
- Read mail you did not forward to your processing address
- Sell, share or rent your data to anyone
- Use your replies or contacts to train models for other customers
- Take a payment card — Paddle is the merchant of record, and card details never reach us
- Write to HubSpot fields we were not granted permission to write
We never touch your inbox
This is the design decision everything else rests on. ReplyCircuit has no mailbox connection, no IMAP login, no Google or Microsoft mail permission, and no way to browse your mail.
Instead, your workspace gets a private processing address on inbox.replycircuit.com. You either set it as the reply-to on your campaigns, or add one forwarding rule for the replies you want handled. Only what arrives at that address is ever seen.
If you stop forwarding, processing stops. There is no back door, because there is no front door.
How your HubSpot connection is held
Connecting uses HubSpot's official OAuth flow through our public app. You approve it inside HubSpot; we never ask for your HubSpot password, and there is nothing for you to copy and paste.
The access and refresh tokens are stored server-side in our database, are never sent to the browser, and are only read by the server code that performs an action you asked for. Tokens refresh silently, so the connection does not quietly expire mid-week.
You can revoke access at any moment from HubSpot itself, or disconnect from inside ReplyCircuit. Either one takes effect immediately.
The permissions we ask for, and the ones we deliberately don't
Required: read and write contacts and companies, and read and write contact properties. That is the minimum needed to fix a contact record and to store what a reply said.
Optional, and only if you grant them: read sequences (to see live enrolments), read and write deals (to log replies against the right deal), and communication preferences (to perform a real opt-out).
We do not request permission to create or edit sequences, to send email as you, or to reach your marketing assets. A portal that declines every optional permission still works — those features simply become guided manual steps instead.
What is stored, and for how long
Reply content is processed transiently to decide what the message is and what it calls for. What we keep is the audit trail: sender, subject, the classification, the action proposed, and whether you approved it.
Non-reply mail is never sent to the AI and is deleted automatically after 30 days. Completed reply records stay in your audit trail, while full email text is trimmed after 12 months.
Contacts, notes, deals and sequence changes live in your HubSpot portal — not in a second copy of your CRM somewhere else.
Account data is held in our hosted database in the United States. Ask for an export or a deletion and you get it; email hello@replycircuit.com and we act within a few business days.
Who on our side can see what
Access to production data is limited to the people who operate the service, is used only to investigate a problem you have reported, and is logged.
Inside your own workspace, access follows your team roles — a workspace member sees that workspace and nothing else. Every record is scoped to its workspace at the database level, not just in the interface.
Nothing changes until you say so
Every reply type starts in suggest mode. The proposed change waits in a review queue with the reply beside it, so you can see the evidence before you approve.
You switch a type to automatic once you trust it — one type at a time, at your pace, and reversible. The audit log records who approved what, so an automatic action is never a mystery.
Sub-processors
HubSpot — your CRM, acted on at your instruction. Paddle — payments and invoicing, as merchant of record. Lovable Cloud — hosting, database and the AI classification that reads a reply.
Each one processes only what it needs to run the service. We will tell workspace owners by email before adding a new sub-processor that handles reply content.
Reporting something
If you believe you have found a vulnerability, email hello@replycircuit.com with the details. We will confirm receipt, keep you updated while we fix it, and we will not pursue anyone who reports in good faith and does not access other customers' data.
Still need something answered before you connect?
Ask us directly, or start the trial and connect a sandbox portal first — nothing is charged, and every reply type starts in review mode.
No credit card required. Data stays in your HubSpot portal.