Legal

Privacy Policy

Last updated: September 17, 2026

RLY is a self-hosted AI reply agent for WhatsApp and Telegram. This policy explains exactly what data is collected, where it lives, and who can see it. No legalese — just the facts.

1. What We Collect

When you run RLY, the following data is generated and stored:

  • WhatsApp and Telegram message content — both incoming messages and AI-generated outgoing replies
  • Contact names and phone numbers of people who message you
  • Session and activity logs (timestamps, which contacts were replied to, which AI model was used)
  • Your dashboard login credentials — specifically a bcrypt-hashed password; your plaintext password is never stored
  • Configuration settings you enter in the dashboard (tone preferences, reply rules, AI model selection)

We do not collect payment information, real-name identity documents, or any data outside of what RLY needs to function.

2. How Your Data Is Stored

RLY is self-hosted. Your message history, contacts, and logs live on your own VPS server — not on any server owned or operated by RLY or Pankaj Soni.

All data is stored in a database on the server you provision and control. This means:

  • You own the hardware and access credentials for that server
  • RLY (the operator) has no routine access to your message data
  • Backups, encryption at rest, and server security are your responsibility as the operator

The dashboard at agent.replylikeyou.com is a web interface that connects to your own backend. It does not store your messages on its own servers.

3. Third-Party AI Providers

To generate replies, RLY sends message content to one of the following AI APIs (whichever you configure):

  • DeepSeek V3 — operated by DeepSeek AI
  • Claude API — operated by Anthropic
  • OpenAI GPT-4o — operated by OpenAI

When a message arrives that requires a reply, the relevant conversation context is sent to your chosen AI provider to generate a response. This means message content leaves your server and is processed by a third-party API.

Each provider has its own privacy policy and data retention practices. We recommend reviewing them:

RLY does not control how these providers handle data once it is transmitted to them.

4. How We Use Your Data

The data RLY collects is used only to operate the service:

  • Message history is used to provide context to the AI so replies sound like you
  • Contact data is used to identify who is messaging and apply per-contact rules
  • Session logs are used to display activity in your dashboard and for debugging
  • Login credentials are used to authenticate access to your dashboard

Your data is not sold, shared with advertisers, or used for any purpose beyond running your personal AI agent.

5. Data Retention

Because RLY is self-hosted, you control retention. Message history and logs are kept until you manually delete them or wipe your server database. There is no automatic expiry by default.

If you stop using RLY and decommission your server, all data stored on that server is deleted with it. RLY does not hold a copy elsewhere.

6. Your Rights

Because your data lives on your own server, you have full control over it at all times:

  • Access — you can query your own database directly at any time
  • Deletion — you can delete individual records or wipe the entire database
  • Export — your data is in a standard database format; you can export it anytime
  • Portability — since you host it, there is no lock-in

If you have questions about data that may have been sent to a third-party AI provider, contact that provider directly using the links in section 3.

7. Security

RLY implements the following security measures on its end:

  • Dashboard passwords are hashed with bcrypt — plaintext passwords are never stored or logged
  • Dashboard access requires authentication; sessions expire on logout
  • All connections to the dashboard use HTTPS (TLS via Let's Encrypt)

The security of your VPS — including firewall rules, SSH access, and database access controls — is your responsibility. We strongly recommend restricting SSH access and keeping your server updated.

8. Children's Privacy

RLY is not intended for use by anyone under the age of 16. We do not knowingly collect data from minors. If you believe a minor is using RLY, please contact us so we can investigate.

9. Changes to This Policy

If this policy changes in a material way, we will update the "Last updated" date at the top of this page. We may also post a notice on the RLY website. Continued use of RLY after a policy update means you accept the revised terms.

We will not make changes that retroactively reduce your privacy rights without clear notice.

10. Contact

RLY is operated by Pankaj Soni as an individual. If you have questions about this privacy policy or how your data is handled, reach out via WhatsApp — the contact link is on the RLY homepage.