Skip to content

Privacy

Version 2026-09-15.1. Operated by Alex Hunter, under the law of England and Wales.

Correspondence address: Suite 2, 68 Great Eastern Street, London EC2A 3JT.

General and data protection enquiries: privacy@replyr.co.uk. Reporting prohibited content or a rights complaint: report@replyr.co.uk.

This explains what re:plyr records about you, why, how long it is kept, and what you can do about it. Alex Hunter is the data controller for the purposes of the UK GDPR and the Data Protection Act 2018.

Scope

This policy covers people with an account and people who open a share link without one. It also covers anyone who visits the site, writes to the operator, or gives something towards the running costs. Where something applies only to some of those, it says so.

What is collected

Your account.

  • Your email address, which is how you sign in.
  • A display name, if you give one.
  • When the account was created and when you last signed in.
  • Your role, and whether the account is active or suspended.
  • That you confirmed you are 18 or over, when you confirmed it, and which version of the terms you accepted.
  • Sign-in links and sessions, stored only as cryptographic hashes. The operator cannot read your session token or reuse a sign-in link.
  • Recovery codes, stored only as cryptographic hashes. The operator cannot read them or tell you what they were. When each new set was made is noted as well, so no more than three can be made in an hour.
  • A change of address you ask for, with the new address, until it is cleared out as set out under How long it is kept.
  • Which roadmap items you have voted for. A vote is your account and the item, and nothing else: no text, no time you spent reading, and nothing shown to anybody. The public page shows a total and never who is in it.
  • The browser identification string attached to each session.
  • Which storage allowance the account is on, and when that started. Nothing is ever paid for it.
  • How much writing the account saved today and yesterday, as one number, and if it reached the limit, when. A single account cannot fill the database every member shares.
  • A one-way hash of the IP address the account was made from, so one person cannot open dozens in a day. The address itself is never stored. The hash is made with a secret key kept outside the database, so the database alone cannot turn it back into an address.

What you upload. Your images and the text you write about them, together with technical details of each file such as its size, dimensions, format and a checksum used to spot duplicates. Details a camera or app writes into a picture file, such as where and when a photo was taken, the device that took it and its owner's name, are removed when the picture is uploaded. Only what is needed to show the picture properly, such as which way up it goes and its colours, is kept. The service does not store the IP address a picture was uploaded from.

Your ad, if you write one. This is the one part of the service that is about you rather than about your fiction, so it is set out on its own. It holds what you type into it: a name to go by, your pronouns, your timezone, how you write, what you are looking for, the genres you like and refuse, your limits, and a way of contacting you. All of it is optional except a title. You can delete the whole page from the ad editor, except while the operator is withholding it.

The contact detail on your ad is not your sign-in address. It is a second one, held only because you typed it, used for nothing, and shown to anybody who opens the ad. Put an address there that you are happy for strangers to have.

Analytics. The service counts how it is used, on its own servers. Nothing about your visit is sent to an analytics company. It records the page visited, the site you arrived from, your country, and the type of browser, operating system and device. The page title is deliberately never recorded, and neither is anything you typed into a search or a tag.

Buttons and links you click, how far down a page you scroll and any error a page runs into in your browser are recorded as events, so the operator can see which parts of the tool are used and which are broken.

How a visit is counted without identifying you. No analytics cookie is set. Instead, your IP address and browser description are combined with a secret value that changes every day and turned into a one-way hash. That hash is what is stored; your address and your browser description are not. The day's secret value is deleted the following morning. A copy stays in the database's restore history, described under How long it is kept, for 30 days after that. Once it has gone from there, nothing the service keeps can turn a stored hash back into an address, whoever asks. The practical effect is that a visit today and a visit tomorrow cannot be connected to each other.

Share links are deliberately not reported in full. The unguessable token is removed in your browser before anything is sent, so a shared page is counted without the link itself ever being recorded.

Analytics runs on the public share pages as well. If someone sends you a link, opening it is counted, even though you have no account.

Cookies and local storage. One cookie is set by this site, and it holds your sign-in session. It is strictly necessary for the service to work and cannot be declined while using it. Cloudflare, which protects the traffic, sets two of its own for security: one that helps it tell people from bots, and one that holds the result of a check your browser runs when a page opens. Cloudflare says both are strictly necessary, that a fresh one is made for each site, and that it does not use them to follow anybody from site to site. There are no advertising, profiling or third-party tracking cookies, which is why there is no consent banner. The site also remembers two display preferences in your browser's own storage: whether the side panel is collapsed, and whether the setup checklist has already been celebrated. Neither of those leaves your device.

Your browser's per-tab storage holds a random number identifying this visit, which is sent with the analytics described above, so that several pages opened one after another can be counted as one visit rather than several. It is not a cookie, it is not tied to your account, it is discarded when you close the tab, and it is not readable by any other site.

While an editor has changes you have not saved, they are also kept in that tab's storage, so they can be brought back if you leave the page by accident. They are removed when you save or press Revert, when you sign out in that tab, and when this site asks whether to leave without saving and you choose to leave. Otherwise they are discarded when you close the tab. They do not leave your device.

Server logs. Cloudflare records ordinary request information, including IP addresses, in the course of delivering and protecting the service.

What you send through the contact form. Your name, your email address, what the message is about, and the message itself. If you happen to be signed in when you send it, the message is linked to your account. A one-way hash of your IP address is stored so the form cannot be used to send hundreds of messages. The address itself is never stored. The hash is made with a secret key kept outside the database, so the database alone cannot turn it back into an address.

Attempts to use a recovery code. A one-way hash of the IP address behind each attempt, so the codes cannot be guessed at. The address itself is never stored. The hash is made with a secret key kept outside the database, so the database alone cannot turn it back into an address. Nothing else about the attempt is kept: not the address, not the code, and not which account it was for.

How often a share link is opened. Each character, scenario and ad keeps a count of how many times its page has been opened and when it was last opened, so the person who made the link can see it. Nothing about who opened it is recorded: no address, no identity, no per-visit record.

Sensitive information

Some information gets extra protection in law. It covers anything revealing your health, ethnicity, politics, religion, trade union membership, sex life or sexual orientation, along with genetic and biometric data. The law calls it special category data. Almost nothing here is intended to hold any of it. Your ad is the exception, and it is dealt with below, under 'Your ad can hold this kind of information'.

Characters here are fiction. A made-up person is not you. Writing one, or drawing one, does not tell the operator anything about your own health, beliefs, ethnicity, politics or sex life, whatever the character is doing. Data protection law is about information relating to you.

What would be information about you is something like a photograph of yourself, a note about your own health, or a line in a file that says what you personally believe or who you are attracted to. Nothing outside your ad asks for any of that, and none of it is wanted in the rest of the service.

Your ad can hold this kind of information, because you put it there. Pronouns, the genres you will and will not write, and your own limits can each say something about you rather than about a character. Nothing makes you fill any of those boxes in, and you can leave every one of them empty.

Where an ad does hold that kind of information, it is held and published because you chose to publish it. In the words the law uses, you have made it public yourself. The operator works nothing out from it, does not profile you, and does not use it to sort or categorise you.

If information like that is uploaded anywhere else anyway, nothing is inferred from it either. Your content is not read to work out anything about you, it is not profiled, and it is not used to sort or categorise you. It is stored so the service works, and it is looked at where there is a reason to, as set out below.

Why, and on what basis

To provide the service. Your account and content are processed to perform the agreement between you and the operator. Basis: performance of a contract.

To publish your ad, if you write one. Storing it and serving it to whoever opens it is part of the same agreement, because publishing it is the whole of what you asked for. Basis: performance of a contract. Where the ad happens to carry information that gets extra protection in law, the condition relied on is that you made it public yourself. You can switch the page off or delete it from the ad editor, except while the operator is withholding it.

To keep the service secure and lawful. Sessions, sign-in records, the age declaration, and records preserved when investigating a report. Basis: legitimate interests, being the interest in preventing misuse, in protecting users, and in being able to show what a user was asked and when. Also legal obligation where one applies.

To keep the shared database working. If an account reaches the daily limit on how much it can save, the operator is sent a note naming it, so a script or a limit set too low can be dealt with. Basis: legitimate interests, being the interest in keeping the database every member shares from filling up.

To understand how the service is used. Basis: legitimate interests, being the interest in knowing which parts of the tool are used, measured in a way that sets no analytics cookie, profiles nobody, involves no third party, and cannot identify anybody once that day's secret value is gone, which is the next morning from the database itself and 30 days after that from its restore history.

To answer you. Messages sent through the contact form, or written to privacy@replyr.co.uk or report@replyr.co.uk, are processed so a reply can be sent, and kept as a record of what was asked. Basis: legitimate interests, being the interest in answering an enquiry and in being able to show how a report or a request was handled.

To keep tax records. A gift is taxable income, so the name and email address it was paid with stay in the operator's payment records. Basis: legal obligation.

To hold content that should not have been uploaded, for the period before it is found and removed. Basis: legitimate interests. Running the service and enforcing the rules that apply to it means content sits here until somebody sees it. It is not analysed and nothing is concluded from it.

You can object to processing based on legitimate interests. Say so at privacy@replyr.co.uk and it will be considered on its merits.

Who else is involved

Cloudflare hosts the application, the database and the image storage, sends the service's email, and delivers and protects the traffic. For that work it acts as a processor on the operator's instructions. Cloudflare also uses some of the same information for its own purposes, mainly keeping its network secure and improving Turnstile's bot detection. For those it is a controller in its own right, under its own privacy policy.

The sign-in, recovery and contact forms also use Cloudflare Turnstile, which checks that a person is using the form. It loads from Cloudflare when the page opens and looks at signals from your browser and device, and when the form is sent the service passes your IP address to Cloudflare to check the result.

Email to the operator goes to a mailbox held by Proton Mail. That includes every contact form message and anything you write to privacy@replyr.co.uk or report@replyr.co.uk. If an account reaches the daily limit on how much it can save, the operator is sent a note naming it by its email address. Proton Mail keeps backups of its own for up to 30 days, so an email deleted from that mailbox can sit in them for that long afterwards.

No payment processor receives anything about you from this service, because the service takes no payments and there is nothing here to buy.

If you choose to give something towards the running costs, you do that on a separate site that re:plyr does not operate, whose own privacy policy covers what it holds. Nothing about a gift is stored in the service, and nothing links one to your account here. The gift is paid into the operator's own payment account, which shows the operator the name and email address it was paid with, and any message left with it. The operator keeps the name and address with the tax records, and never matches any of it to an account. Your card details never come near this service.

Cloudflare and the operator's Proton Mail mailbox are the only places the operator sends your sign-in address. If you put a contact detail on your ad, everybody who opens the ad has it, because that is what the ad is for. That one is your own publication rather than a disclosure by the operator, and it is the only one. There is no advertising network, no data broker, no email marketing tool and no third-party analytics. If that list ever grows, this page changes first.

Content goes to one other place, and only when somebody sends it there. Running the /replyr command in Discord on a share link posts that character or scenario's fields into the Discord channel it was run in. Anyone holding the link can do that, which is the same access the link already gives them, and nothing about your account is sent with it.

The operator can see all accounts and all content, including yours, to administer the service and to enforce the Acceptable Use policy. Uploads may be reviewed at any time, so assume a person may look at anything you store here.

That does not mean everything is read. Nobody reads members' libraries as a matter of course. The operator may look through recent uploads to check them against the rules, and looks at particular content when there is a reason to: a report, a fault being investigated, a security question, or something the law requires.

Nothing is sold, rented, or shared for advertising, and nothing is used to train anyone's models. Information is disclosed to law enforcement or another authority where the law requires it, or where the operator considers it necessary to report apparently unlawful material.

Where information is held

The database and image storage, including the backup copy, are set up with a preference for Western Europe, and the analytics are in that same database. Cloudflare treats that as a preference rather than a promise, so it may hold them elsewhere. Cloudflare operates globally, so some processing, including support and security operations, may take place outside the United Kingdom.

Email to the operator is always held outside the United Kingdom, because Proton Mail stores mail only in Switzerland, Germany or Norway.

Email to the operator is covered by United Kingdom law, which approves sending personal information to Switzerland, Germany and Norway. Where Cloudflare moves information outside the United Kingdom, it is protected by the safeguards Cloudflare puts in place: its certification under the UK Extension to the EU-US Data Privacy Framework, and the EU standard contractual clauses with the United Kingdom's International Data Transfer Addendum where that certification does not reach.

How long it is kept

Your account and content, until you or the operator delete them.

Your ad, until you delete it. Switching it off stops the page working straight away and keeps what you wrote, so putting it back takes no more than switching it on. Neither reaches anybody who already copied what was on it, and a picture on it may be served from caches for up to 5 minutes afterwards.

An account nobody has signed into for 9 months may be closed and its content deleted, after at least 30 days' notice by email. This is set out in the Terms of Use. Signing in starts that period again.

Roadmap votes are kept until you remove the vote, the item is removed, or the account is deleted, whichever comes first.

Recovery codes are kept until you ask for a new set or the account is deleted. The note of when a set was made is cleared out within two days. A request to change your address expires after 30 minutes if it is not confirmed, and the request itself, with the address it named, is cleared out within two days either way.

Sessions expire 30 days after sign in, and are deleted when you sign out or when your account is suspended.

Sign-in links expire 15 minutes after they are sent, can only be used once, and are cleared out within two days.

Deleting a picture removes both the database record and the stored file. The backup copy below is the exception, and it goes when the account does.

The hashes of the IP address an account was made from, a contact form message was sent from and a recovery attempt came from are all cleared out within two days.

Each day's writing figure is cleared out within two days of that day ending.

Messages sent through the contact form, and the copy of each emailed to the operator, are kept until the operator deletes them, which is done once the enquiry is closed and nothing turns on keeping it. The same goes for anything written to privacy@replyr.co.uk or report@replyr.co.uk. A message forming part of the record of a report or a rights complaint is kept for as long as that purpose requires. Closing your account does not delete them, because a message can be part of the record of a report.

A note telling the operator that an account reached the daily limit on how much it can save is deleted from the mailbox within 30 days of arriving.

The record of a gift, for at least 5 years after the 31 January filing deadline for the tax year it was given in, which is what tax law requires. The payment account may keep its own history for longer, under its own policy.

A record of what the operator does to an account. Suspending, reactivating or closing an account writes a row saying what was done, to what, when and why. So do changing its role or storage allowance, resending a sign-in link, removing or restoring content, and sending a dormancy notice. These rows are kept after the account itself has gone, deliberately: the record of an action has to outlive the thing it was about, or the trail empties itself at exactly the moment somebody asks what happened. Each of those rows keeps the account's email address in plain text, for the same reason. You can ask for a copy of the rows about you, and your export lists what was done and when.

Records preserved in connection with apparently unlawful material are kept for as long as is necessary for that purpose, which may be longer than the account itself.

Analytics rows are deleted after 400 days. The daily secret that makes a visit countable is deleted the next morning and leaves the restore history 30 days later, so a row older than that cannot identify anybody.

There is a backup copy of uploaded files. Every picture is written to a second store when it is uploaded, so that a file lost to a fault here can be put back. Deleting a picture yourself leaves that copy in place, which is what makes the mistake recoverable. A picture the operator deletes under the Acceptable Use policy loses its copy too. Nobody can reach a backup copy through the service, and none is ever served to anybody.

Deleting your account removes the copies as well, in the same operation. Erasure means erasure, so the backup is not a way of keeping what somebody asked to have destroyed, and nor is the restore history below, which can no longer bring it back after 30 days. A copy the deletion cannot find, because of a fault or because the picture was deleted before the service began recording where each copy went, is removed when the backup is next checked.

The database keeps a restore history. So that a fault can be undone, the database can be put back to how it stood at any moment in the last 30 days. Anything deleted from it, a closed account included, can be brought back from that history for 30 days, and after that it cannot. It is used only to recover from a fault, nobody can reach it through the service, and stored pictures are not part of it.

Security

Sign-in tokens and session tokens are stored only as hashes. Traffic is encrypted in transit. Accounts are separated so that one cannot read another's content. Sign in is rate limited. The application sets a content security policy and related protections.

Share links are the deliberate exception. Anyone holding one can open the page. That is the point of them, and it means anything you share by link should be treated as published to whoever receives it.

No system is perfectly secure. Please do not put anything on this service that would be seriously harmful to you if it became public.

If a breach occurs that is likely to result in a risk to your rights, the Information Commissioner will be notified within 72 hours of the operator becoming aware of it, and you will be told without undue delay where the risk is high.

Your rights

You can ask to:

  • see a copy of the information held about you;
  • have inaccurate information corrected;
  • have information deleted;
  • restrict or object to how it is used;
  • receive it in a portable form; and
  • withdraw consent where consent is the basis being relied on.

You can see a copy, and delete it, yourself. Your account page has two downloads and a delete that removes the account, the content and the stored files. The data file holds your account, your writing and your ad if you wrote one, with a link to each picture. The archive holds the same with the pictures themselves, as long as the library fits in one archive. None of them needs a request or a wait, unless the account is suspended, because records are preserved while something is being looked into.

Write to privacy@replyr.co.uk. Requests are answered within 30 days. There is no charge unless a request is manifestly unfounded or excessive.

If you are not satisfied with the response you can complain to the Information Commissioner's Office at ico.org.uk, or 0303 123 1113.

Automated decisions

No decision producing legal or similarly significant effects is taken about you by automated means. Suspension and removal decisions are taken by a person.

Children

This service is not for anyone under 18 and is not directed at children. If the operator learns that an account belongs to someone under 18, it is closed and the information deleted, other than what must be kept.

Changes

This policy may change. Where a change is material, account holders are asked to accept the new version before continuing to use the service.