RepSelf · operated by Logos Fortuna

Privacy Policy

RepSelf lets people set up an AI representative ("Rep") that talks to visitors on their public rep.page and, only with the owner's approval, performs actions such as sending a calendar invitation. This policy describes what we store and why. Last updated: 30 September 2026.

What we store

Conversations: messages exchanged with a Rep, so the Rep's owner can read and follow up on them. Contact details a visitor chooses to share (such as an email address) are stored for that purpose.

Owner accounts: the owner's name, email address and Rep configuration.

Sources: files, web links and product details an owner adds to their Rep's Knowledge. We store the files and the text read from them, and prepare short summaries so the Rep can answer questions. Anything an owner lets their Rep read may be told to visitors. Scanned PDF pages are read with text recognition (OCR); web pages that load their content with JavaScript are opened in a browser to be read. A source and everything read from it are deleted when the owner deletes it.

Forms: when a visitor agrees to go through an owner's form (for example a job application), we store their answers and any file they upload for the period the owner chose — the visitor is told this period before the first question, 180 days by default — and then delete them automatically. Uploaded files are checked for malware on a server we operate, are never read by the Rep, and can be downloaded only by the owner. If the owner sets scoring rules, answers are checked against those rules automatically; the result is visible only to the owner, and nothing is decided or sent because of it.

Connected accounts (e.g. Zoom, Microsoft, Google): when an owner connects an account, we store the OAuth tokens needed to act on their behalf. Tokens are encrypted at rest and are used only for the features the owner turned on, such as creating a meeting the owner approved.

Calendar availability: if an owner turns on Availability, we read when their connected calendar (Microsoft, Google, or a private calendar link the owner adds) is busy, so their Rep can offer visitors a few free times. A calendar link is stored encrypted and is never shown again after it is added. We read only busy and free time ranges — never event titles, descriptions, attendees or locations — and we do not store them: they are read when needed and discarded. Visitors see at most a few free slots, never the calendar itself.

Google user data: RepSelf's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We request only the free/busy calendar scope and the account's email address; the data is used solely to offer the owner's free times to visitors of their Rep. Busy time ranges are never passed to anyone; only the few free times offered to a visitor appear in the Rep's conversation, which is generated with an AI model provider. Google data is never sold, used for advertising, or used to train AI models.

WhatsApp: an owner can add a WhatsApp number to receive notifications from their Rep, reply to it and approve its proposed actions there. We store that number, whether it has been verified, the messages exchanged with it and the delivery status WhatsApp reports. When a Rep asks a visitor to verify a phone number, we send a one-time code to that number on WhatsApp and store the number and the result with the conversation. We message a number only after its owner has added and verified it, or when a visitor asks for a code.

Operational records: action requests, approval decisions and usage counters, kept as an audit trail for the owner.

What we do not do

We do not sell personal data. We do not use conversation content or connected-account data for advertising. Visitors are always told they are talking to an AI representative.

Processors

The service runs on Cloudflare infrastructure. Rep replies are generated by third-party LLM providers, which receive conversation content to produce a reply. When an owner connects Zoom, Microsoft or Google, those APIs are called to carry out approved actions or, with Availability on, to read busy times. WhatsApp messages are delivered through the WhatsApp Business Platform operated by Meta, which receives the phone numbers and message content needed to deliver them. Documents an owner adds may be sent to AI model providers to prepare summaries and, for scanned pages, to Mistral AI for text recognition; web pages may be read with Cloudflare's browser service. Files visitors upload are scanned on our own server and are not sent to any third party.

Retention and deletion

Connected-account tokens are deleted immediately when the owner disconnects the account on the panel, or when we receive a deauthorization notice from the provider. An owner can remove their WhatsApp number on the panel at any time; we then stop messaging it and delete the stored number. Conversation and audit records are kept while the owner's account is active. Sources are kept until the owner deletes them. Form answers and uploaded files are deleted automatically when the period shown to the visitor ends, or earlier if the owner deletes the submission or the form.

Your rights

You can ask us at any time to access, correct, export or delete the personal data we hold about you, and to object to or restrict its processing. This applies to owners and to visitors who left information in a conversation or a form alike. To exercise any of these rights, email repself@logosfortuna.com — we verify the request and respond within 30 days. If you believe we have not handled your data correctly, you can also complain to your local data protection authority.