Legal

Security

ReplyScore is built so the browser never talks to the scan database. Payments stay with Stripe. Report links are unguessable tokens, not logins.

No accounts

There is no customer login. Your teaser and full report are reached through a tokenised URL emailed to you. Treat that link like a document: anyone who has it can open the report.

Database access

Scan tables use deny-all row-level security. The public site does not use an anonymous database key. Our servers read and write with a service-role key that never ships to the browser.

Payments

Card details are collected on Stripe Checkout. ReplyScore stores the Stripe session reference and payment status, not the card number. The merchant account is held by Reply Intelligence Group Ltd.

Abuse controls

We store a salted hash of the caller IP, not the raw address, to cap scans per hour and per day and to stop one visitor receiving another visitor's report token. External AI spend is capped per scan and per day.

What we do not do

We do not scrape consumer ChatGPT or Gemini sessions. Engine checks use official APIs (Anthropic, Perplexity, DataForSEO). The crawler identifies as ReplyScoreBot and obeys robots.txt. Details: bot identity and how we test.

Report a problem

Last updated 14 August 2026