Legal
Security
ReplyScore is built so the browser never talks to the scan database. Payments stay with Stripe. Report links are unguessable tokens, not logins.
No accounts
There is no customer login. Your teaser and full report are reached through a tokenised URL emailed to you. Treat that link like a document: anyone who has it can open the report.
Database access
Scan tables use deny-all row-level security. The public site does not use an anonymous database key. Our servers read and write with a service-role key that never ships to the browser.
Payments
Card details are collected on Stripe Checkout. ReplyScore stores the Stripe session reference and payment status, not the card number. The merchant account is held by Reply Intelligence Group Ltd.
Abuse controls
We store a salted hash of the caller IP, not the raw address, to cap scans per hour and per day and to stop one visitor receiving another visitor's report token. External AI spend is capped per scan and per day.
What we do not do
We do not scrape consumer ChatGPT or Gemini sessions. Engine checks use official APIs (Anthropic, Perplexity, DataForSEO). The crawler identifies as ReplyScoreBot and obeys robots.txt. Details: bot identity and how we test.
Report a problem
Security issues: hello@replyintelligencegroup.co.uk. Data rights: privacy@replyscore.co.uk.
Last updated 14 August 2026