Privacy
What the demo keeps, and why
Last updated 2026-10-04
Firstreply is a portfolio demo. This page describes how the demo behaves; it is not legal advice.
The short version
- Firstreply is a portfolio demo. Please use the synthetic demo leads, not real people’s details.
- It only processes leads that were sent to it. It never contacts anyone who did not write first.
- It does not sell data, show ads, or train models on what you enter.
What is stored
For your account: your name, email address, organisation name, and a session cookie that keeps you signed in. For your workspace: your rubric, voice and offer text, availability rules, forms and webhook tokens.
For each lead: the fields sent with it (name, email, company, message and any custom fields), the summary enrichment produced, the score and its reasons, the message thread, offered slots and any meeting booked. Everything is scoped to your organisation in the app’s Postgres database.
What enrichment reads
When a lead arrives from a company email address, Firstreply fetches that company’s public homepage, without running scripts, with an eight-second limit, and only where robots.txt allows. It keeps the page title, description, headings and a short text excerpt. Free-mail domains such as Gmail are skipped. It does not look up people on social networks or buy data from brokers.
Model providers
Scoring, drafting and reply reading send the lead’s message, the enrichment summary and your workspace settings to a hosted language model (Groq, with Google Gemini as a fallback). Free tiers of these services may use inputs to improve their products, which is one reason the demo asks for synthetic data only. Every call is logged in your workspace with the model, prompt version, token counts and time taken.
By default outgoing email goes to an in-app outbox and is not delivered. Where delivery is switched on, mail is sent through Resend. Inbound replies in the demo are pasted into the Demo Inbox or simulated, and simulated replies are labelled as such.
Payments and analytics
Billing uses Stripe in test mode, so no real card data reaches this app and no money moves. The site uses Vercel Analytics for aggregate page views, without advertising cookies.
Deleting your data
To have your account and workspace removed, open an issue on the GitHub repository and it will be deleted. See also the terms.