Skip to content
replywell.
DashboardReview sources

Your data, clearly explained.

Replywell is a draft-only proof of concept. It does not publish replies, take payments or activate a review-platform subscription.

Accounts and saved work

The workspace identifies its active storage mode. In local PostgreSQL pilot mode, account details, business preferences, reviews, drafts and refresh records are stored on this computer; local accounts do not send verification emails. When hosted Supabase is configured, these records are stored in its PostgreSQL database instead. Access is scoped to the signed-in owner. Google connection tokens are encrypted by the server and are not returned to the browser. Disconnecting removes the connection and its stored credentials, but retains your reviews, drafts and business-to-source identity. You can also revoke provider access in the provider’s account settings.

Private beta and account protection

Public registration is closed. Review tools require an approved, confirmed beta account. Sign-in and email recovery use Cloudflare Turnstile, which processes browser and network signals to detect automated requests. Supabase verifies the security token before authenticating. Replywell also limits repeated account requests using keyed hashes of email addresses and trusted network addresses; these counters contain no raw email or IP address and expire after two days. These protections do not send your password, business details or reviews to Cloudflare. Cloudflare privacy policy

Dashboard scores

Replywell’s blended score is calculated from loaded review records. Each numeric rating is divided by its native maximum, then all included ratings are averaged on a 0–100 scale. Unrated recommendations are excluded from this calculation. Matching review IDs on the same source count once; cross-platform syndicated reviews may still overlap. The score is not an official provider rating or a credit score. Monthly views group the loaded reviews by publication month, rather than reconstructing previous published scores.

Setup and browser storage

The setup questions keep entries in page memory. Choosing Continue to account places business preferences in this tab’s session storage so they can be carried into the workspace; they are removed there after saving. Passwords and provider keys are not stored in browser storage. Account sessions use HttpOnly cookies. Business name and location may appear in setup URLs.

Real-review test and preparation mode

The public test contains three attributed excerpts from a real Trustpilot listing, captured on 3 October 2026. It is a snapshot, not a live feed or a connection to that business; existing reply status is unknown. Its draft edits remain in page memory. The separate fictional walkthrough and preparation-mode reports also remain in page memory. Workspace imports, in contrast, are uploaded and saved once you sign in and confirm permission.

Provider access

Google Places supplies a limited public sample and no owner-reply status. Google Business Profile requires owner authorisation and API access; Google’s management scope is requested, but this application only reads review data. Other providers have their own access, storage and processing restrictions. Only use reviews covered by appropriate permissions and licences. Public visibility alone does not establish permission for bulk collection or AI processing.

Review research

The /research page sends your selected Trustpilot or Google Maps listing and sample limit to Apify when you confirm permission and choose Collect reviews. The service collects up to ten newest reviews. Google collections disable optional reviewer personal data; the application retains review text, rating, source link when supplied and owner replies. Trustpilot collections retain the public reviewer name supplied by the collector. Provider API tokens stay on the server. The account backend stores collection job details and successful samples separately from connected business reviews; these remain until the account is deleted or an operator removes them. Apify also stores runs and datasets under its own retention settings.

The latest research sample and replies you explicitly save are also kept in this browser profile’s local storage. Anyone using the same profile can read them. They remain until you choose Remove this saved sample or clear site storage; a successful new collection replaces the previous device sample and drafts. Removing the device copy does not delete the account or Apify copies. Failed collection keeps your previous device sample. Research is a small sample and does not establish an owner-authorised business connection or complete review feed. The selected review is sent to OpenRouter and its model provider only when you choose Generate. Replies are never published by research.

An optional local browser worker is retained for developer use through /api/research/browser. It visits the selected provider, which may set its own cookies, and keeps the session in memory for up to fifteen minutes. It is disabled by default and unavailable on hosted deployments.

Business demos

The /demo flow saves business details, confirmed listings, collection progress, returned samples and explicitly saved drafts under the signed-in presenter’s account. A demo requests up to 100 reviews per selected source. Google Places or a managed Google connection is used for lookup when available; public lookup and reviews can fall back to Apify. Trustpilot’s native API is preferred when configured. Customer account connection is optional for public collection. Business search details are sent to the selected lookup provider; the website domain identifies a suggested Trustpilot profile that you confirm. Reports remain until the account is deleted or an operator removes them. Other people with access to the presenter account can read them. Apify retains its own run and dataset copies. Demo review records are separate from workspace imports and do not automatically establish a connected customer account.

AI drafting

Generating a reply sends review text and rating, business name and tone to OpenRouter and its model provider. The saved workspace and business demo also supply services and the public contact email when provided. Reviewer names and source URLs are omitted; recognisable email addresses and UK mobile numbers are redacted from review text, which is not complete anonymisation. Provider routing requests providers marked as not collecting data; this is not a guarantee of zero retention. Drafts can be wrong and need human review. Loading prepared fictional examples makes no model request; regenerating does.

Daily checks and summaries

Background refreshes require configured provider connections and a deployed scheduler. Daily email summaries additionally require email configuration and your saved opt-in. They go to the account email, not the public customer-contact address. A failed refresh is recorded as a failure, not as a day with no updates. No active schedule or verified delivery is implied by enabling the preference alone.

Cookies and providers

No ads or analytics trackers are loaded. See the cookie and storage notice. Supabase, Google, OpenRouter and any configured email or review provider may process technical metadata under their own policies. The prototype needs an identified operator and contact details before a public customer launch.

Apify privacy · Supabase privacy · OpenRouter privacy · Google privacy

Your voice. A little less on your plate.
Privacy & dataCookie details