1. Who is responsible for your data
Futuristic SRL is the data controller for JoyReply accounts and the service data described here. You can contact us at privacy@joyreply.com for privacy matters and contact@joyreply.com for product support.
When a creator connects a social Page, that creator remains responsible for the relationship with their audience. JoyReply processes Page and conversation data on the creator's instructions so the service can work.
2. Data we handle and where it comes from
We collect information you give us, information produced while you use JoyReply, and information received from services you choose to connect.
- Account and workspace details, language, role, settings, support messages, and security events.
- Connected Page or profile identifiers, encrypted access tokens, permissions, posts, comments, replies, reactions, media context, and available insights.
- Setter program profiles, qualification rules, saved booking links, conversation history, contact details a lead chooses to provide, stop or no-contact state, and booking-link handoff state.
- Knowledge sources, approved website pages, uploaded notes or documents, brand examples, and crawl records.
- Studio requests, clarifying answers, uploaded images or videos, generated or edited assets, review decisions, voice choices, project state, credit records, and provenance metadata.
- Billing-profile details, server-issued quotes, checkout and consent records, payment and invoice status, credit purchases and usage, cancellations, withdrawal statements, refund requests, correction documents, and delivery receipts. JoyReply does not receive or store your full card details.
- Calendar drafts, planned or scheduled posts, selected Page, publishing state, and growth or audience signals when the platform makes them available.
- Device, browser, session, request, audit, error, abuse-prevention, and diagnostic data needed to secure and operate the service.
3. Why we use it and our legal bases
We use only the data needed for the purpose at hand. The legal basis depends on the feature and your relationship with us.
| Purpose | Typical legal basis |
|---|---|
| Create and secure an account; provide connected-Page, Inbox, Setter, Studio, Calendar, Growth, and support functions | Contract or steps requested before a contract |
| Prevent abuse, investigate failures, protect accounts, keep audit records, and improve reliability | Our legitimate interests, balanced against your rights |
| Send optional product or marketing messages | Consent, or another basis allowed by applicable electronic-communications law |
| Keep accounting, legal, compliance, or dispute records | Legal obligation or legitimate interests |
| Use optional device access or non-essential storage in the future | Consent, where required |
5. Setter and automated conversations
Setter is a restricted feature, not part of ordinary account or workspace access. JoyReply's founder grants access to a named user and workspace and separately approves activation for a verified Page, programme and booking link. A delegate cannot grant access or approve changed authority. The access grant and operational activation are separate controls.
An approved Setter assignment can qualify people who ask about its programme and share only the saved booking link when appropriate. JoyReply must not invent programme facts, discounts, availability, or a confirmed booking.
A request such as stop, do not contact me, or an equivalent clear refusal closes the automated conversation. When the system cannot continue safely, it should stop rather than keep pushing the person. We do not use Setter conversations to make decisions that produce legal or similarly significant effects about the person.
6. Studio, uploads, Calendar, and publishing
Studio processes your requests and reference files to create or edit images, videos, voiceovers and music. My library is personal: workspace membership alone does not let someone else list, preview, download, reuse or delete your files. You can see your own files across workspaces you can still access. Restricted staff access for an authorised review or support task is separate and audited.
Calendar stores private dated plans, your timezone, optional channels and media attachments, reminder settings, and your manual completion record. Email reminders help you remember the chosen time; you publish manually. Saving a plan or marking it done does not publish anything to a social platform. Calendar attachments do not extend file storage.
7. AI assistance and automated analysis
JoyReply uses AI to understand post and conversation context, classify intent and safety signals, draft replies, guide Setter conversations, plan content, and help create or edit media. Outputs can be incomplete or wrong, so sensitive claims and public actions need the level of review shown in the workspace.
We do not sell customer content. Customer data is used to provide and protect that customer's workspace. We do not use it to train a shared JoyReply model unless we first provide a separate, valid choice that clearly explains the change.
9. International transfers
Some providers or connected platforms may process data outside Romania or the European Economic Area. Where data-protection law requires it, we rely on an adequacy decision, approved contractual safeguards such as standard contractual clauses, or another lawful transfer mechanism.
10. How long we keep data
For the launch discount, we retain the account's eligibility record while it is needed to honour the offer. To prevent duplicate places, we also keep a protected, non-readable representation of the verified email while the limited campaign remains open, including after account deletion. It is not used for advertising or to restore the deleted account. Campaign evidence is reviewed for necessity when admissions close; financial evidence follows the separate statutory retention rules. You can ask privacy@joyreply.com about this processing or object to fraud-prevention processing based on legitimate interests.
We keep account and workspace data while the account is active. Connected data, text drafts, conversations and Calendar plans follow their feature-specific deletion rules. Creative files have the fixed storage periods below. Thirty days is our storage policy, not a retention period required by law. We keep only minimal expired-file history needed to explain delivery, expiry and credit records, without keeping the expired content in that history.
At expiry or confirmed deletion, the file becomes unavailable for preview, download and new reuse. Cleanup runs every 15 minutes and includes originals, variants, thumbnails and caches. If a storage location is offline, physical deletion remains pending until it reconnects; the file remains inaccessible through JoyReply. A shared physical copy is removed once no valid reference or bounded execution hold needs it.
We show the expiry date in My library and completion emails and send grouped reminders seven days and one day before expiry. Email can be delayed or undelivered, so download files you want to keep before the displayed date. Downloads, retries, Calendar entries and reuse do not extend storage. Automatic recovery does not shorten the original availability period.
Email-delivery and bounce evidence is normally removed after 90 days. Pending trial claims normally expire after 48 hours, trial activation receipts after 30 days, and pseudonymous one-trial claim evidence after two years so the same trial is not repeatedly claimed. Payment, invoice, credit, withdrawal, refund, correction-document, and related audit records are kept for the applicable accounting, consumer-protection, fraud-prevention, and legal-claims periods. Romanian accounting documents are currently generally retained for five years calculated from 1 July of the year after the relevant financial year.
When an account or channel is deleted, we remove or anonymise eligible data after verification. Limited security, legal, accounting, dispute, fraud-prevention, and deletion-request evidence may remain for its stated period. Encrypted backups follow a documented, bounded rotation; a deletion is reapplied if an older backup must be restored.
While a YouTube connection remains active, JoyReply refreshes stored YouTube Authorized Data through the YouTube API at least once every 30 days. If the data cannot be refreshed within that period, JoyReply deletes it. After you disconnect YouTube, revoke access in your Google Account, or ask us to delete the connection, any remaining YouTube Authorized Data is deleted as soon as possible and no later than seven calendar days after the request. JoyReply retains only a minimal record that contains no YouTube Authorized Data when retention is permitted or required by law.
| Creative data | Storage period |
|---|---|
| New generated images, videos, voiceovers and music | 30 days from first customer availability; each result shows its exact expiry date. |
| Generated files already stored when this policy starts | A full 30-day grace period from the policy rollout, with a visible expiry date. |
| Ordinary uploaded references | 30 days from upload. Existing files receive the rollout grace period. |
| References made from a generated file | The original file's expiry date; creating a reference does not start another 30 days. |
| Saved personal voices and their reference recordings | Until the voice or account is deleted, within the existing storage quotas. |
| Input copies for an already confirmed job | Only until terminal reconciliation, and no later than seven days from confirmation. These private execution copies do not allow new reuse or public download. |
| Encrypted backups containing media | No more than 15 additional days after expiry or deletion. Expiry and deletion are reapplied before restored data can be served. Financial and database recovery records have separate justified retention periods and do not extend access to expired media. |
11. Security
We use access controls, encrypted connection credentials, restricted administration, session protection, logs, and operational checks designed to reduce unauthorised access or loss. No online service can promise perfect security. Please use a strong password and tell us promptly if you suspect misuse.
12. Your rights
Depending on the situation, you can ask for access, correction, deletion, restriction, portability, or objection. You can withdraw consent at any time where consent is the basis, without affecting earlier lawful processing. You also have the right to complain to a data-protection authority.
Email privacy@joyreply.com from the account address when possible. We may ask for enough information to verify the request and protect the wrong account from being changed or deleted. We normally respond within one month; the law allows an extension for complex or numerous requests, in which case we will explain the delay.
13. Children and policy changes
JoyReply is a professional workspace and is not directed to children. Do not use it to collect unnecessary information about minors.
We update this policy when the product, providers, or law materially changes. The effective date at the top identifies the current version. If a change materially affects active users, we will use a reasonable in-product or email notice.
Need a copy of your data or want it deleted?
Use the signed-in Settings request when available, or email privacy@joyreply.com with your account email and the connected Page name.
4. Connected social Pages and audience data
JoyReply receives data only from Pages, profiles, or channels that an authorised account chooses to connect. Each connection appears separately and requests only the read access shown on that platform's consent screen.
The optional public connections use the following data when available: Facebook Pages: Page identity, posts, and comments. Instagram Professional: profile, media, and approved insights. YouTube: channel identity, handle, avatar, subscriber count, and public video totals. TikTok: profile, public statistics, and recent public videos.
These public connections are read only. JoyReply does not upload, publish, edit, delete, comment, rate, message, moderate, or reply through them. Cached data can remain visible during a temporary provider failure, and the account owner can disconnect a channel at any time.
Comments can contain data about people who have not opened a JoyReply account. We use that data only to show the authorised Page owner the conversation and its post context, prepare a private draft where that feature is available, and keep the Page-specific audit trail. Switching channels must switch the data scope as well.
JoyReply's use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements. Connected data is not sold, used for advertising, or used to train a shared model.
You can revoke JoyReply's access at any time from your Google Account permissions. Disconnecting YouTube in JoyReply also asks Google to revoke the connection and removes the connection credentials and cached YouTube identity and statistics from JoyReply, even if Google cannot complete the revocation request at that moment.