Reputation Systems

Reputation Review Reply Privacy Policy

Effective September 9, 2026

Overview

Reputation Review Reply is a Chrome extension published by Shrikrishna Gavhane. It helps hotel managers generate, edit, copy, and post responses to guest reviews on supported review platforms. This policy explains the data the extension handles and how that data is used.

Information the extension handles

The extension handles information only as needed to provide review-reply functionality:

The extension does not collect a user's general browsing history. Its content script runs on HTTPS pages to recognize supported hotel-review surfaces, but it sends page information to the RR service only when the user requests a reply.

How information is used

Review information, reply settings, and the platform hostname are sent over HTTPS to rr-api.reputationsystems.ai to generate the response requested by the user. Authentication and operational information is used to validate access, apply rate limits, attribute usage, prevent abuse, secure the service, and diagnose failures. Information is not used for advertising, creditworthiness, lending, or unrelated purposes.

Storage and retention

The full RR API key, its identifier, connection time, and reply settings are stored in chrome.storage.local in the user's Chrome profile. Extension storage access is restricted to trusted extension contexts. The RR website sends a newly created extension key directly to the installed extension; no copy and paste is required. For reconnection, the website sends a short-lived account token to the extension, which uses it to verify key ownership with the RR API but does not store that token. Disconnecting in the popup removes the locally stored key.

The RR service stores only a one-way hash of each API key, together with a short prefix and final four characters used for identification. Usage records contain the account identifier, API-key identifier, model identifier, request timestamp, and cost attribution. The RR application does not intentionally store review text, reviewer names, manager signature fields, or generated replies in its application database after the generation request completes.

Security and infrastructure logs are retained only as reasonably necessary to operate, secure, and troubleshoot the service. Users should not submit confidential information that is unnecessary for replying to a public review.

Service providers and disclosure

Reputation Systems uses contracted hosting, network, database, security, and model-inference providers to operate the service. Current providers include Amazon Web Services for application infrastructure and Salad Technologies, Inc. (SaladCloud) for model inference; Groq, Inc. may process the same request only when it is configured as the fallback model provider. Review text is provided to model-inference infrastructure solely to generate the requested reply. These providers may process information only on our behalf and for the service purpose. Information may also be disclosed when required by law, to protect users or the service from fraud or abuse, or as part of a business transfer subject to applicable notice and consent requirements.

Reputation Systems does not sell extension user data. It does not transfer extension user data to advertising platforms, data brokers, or information resellers. Employees and contractors are not permitted to read review content except with the user's specific consent for support, when necessary for security or abuse investigation, when required by law, or after data has been aggregated and anonymized for permitted internal operations.

User choices

The extension remains off until the user connects a valid RR API key from the RR website. Its connection lasts 30 days before account verification is required again. Signing out disables the connection; disconnecting in the popup removes the locally stored key. A user controls when review information is transmitted by selecting review text, clicking a recognized review, or selecting an RR reply action. Generated text remains editable, and supported native posting workflows require a final user click. Users can uninstall the extension to remove its local data.

Security

Data transmitted between the extension and the RR service is protected with HTTPS. API keys are attached by the extension's background service worker rather than webpage scripts. No method of transmission or storage is completely secure, so users should protect API keys and revoke a key if they believe it has been exposed.

Chrome Web Store Limited Use

The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements. Extension data is used only to provide or improve the extension's single user-facing purpose and related security and operational functions.

Changes to this policy

This policy may be updated when the extension's data practices or applicable requirements change. Material changes will be disclosed before new data handling begins. The effective date above identifies the latest version.

Contact

For privacy questions or data requests, email admin@multisystems.ai.