← RepCycle

Privacy Policy

How RepCycle collects, uses, stores, and deletes the data generated when your team practices sales calls against an AI prospect.

Effective 19 August 2026

1.Who we are

RepCycle is a sales-training simulator. Sales representatives practice full deal cycles against an AI prospect and receive scoring and coaching on their performance.

When your employer subscribes to RepCycle, they are the controller of the training data their team generates and RepCycle is the processor acting on their instructions. If you are a representative, direct access and deletion requests to your employer first.

2.What we collect

We collect only what the product needs to run and to score a call:

  • Account data — name, work email, organization, role, and authentication identifiers from your identity provider.
  • Call transcripts — the text of practice calls you initiate, including per-turn timestamps used as scoring evidence. Call audio is processed in real time to produce that transcript; RepCycle does not retain the audio itself by default.
  • Performance data — scores, per-behavior assessments, coaching notes, certification status, and the simulation configuration a score was produced against.
  • Content you upload — sales collateral, call recordings imported from connected systems, and the derived text embeddings used to make the AI prospect realistic.
  • Usage and diagnostic data — pages viewed, features used, and error reports.

3.Voice calls

Practice calls are captured as text because the transcript IS the product: scoring, coaching, and evidence for a disputed score all depend on what was actually said.

Your speech is converted to text in real time by our speech vendor. RepCycle does not retain the audio itself by default — what we store is the transcript. Where an organization enables audio retention, recordings are kept for no longer than 90 days and are then deleted.

You are asked for explicit consent before your first call and cannot start a call without it. Consent is recorded, and withdrawing it stops future capture.

Neither your audio nor your transcripts are used to train third-party AI models. They are processed by our speech and language vendors under contracts that prohibit training on customer data.

4.How we use it

We use your data to:

  • Run the simulation and generate the AI prospect's responses.
  • Score calls and produce coaching feedback.
  • Show managers and administrators team-level progress within their own organization.
  • Bill your organization for usage.
  • Diagnose errors, prevent abuse, and keep the service secure.

5.Who we share it with

We do not sell personal data and we do not share it for advertising.

We share data only with subprocessors that operate part of the service on our behalf, each under a data-processing agreement:

  • Supabase — application database and file storage.
  • Anthropic and OpenAI — AI prospect responses, scoring, live voice, and the speech-to-text transcription performed inside the live call.
  • Stripe — payment processing (Stripe receives billing data, never call content).
  • Sentry — error monitoring. Error reports may incidentally include user identifiers.
  • Vercel — application hosting.
  • WorkOS — authentication and single sign-on.
  • Novu and Resend — transactional email and in-app notifications.
  • PostHog — product analytics.

6.Where data is stored, and how it is isolated

Data is stored in the United States.

Every record is bound to your organization and access is enforced in the database itself, not only in application code, so one customer cannot read another's data.

Support staff cannot browse customer data at will. Access requires an approved, time-limited grant scoped to a single organization, and every action taken under one is recorded in an immutable audit log.

7.How long we keep it

Retention is enforced by the system, not by policy alone:

  • Call audio — not retained by default; where audio retention is enabled, no longer than 90 days.
  • Transcripts, scores, and coaching — for the life of the account.
  • Audit logs — 2 years. These are append-only and cannot be edited or deleted, including by us; that is what makes them trustworthy.
  • Unauthenticated trial calls — purged within 48 hours.
  • After account closure, customer data is deleted within 30 days, except records we are required to retain (audit logs and billing records).

8.Your rights

Depending on where you live, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. If you are in the EEA or UK, we process your data under legitimate interest and contractual necessity, and you may lodge a complaint with your supervisory authority.

To exercise any of these rights, contact us at the address below. If your account was created by your employer, we will refer the request to them as the data controller and assist them in fulfilling it.

9.Cookies

We use cookies that are strictly necessary to run the service: keeping you signed in, remembering which organization you are working in, and protecting against cross-site request forgery. We do not use advertising cookies.

Product-analytics cookies help us understand which features get used. You can block them in your browser without losing access to the product.

10.Security

All traffic is encrypted in transit and data is encrypted at rest. Access to production systems is limited, logged, and reviewed. We maintain an incident-response process and will notify affected customers without undue delay if a breach affects their data.

11.Changes to this policy

If we make a material change we will update the effective date above and notify account administrators before the change takes effect.