Your data: security, storage, and export
Your customer conversations are sensitive, and AcornReply is built to keep them private, isolated to your team, and yours to take with you. Here's how your data is handled.
Where your data lives
Your data is stored in Postgres in the United States. Each workspace's data is row-isolated and every query is scoped by workspace ID — there's no path for one workspace to see another's conversations, customers, or knowledge base.
How access is secured
- Sign-in uses Google SSO or an email magic link (plus email-and-password if you set one), so access to your inbox is protected by real authentication.
- Public contact submissions pass through a bot-prevention challenge before they can create a conversation.
- Inbound email webhooks are verified with a shared secret, so only legitimate mail reaches your inbox.
- We don't sell or share your customer data.
Exporting your inbox
Your data isn't locked in. You can export your inbox — conversations and customers — as JSON. During early access this is available on request; self-serve export is part of launch. Either way, you can take a full copy with you whenever you want.
Deleting your data
You're in control of removal, too:
- Delete a workspace to remove that inbox and everything in it.
- Delete your account from settings at any time; all associated conversations and customers are removed.
Deletion is permanent, so export first if you want a copy.
A note on the AI
AI drafts are grounded in your knowledge base and the conversation at hand. Unpublished or "not in use" knowledge-base entries — and answers captured privately from resolved conversations — inform drafting for your workspace only; they're never exposed to other tenants or shown publicly.
For the security patterns AcornReply follows across the board, and anything not covered here, reach out to support — we're happy to walk through specifics.