Privacy policy
Learn how Reminda protects your personal data with zero-knowledge E2EE encryption, transparent processing, and strict privacy controls.
1. Introduction & scope
This Privacy policy describes how Reminda ('we', 'us', or 'our') collects, utilizes, secures, and discloses your information when you access or use our software, web application, mobile applications, and associated services (collectively, the 'Services').
By using the Services, you acknowledge that you have read and understood the practices described in this Privacy policy. This document is designed to align with major global privacy frameworks, including the General Data Protection Regulation (GDPR), the UK GDPR, and the California Consumer Privacy Act (CCPA) as amended by the CPRA.
2. Zero-knowledge architecture & encrypted user data
Reminda is engineered upon a foundational Zero-Knowledge End-to-End Encryption (E2EE) architecture. We distinguish strictly between administrative account data and your private content.
• User Content: All study materials, text notes, flashcards, and uploaded files ('User Data') are encrypted locally on your device utilizing AES-256-GCM cryptography before transmission to our servers. Reminda does not possess, store, or have access to your master passphrase or cryptographic decryption keys.
• Absolute Privacy: Because we cannot decrypt your User Data, we cannot read, mine, analyze, or sell your private content. You bear sole responsibility for maintaining access to your recovery credentials.
3. Information we collect
To operate, maintain, and support the Services, we collect specific, limited categories of information:
• Account Credentials: Information required to establish your account, including your email address and hashed authentication data.
• Billing & Subscription Data: Transaction histories and subscription status. Payment processing is handled securely by specialized third-party merchants of record (e.g., Paddle, RevenueCat, Apple, Google, MoMo). We do not collect or store full credit card numbers on our infrastructure.
• Technical & Usage Telemetry: Anonymized device identifiers, operating system versions, and crash diagnostics. This data is collected strictly for performance optimization, security monitoring, and debugging purposes.
4. Purposes and legal basis for processing
We process your personal information only when we possess a valid legal basis to do so. These bases include:
• Contractual Necessity: Providing you with the core functionality of the Services, managing your account, and processing subscriptions.
• Legitimate Interests: Ensuring platform security, mitigating fraud, and analyzing aggregated, anonymized usage data to improve our software.
• Consent: Where legally required, we rely on your explicit consent for specific processing activities, which you may withdraw at any time via your account settings.
5. Artificial intelligence & third-party processing
The Services may incorporate Artificial Intelligence (AI) features, such as automated flashcard generation and contextual analysis, powered by third-party enterprise APIs.
• Zero-Retention API Policies: We strictly partner with AI providers under enterprise agreements that prohibit data retention. Your decrypted queries are processed ephemerally in-memory.
• No Model Training: Your User Data and metadata are never utilized to train, fine-tune, or otherwise improve public or foundational machine learning models.
6. Data sharing & sub-processors
We do not sell your personal information to data brokers or advertising networks. We may share necessary administrative data solely with trusted third-party sub-processors who assist in operating our Services, subject to stringent data processing agreements.
These service providers may include cloud hosting infrastructure (e.g., Google Cloud, Cloudflare), and transactional email services (e.g., Postmark). A complete list of current sub-processors is available upon request.
7. International data transfers
Reminda operates globally, meaning your information may be transferred to, stored, or processed in jurisdictions outside of your country of residence (including the United States or European Union).
Where such international transfers occur, we implement legally recognized safeguards, such as the European Commission’s Standard Contractual Clauses (SCCs) or equivalent adequacy mechanisms, to ensure your data receives an appropriate level of protection.
8. Data retention & account deletion
We retain your administrative account information for as long as your account remains active or as necessary to fulfill our legal and regulatory obligations.
Upon requesting account deletion, all associated encrypted User Data will be immediately inaccessible and permanently purged from our primary databases and backup systems within thirty (30) days. Due to our zero-knowledge architecture, we cannot recover data once this deletion process is initiated.
9. Your privacy rights
Depending on your applicable jurisdiction (including the EU, UK, and California), you possess specific legal rights regarding your personal data:
• Right to Access & Portability: You may export your unencrypted User Data at any time directly through the client application in standard interoperable formats (e.g., Markdown, JSON).
• Right to Rectification & Erasure: You may update your account information or request full account deletion via the application settings.
• Right to Object & Restrict: You may object to or request restrictions on certain processing activities by contacting our privacy team.
10. Children's privacy
Our Services are intended for a general audience and are not directed toward individuals under the age of 13 (or 16, depending on regional legal definitions). We do not knowingly collect personal information from children. If we become aware that we have inadvertently collected data from a minor without valid parental consent, we will take immediate steps to delete such information.
11. Updates to this policy
We reserve the right to periodically revise this Privacy policy to reflect changes in our operational practices, technological advancements, or legal requirements. Material modifications will be communicated to you via the Services or email prior to taking effect. The 'Last Updated' date at the top of this document indicates the most recent revision.
Privacy officer contact
Have privacy questions or a data subject request? Contact our compliance team.