How we handle your data.
This policy explains what information we collect when you use Remi (the platform at remiremindsyou.com and the WhatsApp agent), how we use it, and what controls you have over it.
Who operates Remi
Remi is operated by Remi Reminds. For questions about this policy, contact us at hola@remiremindsyou.com.
What information we collect
What you give us
- Account: email, password (encrypted by our auth provider, Clerk).
- Profile: optional name, locale, timezone.
- WhatsApp number: so the Remi agent can send you reminders.
- Reminder and list content: the text you write, dates, recurrence rules.
- Payments: if you buy a subscription, Stripe processes your card. We only store a customer identifier and the subscription status — never your card number.
What we collect automatically
- Messages you send to the bot on WhatsApp, plus metadata (timestamp, message id).
- Basic technical data: IP address, browser type, pages visited.
Cookies and browser storage
Remi uses strictly necessary cookies only. We run no advertising, profiling, or cross-site tracking cookies, and there are no ad networks on the platform. That is why you will not see a cookie banner — there is nothing optional to accept or reject.
- Session (Clerk): cookies such as
__sessionand__clerk_*keep you signed in and protect forms against CSRF. Without them the dashboard does not work. They expire when you sign out or the session lapses. - Preferences: we store your language so we do not have to ask on every visit.
You can clear these cookies from your browser at any time; the effect is that you will be signed out.
Error diagnostics (Sentry)
When something breaks on the platform we use Sentry to record the error so we can fix it. This includes a replay of the seconds leading up to the failure, captured only when an error occurs — we never record ordinary sessions at random. In those replays all text is masked and media is blocked, so the content of your reminders, your phone number, and your email are not visible. They are retained for 90 days and then deleted.
Google Calendar (optional)
Connecting your Google Calendar is optional — Remi works fully without it. If you connect it from Settings, we request the minimum scope needed (calendar.events) and use it only for:
- Creating events you explicitly ask for. When you write “schedule the meeting Thursday 3–4pm”, we create that event. Your regular reminders are not written to your calendar.
- Creating a Google Meet room for that event, if you ask for one.
- Inviting your contacts to that event — only if you ask, only if that contact already gave consent, and only if you saved their email address.
- Reading your events to warn you about scheduling conflicts and to answer “what do I have on Thursday?”.
- Updating or deleting the events Remi created, when you reschedule or cancel the corresponding reminder.
What we store: the OAuth tokens needed to act on your behalf, the email address of the account you connected, and — for events Remi itself created — their id and Meet link (so the reminder we send at meeting time can include the join link). We do not store the contents of events we did not create.
How to disconnect: Settings → Google Calendar → Disconnect. We revoke the token with Google at that moment and lose all access. You can also do it from your Google Account permissions. Events already in your calendar stay there — they are yours.
Remi’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use your calendar data for advertising or to train artificial-intelligence models.
How we use it
- To deliver the service: remind you of things, show your data in the dashboard.
- To authenticate your account and prevent abuse.
- To bill your subscription if you have a paid plan.
- To improve the product through aggregate usage patterns — never specific reminder content.
What we do NOT do
- We never sell your data to third parties.
- We do not use your messages to train third-party AI models.
- We do not show your data to other users (except in the shared reminders flow, which requires explicit consent).
Who we share information with
We work with these infrastructure providers:
- Clerk — user authentication.
- Supabase — database that holds your reminders and lists.
- Vercel — web hosting.
- Railway — API hosting.
- WhatsApp / Meta — for delivering bot messages. Their privacy policy also applies.
- Stripe — payment processing (only if you buy a plan).
- Sentry — technical error logging for the platform.
Your rights
No matter where you live, you can ask us to:
- Access the information we hold about you
- Correct inaccurate information
- Delete your account and all associated data
- Export your data in a portable format (JSON)
- Withdraw your consent to processing
To exercise any of these rights, email us at hola@remiremindsyou.com. We respond within 30 days.
Retention
We keep your information while your account is active. If you delete your account, we remove all personal data within 30 days, except what we're legally required to keep (e.g. billing records).
Security
All information is transmitted over HTTPS. Passwords are hashed by Clerk using bcrypt. WhatsApp end-to-end encrypts messages between you and the bot. Sensitive fields in the database are stored encrypted.
Changes to this policy
If we materially change this policy we'll notify you by email and post a notice on the site. The "last updated" date above always reflects the current version.