How we handle your data.
This policy explains what information we collect when you use Remi Reminds You (“Remi”: the platform at remiremindsyou.com and the WhatsApp agent), how we use it, and what controls you have over it.
Who operates Remi Reminds You
Remi Reminds You is operated by Remi Reminds. For questions about this policy, contact us at hola@remiremindsyou.com.
What information we collect
What you give us
- Account: email, password (encrypted by our auth provider, Clerk).
- Profile: optional name, locale, timezone.
- WhatsApp number: so the Remi agent can send you reminders.
- Reminder and list content: the text you write, dates, recurrence rules.
- Payments: if you buy a subscription, Stripe processes your card. We only store a customer identifier and the subscription status — never your card number.
What we collect automatically
- Messages you send to the bot on WhatsApp, plus metadata (timestamp, message id).
- Basic technical data: IP address, browser type, pages visited.
Cookies and browser storage
Remi uses strictly necessary cookies only. We run no advertising, profiling, or cross-site tracking cookies, and there are no ad networks on the platform. That is why you will not see a cookie banner — there is nothing optional to accept or reject.
- Session (Clerk): cookies such as
__sessionand__clerk_*keep you signed in and protect forms against CSRF. Without them the dashboard does not work. They expire when you sign out or the session lapses. - Preferences: we store your language so we do not have to ask on every visit.
You can clear these cookies from your browser at any time; the effect is that you will be signed out.
Error diagnostics (Sentry)
When something breaks on the platform we use Sentry to record the error so we can fix it. This includes a replay of the seconds leading up to the failure, captured only when an error occurs — we never record ordinary sessions at random. In those replays all text is masked and media is blocked, so the content of your reminders, your phone number, and your email are not visible. They are retained for 90 days and then deleted. We do not send Google Calendar data to Sentry.
Google Calendar (optional)
Connecting your Google Calendar is optional — Remi works fully without it. If you connect it from Settings, we request the minimum scope needed (calendar.events) and use it only for:
- Creating events you explicitly ask for. When you write “schedule the meeting Thursday 3–4pm”, we create that event. Your regular reminders are not written to your calendar.
- Creating a Google Meet room for that event, if you ask for one.
- Inviting your contacts to that event — only if you ask, only if that contact already gave consent, and only if you saved their email address.
- Reading your events to warn you about scheduling conflicts and to answer “what do I have on Thursday?”.
- Updating or deleting the events Remi created, when you reschedule or cancel the corresponding reminder.
What we store: the OAuth tokens needed to act on your behalf, the email address of the account you connected, and — for events Remi itself created — their id and Meet link (so the reminder we send at meeting time can include the join link). We do not store the contents of events we did not create.
How to disconnect: Settings → Google Calendar → Disconnect. We revoke the token with Google at that moment and lose all access. You can also do it from your Google Account permissions. Events already in your calendar stay there — they are yours.
Limited Use of Google data
Remi’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We use your Google Calendar data only to provide the calendar features described above — the ones you ask for — and to fix them when they break.
- We do not use it for advertising of any kind: no ads shown to you, no profiling, no campaign measurement.
- We do not sell it or hand it to data brokers.
- We do not use it to train or fine-tune artificial-intelligence models — ours or anyone else’s, general or specialized.
- We keep it out of our product analytics: the aggregate metrics we use to decide what to build are computed without Google data.
- No human reads it, except in the four cases Google’s own policy allows: you give us explicit permission to look at something specific, it is necessary for security (investigating abuse or a breach), the law requires it, or the data is aggregated and anonymized for internal operations.
- We transfer it only to the providers strictly necessary to deliver the feature you asked for (see Who we share information with), or where the law requires it.
- When you disconnect Google Calendar we revoke the token and delete the calendar data we had stored.
If any other part of this policy appears to say something different about data obtained from Google APIs, this section governs.
How we use it
- To deliver the service: remind you of things, show your data in the dashboard.
- To authenticate your account and prevent abuse.
- To bill your subscription if you have a paid plan.
- To improve the product through aggregate usage patterns — never specific reminder content. Google Calendar data is excluded from that analysis.
We use your information for nothing else. In particular, we run no advertising, we do not profile you, and we neither sell nor rent anything we store.
Interpreting your messages
To understand what you write in plain language (“remind me to pay the power bill on the 15th”), the text of your message is processed by a language-model provider. If you ask about your schedule, that can include the event details needed to answer you. We send only what is needed to produce that reply, and neither your messages nor your Google data are used to train models.
What we do NOT do
- We never sell your data to third parties.
- We do not use your messages or your Google data to train AI models — ours or anyone else’s.
- We run no advertising on your information, ours or anyone else’s.
- We do not show your data to other users (except in the shared reminders flow, which requires explicit consent).
Who we share information with
We work with these infrastructure providers:
- Clerk — user authentication.
- Supabase — database that holds your reminders and lists.
- Vercel — web hosting.
- Railway — API hosting.
- WhatsApp / Meta — for delivering bot messages. Their privacy policy also applies.
- Stripe — payment processing (only if you buy a plan).
- Sentry — technical error logging for the platform.
- Language-model provider — to interpret what you write to the bot and compose its reply.
None of them receives your information for their own purposes: they process it on our instructions, to deliver the service. Google Calendar data reaches only the few that the feature requires: the database that holds the tokens and the ids of events Remi created, the API host that talks to Google, WhatsApp to deliver what you asked for (the Meet link in a reminder, say), and the language-model provider when you ask about your schedule. We do not send calendar data to Sentry.
Your rights
No matter where you live, you can ask us to:
- Access the information we hold about you
- Correct inaccurate information
- Delete your account and all associated data
- Export your data in a portable format (JSON)
- Withdraw your consent to processing
To exercise any of these rights, email us at hola@remiremindsyou.com. We respond within 30 days.
Retention
We keep your information while your account is active. If you delete your account, we remove all personal data within 30 days, except what we're legally required to keep (e.g. billing records).
Security
All information is transmitted over HTTPS. Passwords are hashed by Clerk using bcrypt. WhatsApp end-to-end encrypts messages between you and the bot. Sensitive fields in the database are stored encrypted.
Changes to this policy
If we materially change this policy we'll notify you by email and post a notice on the site. The "last updated" date above always reflects the current version.