Skip to main content
RenewOS

Legal

Privacy Policy

What we store, why we store it, and how we keep it private.

No cloud AI — by design. We never use your content to train models. The only automated step — the on-device "Detect expiry date" scan — never sends your documents anywhere.

Private by default

Items, notes and attachments are yours. We never sell your data and never share it with third parties for advertising.

Strong authentication

Passwords are salted and hashed (PBKDF2). Sessions are individually revocable. Resets use single-use, time-limited tokens.

Minimal collection

Only what the product needs: your name, email, timezone and the expiry data you enter. No fingerprinting or ad tracking.

Export anytime

Take your data as CSV, JSON or ICS at any time. Account deletion follows a documented retention workflow with a recovery window.

1. What we collect

Last updated: September 2026
Account data: your name and email address. Product data: the expiry items, reminder schedules, people profiles and file attachments you create. Operational data: aggregated request counts and error rates for reliability and abuse prevention. We do not track document content for analytics or profiling.

2. How we use it

To operate the product (scheduling and delivering reminders), to secure your account, and to maintain service reliability. We never use your content to train AI models — RenewOS deliberately contains no AI components.

3. Data storage & security

Data is stored with strong access controls and encrypted at rest. Attachments live in private cloud storage and are only accessible via signed, short-lived URLs tied to your authenticated session. Even RenewOS administrators cannot casually access your attachment content.

4. Sharing

We do not sell your data. We share the minimum necessary with infrastructure providers that help us run the service (hosting, email delivery, payment processing). Each provider is bound by data-protection agreements. We do not share your data with data brokers or advertising networks.

5. Your rights (GDPR & more)

You can access, export, correct and delete your data. Account deletion is available in Settings → Account. Where GDPR, UK GDPR, CCPA or similar laws apply, you may exercise your rights by contacting us; we respond within the statutory timeframe (typically 30 days).

6. Cookies & sessions

We use a single essential session cookie for authentication. We do not use advertising cookies, cross-site tracking cookies, or third-party analytics that observe your browsing outside of RenewOS.

7. Retention & deletion

Soft-deleted records are held for a short recovery window before permanent destruction, so accidental deletion is recoverable. When you delete your account, your personal data is permanently removed according to our documented workflow. Aggregated, anonymised operational metrics may be retained longer.

8. International transfers

Your data may be processed in regions other than your own for reliability and redundancy. Where this occurs, we apply appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms recognised by your jurisdiction.

9. Contact

Privacy questions? Use our Contact page or email [email protected]. For GDPR data subject requests, include "DATA REQUEST" in the subject line.