Last updated: August 23, 2026
This policy explains how Reflexive (the “Service”), available at reflexive.at, processes personal data. Data controller: the individual operator of Reflexive. Contact for personal data requests: Telegram @sefrwea. The Service is provided in beta and may change. Personal data is processed on servers in the European Union (Finland). Where you are in the European Economic Area (EEA) or UK, the EU General Data Protection Regulation (GDPR) and applicable national law apply to this processing.
The Service is primarily aimed at users in the European Economic Area (EEA) and the United Kingdom. It is also available to users in other countries, including the Republic of Kazakhstan. If you are outside the EEA/UK, your local data-protection rules may apply in addition to this policy. By registering or using the Service you are informed that account data is stored in Helsinki, Finland (EU), and you accept this policy.
On registration: email and password hash; with Google OAuth sign-in — email and Google account identifier. During use: note text, diagrams, metadata (dates, hashtags, branches), account settings, registration and last login dates, beta subscription status. Optionally: OpenAI API key (encrypted on the server with AES-256-GCM). Technical data: IP address and browser data may be processed on the server for security and diagnostics (logs — limited retention). In the browser (localStorage): sign-in tokens, language, theme, drafts, cookie consent — see Cookie Policy.
Processing is necessary to provide Service features (notes, diagrams, export, AI analysis), registration and authentication, security, support and product improvement. Legal bases: consent (creating an account / Terms of Use), contract performance (Terms of Use), legitimate interests (security, abuse prevention). Marketing emails require a separate optional opt-in at registration (can be changed in Settings).
Primary storage of user personal data is on a virtual server (VPS) in a data centre in Helsinki, Finland (European Union / EEA). Database: PostgreSQL on the same server. Backups (if created) are kept in the same geographic area (Finland / EU) or with a provider offering equivalent safeguards under GDPR.
Your account data is processed and stored in Finland (EEA). Some processors are outside the EEA: (a) OpenAI, Inc. (USA and others) — note text and related context when you use AI features or when a server OpenAI key is configured; (b) Google LLC (USA / global) — when you sign in with Google OAuth. We transfer only what is needed for these purposes, using appropriate safeguards where required (e.g. EU Standard Contractual Clauses or equivalent). If you register from outside the EEA (e.g. Kazakhstan), creating an account includes consent to transfer and storage in Finland as described here. Using AI features that send text to OpenAI involves further transfer outside the EEA. You may withdraw consent and request deletion — see Your rights; withdrawal may limit use of the Service.
We do not sell or rent personal data. Transfer may occur only to: OpenAI — for AI analysis; Google — for OAuth; the hosting provider in Helsinki — for infrastructure; public authorities in Finland, the EU/EEA, or (where applicable) the Republic of Kazakhstan — when required by law. The list of recipient categories may be updated; current information is in this policy.
Data is kept until account deletion or your deletion request, unless longer retention is required by law. Security logs — typically up to 90 days. Guest sessions may be removed on logout or server cleanup. After account deletion, data is removed from the active database within a reasonable time; backups may persist for a limited period until rotation.
If GDPR applies to you, you may: access your data; rectify inaccurate data; erase data where there is no legal basis to keep it; restrict processing; data portability where applicable; object to processing based on legitimate interests; withdraw consent where processing is based on consent; lodge a complaint with a supervisory authority — in your EU/EEA country of residence, place of work, or place of the alleged infringement, or with the Finnish Office of the Data Protection Ombudsman (Tietosuojavaltuutettu). If you are in the Republic of Kazakhstan, you may also exercise rights under applicable Kazakh personal data law (e.g. access, correction, deletion where provided). Requests: Telegram @sefrwea with your account email. We respond within one month where GDPR requires it, or within a reasonable time otherwise.
Note text and your optional OpenAI API key are encrypted on the server with AES-256-GCM before saving to the database. Encryption keys are kept separate from the data. Passwords are not stored in plain text — only as a cryptographic hash. Connections use HTTPS (TLS). We apply reasonable technical and organisational measures appropriate for a beta service; absolute security is not guaranteed.
The Service is not intended for anyone under 16. We do not knowingly collect children’s personal data. If you believe a child provided data to us, contact us and we will delete it.
Details on localStorage and possible cookies are on the Cookie Policy page. Essential technical data (sign-in, settings) is required for the Service. Optional analytics — only after consent in the cookie banner (not active today).
This policy may be updated. The current version is always on this page with the update date. For material changes we may notify by email or in the Service UI. Continued use after changes means acceptance unless the law requires renewed consent.