← ← Reflexive

Privacy policy

Last updated: August 23, 2026

1. General

This policy explains how Reflexive (the “Service”), available at reflexive.at, processes personal data. Data controller: the individual operator of Reflexive. Contact for personal data requests: Telegram @sefrwea. The Service is provided in beta and may change. Personal data is processed on servers in the European Union (Finland). Where you are in the European Economic Area (EEA) or UK, the EU General Data Protection Regulation (GDPR) and applicable national law apply to this processing.

2. Geography and audience

The Service is primarily aimed at users in the European Economic Area (EEA) and the United Kingdom. It is also available to users in other countries, including the Republic of Kazakhstan. If you are outside the EEA/UK, your local data-protection rules may apply in addition to this policy. By registering or using the Service you are informed that account data is stored in Helsinki, Finland (EU), and you accept this policy.

3. Data we collect

On registration: email and password hash; with Google OAuth sign-in — email and Google account identifier. During use: note text, diagrams, metadata (dates, hashtags, branches), account settings, registration and last login dates, beta subscription status. Optionally: OpenAI API key (encrypted on the server with AES-256-GCM). Technical data: IP address and browser data may be processed on the server for security and diagnostics (logs — limited retention). In the browser (localStorage): sign-in tokens, language, theme, drafts, cookie consent — see Cookie Policy.

4. Purposes and legal basis

Processing is necessary to provide Service features (notes, diagrams, export, AI analysis), registration and authentication, security, support and product improvement. Legal bases: consent (creating an account / Terms of Use), contract performance (Terms of Use), legitimate interests (security, abuse prevention). Marketing emails require a separate optional opt-in at registration (can be changed in Settings).

5. Storage location and infrastructure

Primary storage of user personal data is on a virtual server (VPS) in a data centre in Helsinki, Finland (European Union / EEA). Database: PostgreSQL on the same server. Backups (if created) are kept in the same geographic area (Finland / EU) or with a provider offering equivalent safeguards under GDPR.

6. Transfers outside the EEA

Your account data is processed and stored in Finland (EEA). Some processors are outside the EEA: (a) OpenAI, Inc. (USA and others) — note text and related context when you use AI features or when a server OpenAI key is configured; (b) Google LLC (USA / global) — when you sign in with Google OAuth. We transfer only what is needed for these purposes, using appropriate safeguards where required (e.g. EU Standard Contractual Clauses or equivalent). If you register from outside the EEA (e.g. Kazakhstan), creating an account includes consent to transfer and storage in Finland as described here. Using AI features that send text to OpenAI involves further transfer outside the EEA. You may withdraw consent and request deletion — see Your rights; withdrawal may limit use of the Service.

7. Third parties

We do not sell or rent personal data. Transfer may occur only to: OpenAI — for AI analysis; Google — for OAuth; the hosting provider in Helsinki — for infrastructure; public authorities in Finland, the EU/EEA, or (where applicable) the Republic of Kazakhstan — when required by law. The list of recipient categories may be updated; current information is in this policy.

8. Retention

Data is kept until account deletion or your deletion request, unless longer retention is required by law. Security logs — typically up to 90 days. Guest sessions may be removed on logout or server cleanup. After account deletion, data is removed from the active database within a reasonable time; backups may persist for a limited period until rotation.

9. Your rights

If GDPR applies to you, you may: access your data; rectify inaccurate data; erase data where there is no legal basis to keep it; restrict processing; data portability where applicable; object to processing based on legitimate interests; withdraw consent where processing is based on consent; lodge a complaint with a supervisory authority — in your EU/EEA country of residence, place of work, or place of the alleged infringement, or with the Finnish Office of the Data Protection Ombudsman (Tietosuojavaltuutettu). If you are in the Republic of Kazakhstan, you may also exercise rights under applicable Kazakh personal data law (e.g. access, correction, deletion where provided). Requests: Telegram @sefrwea with your account email. We respond within one month where GDPR requires it, or within a reasonable time otherwise.

10. Security

Note text and your optional OpenAI API key are encrypted on the server with AES-256-GCM before saving to the database. Encryption keys are kept separate from the data. Passwords are not stored in plain text — only as a cryptographic hash. Connections use HTTPS (TLS). We apply reasonable technical and organisational measures appropriate for a beta service; absolute security is not guaranteed.

11. Children

The Service is not intended for anyone under 16. We do not knowingly collect children’s personal data. If you believe a child provided data to us, contact us and we will delete it.

12. Cookies and local storage

Details on localStorage and possible cookies are on the Cookie Policy page. Essential technical data (sign-in, settings) is required for the Service. Optional analytics — only after consent in the cookie banner (not active today).

13. Changes

This policy may be updated. The current version is always on this page with the update date. For material changes we may notify by email or in the Service UI. Continued use after changes means acceptance unless the law requires renewed consent.