Privacy Policy
Effective and last updated: September 5, 2026
Volodymyr Lozynskyi, based in Spain, operates Reunier (the Service) and is the controller of the personal data described below. This notice explains how Reunier processes personal data; it is not a request for blanket consent.
1. Data we process
- Account and preferences: email address, password hash, Google or Apple account identifier when the corresponding optional sign-in is used, an encrypted Apple authorization-revocation credential, email-verification and email-visibility status, language, notification preferences, role, account status, and account creation/update/deletion dates. If you choose Apple's Hide My Email, Reunier receives and stores Apple's private relay address rather than the address behind it. When another verified address is hidden through Reunier, profile responses show
****@domain; Reunier still retains the complete address to operate the account and send required confirmations. The Apple revocation credential is used only to withdraw Reunier's authorization when the account is deleted. - Rooms and events: room names, membership and display names, roles, room settings and join credentials; event titles, descriptions, dates, participation deadlines, type, recurrence, location text and, if entered, latitude/longitude; following and participation status, comments, optional adult/child counts, selected quantities, poll answers, and organizer-defined participation statuses. Other room members can see data shared within that room as required by the feature. Event authors see participants and participation totals, but not the identities of followers. A valid event-invitation link can show a non-member only the event title, description, type, schedule, and participation deadline before the person joins the room. It does not expose room members, poll or status data, organizer messages, room credentials, or the event's exact location through that preview.
- Authentication and device data: session and token identifiers, hashed refresh tokens, device type, user agent, app or installation identifiers made available by platform services, session activity/expiry/revocation times, essential cookies, and mobile push-notification tokens.
- Optional calendar connection: when you separately connect Google Calendar, Reunier stores the provider, granted scope, connection time, time zone, the identifier of the separate calendar created by Reunier, encrypted OAuth access and refresh tokens with their expiry, and the status and external identifiers of Reunier event copies. In the iOS app, Apple Calendar synchronization is performed locally through EventKit: the app stores the identifier of its separate Reunier calendar and the identifiers of the event copies on that device, while no Apple Calendar token or existing calendar content is sent to Reunier's server. iOS may describe this permission as full calendar access because EventKit requires permission to create, update, and remove event copies; Reunier uses it only for the separate calendar and copies it manages. For events in which you participate, the integration uses the title, start and optional end time, location text if present, and a link back to the event. Following alone does not activate calendar synchronization. Reunier's calendar logic does not inspect or import your existing events, contacts, availability, or attendee lists.
- Optional voice input and system assistants: when you tap the microphone while creating an event or invoke Reunier through Siri or Google Assistant, the applicable device, assistant, or browser speech-recognition service processes your spoken request under its own privacy notice. Google Assistant opens Reunier's voice-creation feature; Siri may also pass the transcript of the event details you provide after its prompt. Reunier receives text, not an audio recording, and uses it only to prepare an event draft for your review. Reunier does not send the audio to its own server or store it. Text you apply follows the same local-draft and event rules as text you type.
- Payments and vouchers: for payments, provider and transaction/customer identifiers, product, room, amount, currency, periods, payment status, timestamps, and refund/chargeback records; for a redeemed voucher, the voucher-code snapshot, room capacity and periods granted, redemption time, whether a room was created, and links to the redeeming user and receiving room while those records still exist. Reunier does not receive or store full payment-card details. A voucher is a transferable, single-use gift code for room-access periods, not a payment or discount.
- Security, support, reports, and communications: verification, email-reveal and recovery tokens and codes, transactional-email records, support correspondence, reports submitted about a room, event or room membership, the report text and a minimal snapshot of the reported context (including the reported account's email at the time of a participant report), IP address, request/error logs, and audit events concerning significant security and business actions.
- Local storage and cookies:
refresh_tokenandtoken_idcookies maintain authenticated sessions; thelocalecookie and local browser storage remember language and cached translations. These are used for requested functionality, not advertising. Mobile operating systems may request permission before issuing a push token.
We receive data from you, your device/browser, other members who add you to a room, Google or Apple when you choose their optional sign-in, Google when you separately connect Google Calendar, the device/browser speech-recognition service when you request voice input, and payment/platform providers involved in a transaction. When a map is displayed, Google Maps may receive the coordinates being displayed together with technical request information such as the IP address and browser or device information. Reunier does not request the Android device's GPS or background location permission; event coordinates are entered or selected by a user.
2. Purposes and legal bases
We process data:
- to register users, authenticate them, provide rooms/events/participation, maintain sessions, and supply paid access — performance of a contract or steps requested before entering one;
- to display an event location on an interactive map when coordinates have been provided — performance of a contract and our legitimate interests in providing the requested location feature;
- to process purchases, refunds where available, accounting, fraud prevention, and mandatory records — contract, legal obligation, and our legitimate interests in protecting transactions and establishing legal claims;
- to redeem vouchers, grant the associated room-access periods, prevent a voucher from being used more than once, and preserve a proportionate record of the grant — performance of a contract and our legitimate interests in preventing abuse and resolving access disputes;
- to send account verification, email-reveal confirmation, recovery, deletion, receipts, and other service messages — contract and legitimate interests in operating a secure Service;
- to send optional push notifications, including event creation, start, participation-deadline, and deadline-change notices selected by the user's event relationship and notification settings — consent, which can be withdrawn in profile/device settings without affecting earlier processing;
- to create a separate Reunier calendar and keep copies of events in sync only after you connect a supported calendar and participate in those Reunier events — consent and your requested performance of the optional feature; consent can be withdrawn by disconnecting the calendar without affecting your Reunier participation;
- to convert an event description into a reviewable draft only when you activate optional voice input — performance of the feature you requested; microphone and speech-recognition permissions can be denied or withdrawn in device/browser settings without affecting manual event creation;
- to secure, troubleshoot, prevent abuse, administer rooms, and keep proportionate audit logs — our legitimate interests in service security, reliability, and enforcement; and
- to comply with law, respond to lawful requests, and protect legal rights — legal obligation or legitimate interests.
Account, authentication, and core room data are required to provide the relevant features. Optional location details, comments, Google or Apple sign-in, calendar connection, notifications, and voice input need not be supplied, but the related optional feature may not work.
Reunier does not use personal data for targeted advertising and does not make decisions producing legal or similarly significant effects solely by automated means.
3. Disclosure and recipients
Data is disclosed only as needed to:
- RevenueCat and the applicable payment channel (Stripe, Apple App Store, or Google Play) for checkout, transaction validation, and payment administration. Their own notices include RevenueCat's Privacy Policy, Stripe's Privacy Policy, Apple's Privacy Policy, and Google's Privacy Policy;
- Apple for optional Sign in with Apple, its private email relay when Hide My Email is selected, the device's EventKit calendar service when Apple Calendar synchronization is enabled, and iOS speech recognition when voice input is requested; Google for optional Google sign-in, Google Calendar synchronization after a separate authorization, Android speech recognition when voice input is requested, Firebase Cloud Messaging for optional push delivery, and Google Maps Platform for displaying user-selected event locations. A browser may use its own speech-recognition provider. Calendar access is used for the separate calendar created by Reunier. Apple, Google, and browser providers process data under their own privacy notices. Google Maps use is also governed by the applicable Google Maps Platform Terms;
- Resend for transactional email, subject to Resend's Privacy Policy;
- the provider hosting Reunier's virtual private server and any storage, backup, or security provider configured to act for us. The primary database, cache, and encrypted operational backups are operated in Reunier-controlled server storage rather than disclosed to a separate managed database provider;
- other members of a private room, according to the room feature and the user's role; and
- authorities, advisers, or a successor to the Service when lawfully necessary.
Providers may also process data as independent controllers under their own notices. Reunier does not sell personal data.
Reunier's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
4. International transfers
Some providers may process data outside the European Economic Area. Where EU law requires it, transfers rely on an adequacy decision, the European Commission's Standard Contractual Clauses with supplementary measures where appropriate, or another lawful safeguard. Contact us for information about the safeguard relevant to a transfer.
5. Retention
We retain data only for as long as needed for the purposes above:
- active account, room, event, and participation data: while needed to provide the Service or until the account/related content is deleted;
- deletion requests: the account is scheduled for deletion after a 7-day cancellation period; operational deletion is then performed, although residual encrypted backups may remain until overwritten under the backup cycle;
- sessions: inactive sessions are excluded immediately after expiry or revocation and their records are deleted after a fourteen-day security and diagnostic retention period, subject to short technical backup retention;
- verification, email-reveal, OAuth exchange, recovery, and deletion-confirmation data: until expiry or use and then deleted after a seven-day operational cleanup allowance;
- Google Calendar connection data: until you disconnect the integration or delete your account; short-lived OAuth state is retained only until use/expiry and the operational cleanup allowance above. Disconnecting removes Reunier's stored connection and attempts to delete its separate Google calendar and revoke the OAuth grant. If Google is temporarily unavailable, you can also remove the calendar or revoke Reunier from your Google account;
- Apple Calendar identifiers stored locally on the iOS device: until you disconnect the integration, remove the Reunier calendar, clear the app's storage, or uninstall the app. Disconnecting attempts to delete the separate Reunier calendar; calendar permission can also be withdrawn in iOS Settings;
- voice audio: not retained by Reunier; an unapplied transcript remains only in the open voice-input screen, while applied text is retained as a local event draft for up to 30 days or as event data after you create the event;
- payment, refund, tax, and accounting records: for the period required by Spanish tax/accounting law and while legal claims may be brought;
- voucher redemption records: retained as a durable record of the access grant and to prevent re-use. If the linked user or room is deleted, those links are removed while the voucher-code snapshot, capacity and periods granted, room-creation outcome, and redemption time remain;
- dismissed support reports: six months after closure; resolved ordinary reports: twelve months after closure; resolved threat/danger or suspected-illegal-activity reports: three years after closure;
- security and audit events: twenty-four months; and
- records subject to a documented legal hold: only for the concrete investigation, legal request, or establishment, exercise, or defence of claims that justified the hold.
Deletion can be limited where retention is legally required. Payment and audit records may be de-identified by removing the user link rather than erased. We do not claim a fixed backup/log deadline unless it is technically enforced.
6. Account deletion
You can request deletion in the Reunier web or mobile app under Profile → Account deletion. An external explanation and access path is available at reunier.com/en/account-deletion, so the request does not require the Android app to remain installed. If you cannot access your account, email legal@reunier.com from the address associated with it; we may request reasonable verification before acting.
A deletion request schedules the account for deletion after a 7-day cancellation period. You can cancel within that period by signing in and using the same account settings. After the period, the account and associated personal data are deleted or de-identified as described in Section 5, except where retention is required for payment, voucher redemption, security, fraud-prevention, or other legal purposes.
7. Security
We use measures appropriate to the risk, including TLS in transit, password hashing, restricted production access, server-side session controls, token expiry/revocation, and monitoring. No service can guarantee absolute security.
8. Your data-protection rights
Subject to applicable law, you may request access, rectification, erasure, restriction, portability, or object to processing based on legitimate interests. You may withdraw consent at any time. You may also lodge a complaint with the Spanish Data Protection Agency (AEPD) at aepd.es or with the authority where you live or work.
Send requests to legal@reunier.com. We may verify identity. We normally respond within one month; legally permitted extensions or exceptions will be explained. Requests are generally free, subject to the rules for manifestly unfounded or excessive requests.
9. Children
The Service is intended only for adults aged 18 or older. A person under 18 may not create an account or use the Service. Room organizers must not submit a child's identifying information unless they have authority and a lawful basis to do so. Participation counts should be used instead of children's names. Contact us if you believe a minor created an account or a child's personal data was provided improperly.
10. Changes
We may update this notice to reflect legal, technical, or service changes. We will post the new effective date and provide prominent in-app or email notice before material changes where appropriate. A prior version remains applicable to processing that occurred before the change where required by law.
11. Contact
Controller: Volodymyr Lozynskyi, Spain
Privacy/legal: legal@reunier.com
Support: support@reunier.com
No data protection officer has been appointed because the Service does not currently consider that appointment legally required.