Privacy Policy

Last Updated: June 22, 2026

Volodymyr Lozynskyi ("we," "us," "our") operates Reunier (the "Service"). This Privacy Policy explains what data we collect, why we collect it, how long we keep it, and what rights you have.

By using Reunier, you agree to this Privacy Policy.

1. Information We Collect

1.1 Account and Profile Data

When you create and use an account, we collect:

  • Email address
  • Password (stored in a secure hashed form)
  • Basic profile and account settings

If you sign in with Google, we also receive your Google account identifier and profile email.

1.2 Room and Event Data

To provide the service, we collect content you create in the app, such as:

  • Room names and settings
  • Event titles, descriptions, dates, and location text
  • Participation data (adults, children, comments, option quantities)
  • Room display names

1.3 Session and Device Data

To keep accounts secure and signed in, we process:

  • Session records (creation, last activity, revocation status)
  • Basic device and browser information
  • Authentication cookies needed for login

1.4 Payment Data

We do not store full card details.

Payments are handled through RevenueCat, which routes transactions through:

  • Stripe (web)
  • Apple App Store (iOS)
  • Google Play (Android)

We may store payment-related records such as:

  • RevenueCat customer ID
  • Stripe customer ID (web only)
  • Purchase/payment identifiers
  • Refund and chargeback identifiers/status
  • Room, amount, currency, periods purchased
  • Payment status and timestamps

1.5 Recovery and Verification Data

To support account security, we process:

  • Email verification and de-verification tokens
  • Password recovery tokens
  • Recovery code status (active/used/revoked)

1.6 Cookies

We use essential cookies for:

  • Authentication
  • Session continuity
  • Language preference

These cookies are required for core app functionality.

1.7 Log Data

We may keep service and security logs, such as:

  • Login and request activity
  • Error logs
  • IP address and timestamps

2. Why We Use Data

We use personal data to:

  • Create and manage your account
  • Provide rooms, events, and participation features
  • Process payments and keep billing records
  • Process and verify eligible refund requests
  • Process account deletion requests, cancellation requests, and final deletion events
  • Send transactional and security emails
  • Prevent abuse, fraud, and unauthorized access
  • Maintain, improve, and secure the service
  • Comply with legal obligations

3. Data Retention

  • Account data: Kept while your account is active and for a reasonable period after deletion.
  • Account deletion requests: When you request account deletion from profile settings, we set a scheduled deletion date 7 days ahead. During that period, you may cancel the request.
  • Final account deletion: After the scheduled date, account deletion is executed by backend scheduled processing and account access is no longer possible.
  • Session data: Removed after inactivity, logout/revocation, or account deletion.
  • Recovery and verification tokens: Short-lived and automatically expire.
  • Payment records: Retained for 7 years for tax/legal compliance, including refund and chargeback records.
  • Deleted accounts: Personal data is deleted within 30 days, except where law requires longer retention.
  • Room/event data: Removed when related rooms are deleted, subject to legal retention duties.

4. Security

We apply reasonable technical and organizational security measures, including:

  • Encrypted data transmission (HTTPS/TLS)
  • Secure account authentication and session controls
  • Restricted access to production systems
  • Ongoing monitoring for abuse and suspicious activity

No system can guarantee absolute security, but we work to protect your data and respond quickly to incidents.

5. Sharing and Disclosure

5.1 Third-Party Service Providers

We share data only when necessary to run Reunier:

  • RevenueCat: Payment infrastructure across web/iOS/Android. See RevenueCat Privacy Policy.
  • Stripe: Web payment processing. See Stripe Privacy Policy.
  • Apple App Store / Google Play: Mobile in-app purchases handled by Apple/Google under their privacy policies.
  • Resend: Transactional email delivery. See Resend Privacy Policy.
  • Google OAuth: Optional Google sign-in. See Google Privacy Policy.
  • Infrastructure providers: Hosting, storage, and backup services where needed.

5.2 Legal Requirements

We may disclose data when required by law or when necessary to:

  • Comply with legal obligations
  • Protect rights and safety
  • Investigate abuse or fraud
  • Enforce our Terms of Service

5.3 Business Transfers

If Reunier is transferred (for example in a sale or merger), user data may transfer as part of that process, in line with applicable law.

6. Your Rights

Depending on your location (including EU/EEA), you may have rights to:

  • Access your personal data
  • Correct inaccurate data
  • Request deletion of your data
  • Object to certain processing
  • Request portability of your data
  • Withdraw consent where processing is based on consent

To exercise your rights, contact: legal@reunier.app.

We usually respond within 30 days.

7. Children's Privacy

Reunier is not intended for children under the applicable age of digital consent. If we learn that we collected data from a child without valid legal basis, we will delete it.

8. International Data Transfers

Your data may be processed in countries outside your own. Where required, we apply appropriate safeguards under EU data protection rules.

9. Third-Party Links

The Service may link to third-party websites. Their privacy practices are governed by their own policies.

10. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. If changes are material, we will provide clear notice in the app, by email, or by updating the date above.

11. Contact

If you have questions about this Privacy Policy, contact:

Reunier Support

Email: support@reunier.app

Legal Contact

Email: legal@reunier.app

Appendix: Data Processing Summary

Data TypePurposeLegal BasisRetentionThird Parties
Email and password hashAccount accessContractAccount lifetime + 30 daysNone
Session and device dataSecurity and loginContract / Legitimate interestSession lifetimeNone
Room and event contentService operationContractRoom lifetime + 30 daysNone
Participation dataEvent coordinationContractEvent lifetime + 30 daysNone
Payment dataBilling and accountingContract / Legal obligation7 yearsRevenueCat, Stripe, Apple, Google
Verification/recovery dataAccount securityContractUntil expiry/useNone
Log dataSecurity and diagnosticsLegitimate interest30–90 daysNone
Google account IDGoogle loginConsent / ContractAccount lifetimeGoogle