Last Updated: June 22, 2026
Volodymyr Lozynskyi ("we," "us," "our") operates Reunier (the "Service"). This Privacy Policy explains what data we collect, why we collect it, how long we keep it, and what rights you have.
By using Reunier, you agree to this Privacy Policy.
1. Information We Collect
1.1 Account and Profile Data
When you create and use an account, we collect:
- Email address
- Password (stored in a secure hashed form)
- Basic profile and account settings
If you sign in with Google, we also receive your Google account identifier and profile email.
1.2 Room and Event Data
To provide the service, we collect content you create in the app, such as:
- Room names and settings
- Event titles, descriptions, dates, and location text
- Participation data (adults, children, comments, option quantities)
- Room display names
1.3 Session and Device Data
To keep accounts secure and signed in, we process:
- Session records (creation, last activity, revocation status)
- Basic device and browser information
- Authentication cookies needed for login
1.4 Payment Data
We do not store full card details.
Payments are handled through RevenueCat, which routes transactions through:
- Stripe (web)
- Apple App Store (iOS)
- Google Play (Android)
We may store payment-related records such as:
- RevenueCat customer ID
- Stripe customer ID (web only)
- Purchase/payment identifiers
- Refund and chargeback identifiers/status
- Room, amount, currency, periods purchased
- Payment status and timestamps
1.5 Recovery and Verification Data
To support account security, we process:
- Email verification and de-verification tokens
- Password recovery tokens
- Recovery code status (active/used/revoked)
1.6 Cookies
We use essential cookies for:
- Authentication
- Session continuity
- Language preference
These cookies are required for core app functionality.
1.7 Log Data
We may keep service and security logs, such as:
- Login and request activity
- Error logs
- IP address and timestamps
2. Why We Use Data
We use personal data to:
- Create and manage your account
- Provide rooms, events, and participation features
- Process payments and keep billing records
- Process and verify eligible refund requests
- Process account deletion requests, cancellation requests, and final deletion events
- Send transactional and security emails
- Prevent abuse, fraud, and unauthorized access
- Maintain, improve, and secure the service
- Comply with legal obligations
3. Data Retention
- Account data: Kept while your account is active and for a reasonable period after deletion.
- Account deletion requests: When you request account deletion from profile settings, we set a scheduled deletion date 7 days ahead. During that period, you may cancel the request.
- Final account deletion: After the scheduled date, account deletion is executed by backend scheduled processing and account access is no longer possible.
- Session data: Removed after inactivity, logout/revocation, or account deletion.
- Recovery and verification tokens: Short-lived and automatically expire.
- Payment records: Retained for 7 years for tax/legal compliance, including refund and chargeback records.
- Deleted accounts: Personal data is deleted within 30 days, except where law requires longer retention.
- Room/event data: Removed when related rooms are deleted, subject to legal retention duties.
4. Security
We apply reasonable technical and organizational security measures, including:
- Encrypted data transmission (HTTPS/TLS)
- Secure account authentication and session controls
- Restricted access to production systems
- Ongoing monitoring for abuse and suspicious activity
No system can guarantee absolute security, but we work to protect your data and respond quickly to incidents.
5. Sharing and Disclosure
5.1 Third-Party Service Providers
We share data only when necessary to run Reunier:
- RevenueCat: Payment infrastructure across web/iOS/Android. See RevenueCat Privacy Policy.
- Stripe: Web payment processing. See Stripe Privacy Policy.
- Apple App Store / Google Play: Mobile in-app purchases handled by Apple/Google under their privacy policies.
- Resend: Transactional email delivery. See Resend Privacy Policy.
- Google OAuth: Optional Google sign-in. See Google Privacy Policy.
- Infrastructure providers: Hosting, storage, and backup services where needed.
5.2 Legal Requirements
We may disclose data when required by law or when necessary to:
- Comply with legal obligations
- Protect rights and safety
- Investigate abuse or fraud
- Enforce our Terms of Service
5.3 Business Transfers
If Reunier is transferred (for example in a sale or merger), user data may transfer as part of that process, in line with applicable law.
6. Your Rights
Depending on your location (including EU/EEA), you may have rights to:
- Access your personal data
- Correct inaccurate data
- Request deletion of your data
- Object to certain processing
- Request portability of your data
- Withdraw consent where processing is based on consent
To exercise your rights, contact: legal@reunier.app.
We usually respond within 30 days.
7. Children's Privacy
Reunier is not intended for children under the applicable age of digital consent. If we learn that we collected data from a child without valid legal basis, we will delete it.
8. International Data Transfers
Your data may be processed in countries outside your own. Where required, we apply appropriate safeguards under EU data protection rules.
9. Third-Party Links
The Service may link to third-party websites. Their privacy practices are governed by their own policies.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If changes are material, we will provide clear notice in the app, by email, or by updating the date above.
11. Contact
If you have questions about this Privacy Policy, contact:
Reunier Support
Email: support@reunier.app
Legal Contact
Email: legal@reunier.app
Appendix: Data Processing Summary
| Data Type | Purpose | Legal Basis | Retention | Third Parties |
|---|---|---|---|---|
| Email and password hash | Account access | Contract | Account lifetime + 30 days | None |
| Session and device data | Security and login | Contract / Legitimate interest | Session lifetime | None |
| Room and event content | Service operation | Contract | Room lifetime + 30 days | None |
| Participation data | Event coordination | Contract | Event lifetime + 30 days | None |
| Payment data | Billing and accounting | Contract / Legal obligation | 7 years | RevenueCat, Stripe, Apple, Google |
| Verification/recovery data | Account security | Contract | Until expiry/use | None |
| Log data | Security and diagnostics | Legitimate interest | 30–90 days | None |
| Google account ID | Google login | Consent / Contract | Account lifetime |