Effective 27 September 2026. Last updated 27 September 2026.
The short version
- Rejynx works on your phone first. Your bills, the messages and statements they came from, your money in and out, your chats and your settings are kept on your phone, in a database encrypted with a key that stays on it, not on our servers. We can't see them.
- The messages the app reads stay on your phone: your SMS (on Android, only if you allow it), the bill emails it reads in your Gmail (only if you connect it), and anything you paste or import into Add a bill or Money. So do the details of your payments, and your transactions and balances. The app never reads your notifications.
- A chat question is different: it goes as you wrote it. If the phone can't answer a question, the whole question goes to an AI provider (through our server, unless you use your own key), word for word as you typed or pasted it. The app keeps on the phone what it recognises as your bank's message about your account (a debit, a credit, a balance, or an OTP for a payment), but anything else you paste there goes, such as a biller's message or an account number. So paste bill messages into Add a bill and bank alerts into Money, not into the chat, and never type an OTP, a PIN or a password into Rejynx.
- When the phone can't answer a question, the app sends it to our server, which passes it to an AI provider and streams the answer back. For a question about bills or money, or one that names one of your payees, a short summary of each bill goes too: payee, category, amount, minimum due, due date, and whether it's paid. That summary goes for bills read from your SMS too, as for those you typed, pasted or imported from a PDF: those six fields were read from the message, and if a payment read from an SMS or an alert you pasted marked a bill paid, the summary says "paid". Bills from your Gmail never go with a question, to us or to an AI provider: neither a bill read from your Gmail nor one a payment read from your Gmail marked paid. Never the message itself, the sender, the payment's amount, date or reference, account numbers, UPI IDs, or your transactions and balances.
- To our server, questions go sealed: encrypted on your phone so that only our server's process can open them, not the web server in front of it, its logs, or anything on the way. The answer comes back sealed, so only your phone can read it. Inside it too goes a random ID the app made, which counts your phone's cloud answers each day. Beside it, not inside, go only a one-way code from that ID (to limit how many questions one phone sends a minute) and the app's key (the same in every copy). None of them says anything about you.
- If you buy a plan, the store's proof of your purchase goes to our server, sealed the same way, so it can ask Apple or Google which plan you have. Apple or Google gets only the purchase's own ID or token. Our server keeps only the plan and when it ends, linked to your phone (and your account, if you sign in), and a keyed hash of the purchase with the phones and accounts that use it, never the proof.
- Signing in is optional. If you sign in with Apple or Google, our server keeps a small account record: a random ID, a keyed hash of your Apple or Google account ID, your email if they gave one (encrypted), the day you signed up, and your plan and when it ends. It counts your cloud answers each day, by your account or, if you don't sign in, by your phone's random ID, to hold each plan to its daily limit, and forgets the count when the day ends. You can delete your account in Settings at any time.
- Our server doesn't store your questions or the answers. It holds them in memory only while it answers.
- Every company that can receive anything is named here, with what it gets, when, why and for how long: Oracle Cloud (which hosts our server), the AI providers Groq, Cloudflare and OpenRouter (and the model host OpenRouter picks), Apple and Google (to sign you in, only if you choose to; to check a purchase; your backups, only if you turn them on; Gmail, only if you connect it), your UPI app (when you pay) and Zoho (which hosts our email, a report on an answer included). See Who gets what and Who processes data for us. Nothing goes to anyone else.
- You can see and control it. Settings β Where your data goes lists the same recipients in the app. Settings β What left my phone lists the questions that have left your phone (the latest 500): where each went, how many messages of the chat went with it, and which bill fields. The line under each answer from the cloud names who answered: our server, then the model and its provider (with your own key, your provider). Settings β Ask before using cloud makes the app ask you each time.
- With your own AI key, questions go straight from your phone to that provider. Our server never sees them, or the key.
- No ads. We don't sell or share your data. No analytics, crash-reporting, tracking or telemetry tools, and no cookies on our website.
Who we are
Rejynx is made by Raheed Mujawar, Gogol, Aquem, Goa 403601, India ("Rejynx", "we", "us"). We make the Rejynx apps for iPhone and Android, and run the server that answers questions in the cloud and the website at re-jynx.raheed.dev.
For the personal data this policy says we process, we are the controller (under the EU and UK GDPR) and the data fiduciary (under India's Digital Personal Data Protection Act, 2023).
| For | Contact |
|---|---|
| Privacy questions and requests | hello@raheed.dev |
| Grievance Officer (India) | Raheed Mujawar, hello@raheed.dev |
| Our representative in the EU (Article 27 GDPR) | None yet: Rejynx isn't offered in the EU or EEA yet |
| Our representative in the UK (Article 27 UK GDPR) | None yet: Rejynx isn't offered in the UK yet |
| Data protection officer | Raheed Mujawar (hello@raheed.dev) |
What this policy covers
The Rejynx apps, our server, our website and anything you send us by email. It doesn't cover your UPI app, your bank, the App Store or Google Play, or an AI provider you use with your own key. They have their own privacy policies.
What stays on your phone
| What | Kept | Until |
|---|---|---|
| Your bills: payee, category, amount, minimum due, due date, statement date, the account's last four digits, whether and when it was paid, in full or in part (and the payment's reference number, when a payment message gave one, and whether that message was an SMS or an email in your Gmail), any snooze, how sure the app was of its reading, where it came from (typed in, pasted, a PDF, your SMS or your Gmail), the sender, and the original message or statement text | The app's database on your phone | You delete the bill, or the app |
| Your money (Money): the transactions and balances read from your bank's SMS or the alerts you paste (amount, in or out, the other party, the account's last digits, the date and the bank's reference), the categories you give them, and your budgets | The app's database | You delete a transaction, or the app |
| The SMS reader's notes (Android, if you allow SMS): how far into your inbox it has read; for a few days, a one-way fingerprint of each message it found something in, so none is read twice; and the readings waiting for you to check, each with its message | The app's database | A few days for the fingerprints; the readings until you check or skip them; the rest until you delete the app |
| Gmail, if you connect it: the IDs of the emails already read, and the readings waiting for you to check. The sign-in token is in the phone's secure storage on iPhone; on Android, Google Play services keeps the permission | The app's database, and the phone's secure storage | 100 days for the IDs; everything until you disconnect Gmail |
| Your chats: your questions and the answers, and any π or π you gave an answer | The app's database | You delete the chat, or the app |
| "What left my phone": for each question that left your phone, when it left, where it went, the model that answered, the first 60 characters of the question, how many messages of the chat went with it, and which bill fields went (their names, not their values) | The app's database | You delete the app |
| Your settings: reminder timing (and a note of the last reminder set for each bill), Hide amounts, the mode and provider you picked, "Ask before using cloud", your "Not a bill" rules, and the UPI ID you typed for each biller | The app's database | You delete the app |
| The phone's random ID (described below): 32 random bytes the app makes the first time it asks our server anything | The phone's secure storage (the iPhone Keychain; on Android, encrypted with a key in the Android Keystore), for this phone only | On Android, you delete the app. On iPhone, the Keychain keeps it when the app is deleted, so a new install is the same phone to our server, and the day's free cloud answers don't start again; it goes when the iPhone is erased |
| The widget's copy (iPhone): what the Next Bill widget shows, for today and each of the next 30 days: your next bill's payee, amount, category and when it's due ("In 3 days"), a link that opens it in the app (with the app's own ID for it), and what's due this week, as a total and a count (no amounts while Hide amounts is on) | A container on your phone that only the app and its widget can read, kept out of iCloud and computer backups | The app writes it again as your bills change, or you delete the app |
| Your own AI key, if you add one | The phone's secure storage (the iPhone Keychain; on Android, encrypted with a key in the Android Keystore), for this phone only | You remove it (see Delete your data) |
| Your account, if you sign in: the session our server gave (a random token), the account's email and plan as our server described them, and with Apple, Sign in with Apple's ID for you (so the app can ask Apple whether you're still signed in) | The phone's secure storage, for this phone only | You sign out, delete the account, or delete the app. On iPhone the Keychain keeps it when the app is deleted, where only Rejynx can read it: installed again, Rejynx deletes it before anything else, and starts signed out |
- The widget (iPhone, if you add it to your Home Screen or Lock Screen) shows your next bill and what's due this week from that copy. It can show amounts on your lock screen: Settings β Hide amounts leaves them out, and your iPhone hides them while it's locked if you turn off Lock Screen widgets (Settings β Face ID & Passcode β Allow Access When Locked).
- PDF statements you import are read on your phone, inside the app, with no network access. The app keeps the bill it finds and the statement's text as that bill's original text. It reads its own temporary copy of the file and deletes that copy once it's read; your own file isn't touched.
- How it's protected: the app's database is encrypted (SQLCipher) with a key made on your phone and kept in its secure storage (the iPhone Keychain; on Android, under a key in the Android Keystore), for this phone only. Your phone's app sandbox keeps other apps out. When you delete a chat or a bill, the app overwrites it in the database file rather than leaving it readable.
- Backups are off unless you turn them on (Settings β Back up to iCloud, or Back up to Google on Android). While they're off, the database is kept out of iCloud and computer backups on iPhone, and out of Google backups and phone-to-phone transfers on Android, along with the reminders the app has scheduled: lose the phone, and what the app kept is gone. Turned on, the whole database goes, encrypted: your bills, chats, settings and Money's transactions, balances and budgets.
- On iPhone, Apple (iCloud) receives it: the encrypted database goes into your iCloud backup (and computer backups), and a copy of its key into your iCloud Keychain, which Apple encrypts end to end, so Apple holds the encrypted file but not a key that opens it. It goes each time your iPhone backs up, while backups are on. Apple keeps it as long as you keep that backup, under its iCloud terms, which let it delete a device's backups once the device hasn't backed up for 180 days. Turning backups off in the app deletes the key's copy from iCloud Keychain, so backups already made can no longer be opened.
- On Android, Google receives it: the database and its key go only into a backup that's encrypted end to end with your screen lock (Android 9 or later; with no screen lock, nothing is backed up) or a direct phone-to-phone transfer, never a backup Google could read. It goes when Android backs up (usually overnight, while charging). Google keeps only the latest backup, under its own terms, and erases it if you don't use the phone for 57 days.
- Your own AI key stays on the phone it was saved on: no backup brings it to another.
We have no access to anything on your phone.
Your SMS, on Android
Only if you allow it (the app explains first, then Android asks), Rejynx reads the SMS on your Android phone to find bills, the payments that paid them, and money in and out of your accounts: the last 60 days the first time, then each new message while the app is open. It never sends an SMS. iPhone doesn't let apps read SMS.
- Read on your phone, and kept there: the bills it finds, which of them were paid, and, from your bank's messages, your transactions and balances (in Money). A message it isn't sure about waits, whole, for you to check or skip. From any other message (a personal message, an OTP, an offer) it keeps nothing.
- Never leaves your phone: the messages themselves, who sent them, OTPs and personal messages, account numbers, a payment's details, and your transactions and balances. Questions about your money are answered on your phone.
- Goes only when you ask about your bills: each bill's payee, category, amount, minimum due, due date and whether it's paid, as for a bill you add yourself (see Questions the phone can't answer), unless a payment read from your Gmail marked it paid (below). They're sealed on your phone so only our server's process can open them; our server passes them to the AI provider that answers and keeps none of it. With your own AI key, they go straight to your provider over HTTPS.
- Turn it off any time in Android's settings (Apps β Rejynx β Permissions β SMS). The bills and money it found stay until you delete them, or the app.
Your Gmail, if you connect it
If you connect Gmail (Connect, or Settings β Gmail), your phone signs in to Google with read-only access and reads bill emails itself: a search for mail from billers and banks, the last 90 days the first time, then what came since, each time the app opens. Only Google is asked, and it gets what any Gmail app sends it: your sign-in, the search and the requests for each message, from your phone. Google already holds your mailbox, and keeps its own records of these requests under its privacy policy. Nothing from your Gmail reaches our server or an AI provider: not the sign-in token, the emails, or the bills found in them. The bills found are kept on your phone like any other, but never go with a question, to us or to an AI provider, even one you use with your own key. Neither does a bill that a payment read from your Gmail marked paid or part-paid (the app's check settled it, or you tapped Mark it paid), however the bill was added. The phone still answers the questions it can about them itself, from all your bills and without an AI model. When a question to the cloud leaves bills from your Gmail out, a note under the answer says how many ("2 Gmail bills kept on phone"); the note and its count stay on your phone. A bill you paste into Add a bill yourself, even from an email, is a pasted bill, and goes as one. Disconnect (Settings β Gmail) takes back the app's access at Google, deletes the token and forgets what the checks kept; the bills already found stay.
What the app reads in Gmail is used only to find your bills and to answer your questions about them. It isn't used for advertising, sold, or read by anyone at Rejynx. Rejynx's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
What leaves your phone, and where it goes
1. Questions the phone can't answer
The app answers some questions itself, such as what's due this week, and those stay on your phone along with their answers. On an iPhone with Apple Intelligence, Apple's model on your phone answers some more about your money and bills, such as why your spending went up; those stay on your phone too, since the model runs on it, and it's told nothing from your Gmail. Anything else goes to our server, which passes it to an AI provider and streams the answer back. Each such question sends:
- your question, exactly as you typed or pasted it (up to 4,000 characters), including any message, number or other text you put in it;
- earlier messages of that chat that went to the cloud: at most the last 20 messages, counting the new question, each cut to 8,000 characters. Never what the phone answered, a question you chose to keep on the phone, or anything you sent with your own key;
- for a question about bills or money, or one that names one of your payees: that is, a question with one of the words bill(s), due, pay, paid, payment(s), card(s), EMI, salary, money, spend, spent, owe, amount or Rs, or the βΉ sign; or with a whole word of three letters or more from the name of any of your bills' payees (for a bill from "Tata Play", the word "play" counts, but not "playlist"): a summary of up to 50 bills, your upcoming bills and those paid in the last 60 days, each typed, pasted, imported from a PDF or read from your SMS, with only these fields: payee name, category, amount, minimum due, due date, and paid or upcoming. Never a bill from your Gmail, or one a payment read from your Gmail marked paid (Your Gmail): a note under the answer says how many it left out ("2 Gmail bills kept on phone"). Before you've added a bill of your own, these are the app's sample bills, and the line under the answer says so ("question + 3 sample bills"); the three samples labelled as from Gmail are left out the same way;
- your choice of mode (Auto, Fast or Thinking) and provider; Sealed on the way: the app encrypts all of this on your phone with our server's public key (HPKE, the Internet standard RFC 9180) before it sends it, inside the usual HTTPS connection. Only our server's own process has the private key that opens it: the web server in front of it, its logs and anything between your phone and our server see only the sealed text. The answer comes back sealed with a key from the same exchange, so only your phone can read it.
Sealed with it, besides: a random ID that the app makes on your phone the first time it asks our server anything (32 bytes from the phone's secure random generator, kept in its secure storage: see What stays on your phone), and if you're signed in, your session. Our server counts your phone's cloud answers each day by the ID, and holds a plan bought on your phone by it (Our server). It isn't linked to your name, email or anything else.
Beside the sealed question, not inside it, go two request headers, which the web server in front of ours and our server can read:
- a code worked out from that random ID (a one-way hash of it, which can't be turned back into the ID). It's used only to limit how many questions one phone can send per minute;
- the app's key, which is the same in every copy of the app and says nothing about you.
What can't be sealed: that you asked something, when, and how big it was; those two headers; and the headers of the answer, which say which provider and model answered, whether it was Fast or Thinking, and with OpenRouter which host. On Auto, Thinking means the question was long (over 400 characters) or had a planning word such as "plan", "compare", "budget" or "should I", so that header says a little about the question.
Like any internet connection, our server also sees your IP address and your app's technical user agent (such as the app and operating-system version).
Never sent by the app itself: the text of any SMS, email, payment alert or PDF the app reads or you give it; who sent it; any bill read from your Gmail, or one a payment read from your Gmail marked paid, not even its six fields; OTPs and personal messages; account or card numbers; UPI IDs; your notifications; the details of a payment (its amount, date, reference number or account); your transactions, balances and budgets; your contacts, location, photos or files; advertising identifiers. Our server checks every request against the list above and refuses one that carries anything else about a bill, before any AI provider sees it.
The exception is what you write in a question. The app sends a question as you wrote it, and our server can't check what's in it. A bank's message about your account pasted into the chat (a debit, a credit, a balance, or an OTP for a payment) is recognised and kept on the phone, but the app can't recognise everything: if you paste a biller's message, a statement or an account number into a chat question, and the phone can't answer it, that text goes to our server and an AI provider like any other question (or, with your own key, straight to your provider). To have a bill message read on your phone only, use Add a bill β Paste a bill message, and for a bank's alert, Money.
You control it. With Settings β Ask before using cloud turned on, each question waits in a card that says what it would send and where, until you tap Send or Keep on phone. Settings β What left my phone records each question as it leaves and shows the latest 500: when it left, the first 60 characters of the question, where it went, how many messages of the chat went with it, which bill fields went (their names, not their values), and how it ended.
2. Our server
Our server is a relay, with a small database for accounts, plans and each day's counts. It opens your sealed question in its own memory, adds Rejynx's short instructions for the AI (with today's date and, for a bill question, the bill summaries), sends the question to an AI provider, and streams the answer back to you, sealed. It never writes a question, an answer or a bill anywhere. It runs on Oracle Cloud in Singapore, on a disk Oracle encrypts at rest (AES-256).
| What | How it's kept | For how long |
|---|---|---|
| Your question, the chat and the bill summaries | In memory, opened only inside our server's process, and only while it answers. Our server never writes them to a file, a database or a log. The web server in front of it (nginx) may put a large request in a temporary file on the server's disk while it passes it on: sealed, so unreadable without our server's key, and deleted when the request ends | Until the answer ends (at most 5 minutes) |
| A random number sealed into each question | In memory, so a copy of a sealed question sent again can be refused (each of the server's processes keeps its own list; an answer to a copy is sealed afresh, and no one but your phone could read it) | 5 minutes |
| The random ID, and the code beside each request | The code: in memory, to limit questions per phone. The ID: opened only in our server's memory, and in its database only as a keyed hash (HMAC, with our own key), beside today's count of your phone's cloud answers and a plan checked from your phone | The code in memory: forgotten within about 90 seconds of your last question. The count: until the day is over |
| Your account, if you sign in (Signing in) | In its database: a random ID; a keyed hash (HMAC) of your Apple or Google account ID, so it can find your account without keeping that ID; your email, if Apple or Google gave one, encrypted with our own key (AES-256-GCM); the day it was made; your plan and when it ends | Until you delete the account. A plan that ended is forgotten 30 days later |
| Your sessions | For each phone signed in: the SHA-256 of its session's random token (the phone keeps the token), and the day it was last used | Until you sign out on that phone, delete the account, or leave it unused for 180 days |
| A plan checked from your phone | The plan and when it ends, by a keyed hash of your phone's random ID, so your phone keeps its plan's limit when you're not signed in | Until 30 days after the plan ends, or you delete your account on that phone |
| Each purchase checked | A keyed hash (HMAC) of the store's ID for it (Apple's original transaction ID, Google's purchase token), with the phones (by the keyed hash of their random ID) and accounts that checked it, and the day each last did: so one purchase gives its plan to 5 phones and 2 accounts at most, not to everyone its store's proof is passed to | A phone or account: 30 days after it last checked the purchase, or when you delete your account on that phone |
| Each day's cloud answers | A count for your account (signed in) and for your phone (by its keyed hash), to hold each plan to its daily limit. Never what was asked | Until the day is over (midnight UTC, 5:30 am in India) |
| Your IP address | The web server in front of ours (nginx) holds it briefly in memory to limit requests per address, and writes it to its access log with the time, the path asked for (such as /v1/chat), the response code and size, and the user agent. Never what you asked | 14 days |
| The web server's error log | When nginx turns a request away for going over the per-address limit, or can't reach our server: the time, your IP address and the request line (such as POST /v1/chat). Never what you asked | 14 days |
| Our server's error lines | When a provider fails: which provider and model, and the error message it gave (usually short). Our server doesn't put your question, the answer, your IP address or your random ID in them | Until overwritten: the log is capped at 30 MB |
3. The AI providers
On Auto, our server asks Groq first, then Cloudflare (Workers AI), then OpenRouter, moving on when one is busy or down. You can pick one in the model menu. The provider receives what our server sends: Rejynx's instructions, the chat and any bill summaries, with our account's key. It sees our server's address, not your IP address, your random ID or anything else about you. The line under each answer names the model and the provider that gave it.
We ask each provider for no training and no retention wherever it offers a way to: on every request to OpenRouter, and in Groq's account settings, where zero data retention is on. Here is what each says it does, in its own words, and where it can't promise that:
| Provider | Keeps what it's sent? | Trains on it? |
|---|---|---|
| Groq, Inc. (United States) | No. Zero data retention is on for our Groq account (a setting in its Data Controls), so Groq doesn't log or store what our server sends it, or its answers: "When ZDR is enabled, Groq will not retain customer data for system reliability and abuse monitoring" (Your Data) | No: "Groq is not permitted to use Inputs or Outputs for training or fine-tuning any AI Model Services or other models, unless explicitly granted permission or instructed by Customer" (Services Agreement) |
| Cloudflare, Inc. (United States; runs models in its data centres worldwide) | Its policy says only that content "may be stored by Cloudflare if you specifically use a storage service" with Workers AI, which we don't (Data usage). It doesn't promise in so many words that it keeps nothing, and gives no retention period. It has no zero-retention setting to turn on | No: "Cloudflare does not use your Customer Content to (1) train any AI models made available on Workers AI or (2) improve any Cloudflare or third-party services" (Data usage) |
| OpenRouter, Inc. (United States) | "OpenRouter does not store your prompts or responses, unless you opt in" (off by default; we're confirming ours is off). It does keep metadata such as token counts and timing, and sorts a small sample of prompts into categories, stored "completely anonymously and never associated with your account or user ID" (Data collection) | Not OpenRouter itself: "OpenRouter does not use your Inputs or Outputs for model training." But "OpenRouter cannot control Model Provider-side training once user data is transmitted to a training-permitted Model Provider" (Privacy policy) |
| The model host OpenRouter picks (varies from question to question) | Our server asks OpenRouter, on every request, for hosts with "a Zero Data Retention policy" that "do not collect user data" (Provider selection). OpenRouter warns that most of the free hosts we use keep or train on prompts; our settings leave those out, and when no other host is free, OpenRouter answers with an error rather than use one. Which host keeps what is the host's own promise as OpenRouter knows it ("not a definitive source of third party data policies"), not a guarantee | As for keeping: only hosts OpenRouter lists as not collecting data are used |
The full list, with what each receives, when and where, is on Who processes data for us. Each of these companies is bound by its agreement with us to protect the data at least as well as this policy describes.
4. With your own AI key
If you add your own key (Settings β Your own AI key), the app sends your questions, with the same instructions, chat and bill summaries (bills read from your SMS included; bills from your Gmail never go, as with our server), straight from your phone to that provider, over HTTPS. They aren't sealed as they are for our server, since the provider's service takes them only as they are. Our server receives nothing: not the question, not the answer, not the key. When you save the key, the app checks it once with the provider, on an address that runs no model. On OpenRouter, the app asks for the same private routing as our server. Because these requests come straight from your phone, the provider also sees your IP address and your app's technical user agent, as any website you visit does; our server isn't there to stand in between.
Your own agreement with that provider (its terms and privacy policy) covers what it does with your questions, and your own account's settings decide what it keeps, not ours: our zero data retention at Groq covers only our account. Any charges go to your account with it.
5. Paying a bill
When you tap Pay, the app opens your UPI app (the one you choose, on the same phone) with the payment filled in: the payee's UPI ID (the one you typed), the payee's name, the amount, and a short note made of the payee's first word, the account's last four digits if known, and "bill" (such as "HDFC 9012 bill"). It gets them only when you tap Pay, so it can make the payment you then confirm. Your UPI app, your bank and the UPI system handle the payment, and the payee receives the note; each keeps its record of the payment under its own terms and the UPI system's rules, which we don't control. Rejynx never sees your UPI PIN, never moves money, and gets nothing back from your UPI app. When you come back, the app asks whether the payment went through; your answer stays on your phone.
6. Reminders
Bill reminders are notifications your phone schedules itself. No push service is used, so nothing goes through a server. A reminder shows the payee, the amount and the due date, including on your lock screen; Settings β Hide amounts leaves the amount out, and you can hide notification previews in your phone's settings. To stop reminders, turn off Rejynx's notifications in your phone's settings: the next time you open the app, it cancels the ones it had set.
7. The provider list
When the chat opens (the first time) and each time you open the model menu, the app asks our server which AI providers it has, so the menu can offer them. The request carries only the app's key: no question, no random ID, nothing about you beyond what any connection shows (your IP address, in the web server's access log).
8. Checking your plan
Plans are bought through the App Store or Google Play: Apple or Google takes the payment, and we never see your card. A plan belongs to the Apple or Google account that bought it. To know which plan you have, the app asks our server to check the purchase:
- What goes to our server: the store's proof of the purchase, your phone's random ID, and if you're signed in, your session, and nothing else about you. On iPhone that's the signed transaction the App Store gave the app (it names the product, its dates and the transaction's ID); on Android, Google Play's purchase token. It's sealed on your phone the same way as a question, so only our server's process can open it, and the answer comes back sealed. The code from the random ID and the app's key go beside it, as with a question.
- When: when you buy or restore a plan, about once a day while you have one, when its date passes, and when you come back from managing your subscription.
- Who else gets it, and why: to confirm the plan, our server asks the store that sold it. Apple (its App Store Server API) gets the transaction's original ID, and Google (its Play Developer API) gets the purchase token: only what they issued themselves, and nothing else about you. They answer with the plan's state (active, renewed, refunded, cancelled). Our server passes that back to your phone, and keeps only the plan and when it ends, linked to your phone and, if you're signed in, your account, so each plan's daily limit applies; and a keyed hash of the purchase with the phones and accounts that use it, so one purchase gives its plan to 5 phones and 2 accounts at most (Our server). The purchase itself isn't written to a file, a database or a log.
- How long Apple and Google keep it: they already hold your purchase as the store that sold it, and keep their records of it under their own privacy policies.
The app keeps the plan our server last confirmed, on your phone.
9. Visiting our website
The server that sends you our website's pages (Oracle Cloud Infrastructure, Singapore (the same server as the Rejynx API)) keeps a standard access log: your IP address, the time, the page asked for, the response and your browser's user agent. We use it only to keep the site running and secure, and it's deleted after 14 days. The website sets no cookies (see Cookies).
10. Emails you send us
If you email us, we get your email address and whatever you write (and anything you attach). We use it only to answer you, and keep it for 12 months after the conversation ends. Our mailbox is hosted by Zoho Mail (Zoho Corporation), which holds your emails for us, in India (Zoho's India data centre), only as long as we keep them, and uses them for nothing of its own.
Reporting an answer. Under an AI answer, π then Report starts an email to us in your own mail app, which you read, add to and send yourself (or not). It starts with only where the answer came from, the line under it (such as "Sealed Β· Groq Β· gpt-oss-20b"): never the answer, your question or anything else of yours. You add what was wrong, and the answer if you choose (you can select and copy it). Once sent, it's an email like any other, kept as above. We use a report only to look into that answer and to make answers better. π and π themselves stay on your phone, with the chat, and go to no one.
11. Signing in, if you choose to
You don't need an account: everything but your plan's place on other phones works without one. If you sign in (on Welcome, or Settings β Sign in):
- With whom: Apple (Sign in with Apple, on iPhone) or Google (on either phone), on their own sheet. With Apple, and with Google on iPhone, the app asks only for your email, and Apple lets you hide it behind a private relay address. On Android, Google's sign-in (Credential Manager) has no way to ask for less: Google gives the app your name and profile picture with your email. Either way, never your Gmail or anything else (connecting Gmail is separate, above).
- What goes to our server: the identity token Apple or Google gave your phone (it says who you are to them: an ID for you, your email if you shared it, that it's for Rejynx, and from Google on Android your name and profile picture), with a random number your phone made for this sign-in, sealed as a question is. Our server checks it with Apple's or Google's public keys, which it fetches from them (that request carries nothing about you), and reads only your ID with them and your email: it keeps neither your name nor your picture.
- What our server keeps, as Our server lists: a random account ID, a keyed hash of your Apple or Google account ID, your email if they gave one (encrypted), the day it was made, your plan and when it ends, a hash of each phone's session, and today's count of your cloud answers. Your phone keeps the session in its secure storage, and sends it, sealed, with each question and plan check.
- Why: so your plan works on all your phones, and each plan's daily limit counts your cloud answers wherever you ask. Answers on your phone, and questions sent with your own AI key, never count.
- Apple and Google: they run the sign-in, so they know you use your account with Rejynx, under their own privacy policies. When you delete an account you made with Apple, your phone shows Apple's sheet once more, and our server sends Apple the one-time code it gives, to take back Rejynx's access to your Apple Account (Sign in with Apple's REST API). Nothing is sent to Google when you delete an account made with Google; you can remove Rejynx in your Google Account's connections.
- Signing out ends that phone's session on our server and forgets the account on the phone. Deleting the account (Settings β Delete account) deletes everything our server keeps for it at once: see Delete your data.
12. Not built yet
Nothing is planned that would send anything new. We'll tell you in the app before anything new leaves your phone.
Who gets what
Every company that can receive anything from Rejynx, and only when a feature you use needs it. The app lists the same in Settings β Where your data goes, and Who processes data for us has the details.
| Who | What it gets | When | Why | How long it keeps it |
|---|---|---|---|---|
| Our server, run by us, hosted by Oracle Cloud in Singapore | Sealed: your question, the chat's earlier cloud messages, bill summaries (six fields), your choice of mode and provider, the store's proof of a purchase, your phone's random ID, and if you sign in, the identity token Apple or Google gave you, then your session. Beside them: a code from the random ID, the app's key, your IP address and the app's user agent. Oracle runs the machine and never sees inside the sealed parts | When you send a question to the cloud, when the app checks your plan, when you sign in or out or delete your account, and when it asks for the provider list or the plans | To answer you, to confirm your plan, to keep your account, to hold each plan to its daily limit, and to limit abuse | Questions and purchases: in memory only, until the answer ends (at most 5 minutes). Your account (email encrypted): until you delete it. Your plan: 30 days after it ends. A purchase's phones and accounts: 30 days after each last checked it. Each day's counts: until the day ends. The code from the random ID, in memory: about 90 seconds after your last question. IP addresses in the web server's logs: 14 days |
| Apple or Google, to sign you in | Your phone's sign-in on their own sheet (your email, if you share it; on Android, Google gives the app your name and picture too, which our server doesn't keep). With Apple, when you delete your account: from our server, the one-time code Apple's sheet just gave, to revoke Rejynx's access | Only if you sign in, and when you delete an account made with Apple | So your plan follows you across phones | Your Apple or Google account, under their privacy policies |
| Groq, Cloudflare (Workers AI) or OpenRouter and the model host it picks | From our server: Rejynx's instructions, your question, the chat's earlier cloud messages and any bill summaries. Not your IP address or random ID | When our server passes on a question (on Auto, Groq first, then Cloudflare, then OpenRouter; or the one you pick) | To write the answer | Their own policies, quoted in The AI providers: Groq keeps nothing (its zero data retention is on for our account); Cloudflare stores it only with a storage service, which we don't use, but gives no retention period; OpenRouter doesn't keep it, and is asked for hosts that keep nothing. None of them trains on it, by its own policy |
| Apple or Google, as the store | From our server: the purchase's own ID (Apple) or token (Google), nothing else | When the app checks your plan | To confirm which plan you have | Their own purchase records, under their privacy policies. We keep nothing |
| Apple (iCloud) or Google (Android backup) | The app's whole database, encrypted, Money's records included; the key only in iCloud Keychain (end-to-end encrypted) or in a backup encrypted with your screen lock | Only if you turn backups on, each time the phone backs up | So you can restore on a new phone | As long as the backup exists (see What stays on your phone) |
| Google (Gmail) | Your phone's requests to your own mailbox, with your sign-in | Only if you connect Gmail, each time the app opens | To find your bills | Google's own records, under its privacy policy |
| Your UPI app | The payee's UPI ID and name, the amount and a short note | When you tap Pay | To make the payment you confirm | Its own records, under its terms and the UPI system's rules |
| Zoho (Zoho Mail) | Your email and what you write (a report on an answer starts with only where the answer came from) | When you email us, or send a report | To host our mailbox | 12 months after the conversation ends |
| Our website's host (Oracle Cloud Infrastructure, Singapore (the same server as the Rejynx API)) | Your IP address, the time, the page and your browser's user agent | When you visit the website | To serve the site | 14 days |
With your own AI key, your questions go only to the provider you chose, under your own agreement with it (With your own AI key). Nobody else receives anything from Rejynx: no analytics, crash-reporting, advertising or tracking company, and no data broker.
No ads, no selling, no tracking
- We don't show ads, and we don't sell your personal data or share it for advertising.
- We don't use analytics, crash-reporting, advertising, tracking or telemetry tools, in the app or on our server, and we don't use your phone's advertising identifier.
- We don't build a profile of you, and we don't use your data to train AI models.
- Our website sets no cookies and loads nothing from other companies (see Cookies).
- The messages the app reads or you give it, the details of your payments, and your transactions and balances stay on your phone (unless you turn backups on: then Apple or Google keeps them in your encrypted backup). What does leave it is described above: the questions you send to the cloud, as you wrote them, and with a bill question a short summary of your bills (never those from your Gmail), sealed for our server; and, if you buy a plan, the store's proof of your purchase, sealed the same way.
Why we use data, and on what legal basis
| Purpose | Data | EU and UK GDPR | India (DPDP Act) |
|---|---|---|---|
| Answering the questions you send to the cloud | Your question, the chat, bill summaries, your choice of mode and provider | Performance of our contract with you (Article 6(1)(b)) | Your consent (section 6); for data you give us to get an answer, the legitimate use in section 7(a) |
| Checking your plan with Apple or Google | The store's proof of your purchase | Performance of our contract with you (Article 6(1)(b)) | As above |
| Your account, and each plan's daily limit | The identity token from Apple or Google, your account record (with your email, if given), sessions, your plan, each day's counts | Performance of our contract with you (Article 6(1)(b)); you choose to sign in | Your consent (section 6), given by signing in; for the limits, the legitimate use in section 7(a) |
| Keeping the service safe, available and fair: rate limits, the free plan's daily limit, one purchase given to a few phones, and abuse prevention | The random ID and its code, a purchase's keyed hash with its phones and accounts, your IP address, server logs (access and error logs) | Our legitimate interest in running a secure service (Article 6(1)(f)) | Your consent, and our duty to keep reasonable security safeguards (section 8(5)) |
| Looking into an answer you report | Your report (an email you send us) | Legitimate interests (Article 6(1)(f)) in answers that are right and safe | Your consent (section 6), given by sending it |
| Fixing problems | Our server's error lines (designed to hold no personal data) | Legitimate interests (Article 6(1)(f)) | As above |
| Running our website | Visitors' IP address, time, page, user agent, in the website host's access log | Legitimate interests (Article 6(1)(f)) in a working, secure website | As for rate limits: consent through this notice, and our duty of reasonable security safeguards (section 8(5)) |
| Answering your requests and complaints | What you send us | Legal obligation (Article 6(1)(c)) and legitimate interests | Legitimate use (section 7) and our duties under sections 8(10) and 13 |
| Meeting legal obligations, such as keeping breach records or answering lawful requests | Only what's needed | Legal obligation (Article 6(1)(c)) | Legitimate use (section 7) |
You don't have to send anything to the cloud. Sending a question to our server is optional, not something the law or our terms require: the app works on your phone without it (your bills, reminders, paying and the questions the phone can answer). If you don't send questions to the cloud, or you use your own key, only the answers the phone can give itself are available through us.
Elsewhere, we rely on performing our contract with you or on your consent, as the local law allows. Where we rely on consent, you can withdraw it at any time, as easily as you gave it: turn on "Ask before using cloud", use your own key, or stop using the cloud features. That doesn't affect what was processed before.
Where data is processed
| Where | What |
|---|---|
| Your phone | Almost everything, wherever you are |
| Singapore | Our server (Oracle Cloud) |
| United States and worldwide | The AI providers (see above); Apple and Google when they check a purchase, and your backup if you turn backups on |
| India (Zoho's India data centre) | Emails you send us (Zoho Mail) |
When data moves between countries, we use the safeguards the law of your country provides:
- EU and EEA: the EUβUS Data Privacy Framework where a US provider is certified under it, otherwise the European Commission's Standard Contractual Clauses (Decision 2021/914), with an assessment of the destination's laws.
- UK: the UK Extension to the Data Privacy Framework, or the UK International Data Transfer Agreement or Addendum.
- India: transfers outside India are allowed except to countries the government restricts by notification (DPDP Act section 16). We'll follow any such restriction.
- Saudi Arabia, the UAE and other countries: the transfer mechanisms their laws allow, such as standard contractual clauses, or your consent where the law requires it.
You can ask us for a copy of the safeguards we rely on.
Your rights
Most of your data is on your phone, where you can see it, change it and delete it yourself, whenever you like (see Delete your data). For anything we hold, email hello@raheed.dev. It's free. We'll acknowledge your request within 48 hours and answer within one month; if we need longer, as the law allows for complex requests, we'll tell you why.
What we hold is very little. If you sign in, we hold your account (with your email, if Apple or Google gave it), which you can delete yourself in Settings, or ask us to. Nothing else we hold carries your name: to find log lines about you, we may ask for the approximate time and your IP address. We'll only use what you give us to answer you.
EU, EEA and UK
Under the GDPR and the UK GDPR you can ask us to: tell you what we hold and give you a copy (access); correct it; delete it; limit how we use it; send it to you or another company in a reusable format (portability); and stop using it where we rely on legitimate interests (objection). You can withdraw consent at any time. You can complain to the data protection authority where you live or work: in the UK, the Information Commissioner's Office (ico.org.uk). In the UK you can also complain to us directly (a right in force since 19 June 2026): we'll acknowledge your complaint within 30 days, look into it without undue delay, and tell you the outcome.
India
Under the DPDP Act you can: get a summary of your personal data we process and who we've shared it with (section 11); have it corrected, completed, updated or erased (section 12); have your grievances answered by our Grievance Officer (section 13); nominate someone to exercise your rights if you die or can't (section 14); and withdraw your consent at any time (section 6(4)). If you're not satisfied with our Grievance Officer's answer, you can complain to the Data Protection Board of India (the Act asks you to come to us first, in section 13(3)). The Board works as a digital office: you'll be able to file a complaint and follow it online, on its portal or its mobile app. These rights and the complaint route apply from 13 May 2027, when those parts of the Act take effect; we answer requests now, and we'll add the address of the Board's portal here once the Board publishes it.
Grievance Officer: Raheed Mujawar, hello@raheed.dev, Gogol, Aquem, Goa 403601, India. We acknowledge within 48 hours and resolve within one month.
Middle East
Data protection laws in Saudi Arabia, the United Arab Emirates, Qatar, Bahrain, Oman, Kuwait and Egypt give you similar rights: to be told how your data is used, to get a copy, to have it corrected or deleted, and to withdraw consent. Contact us to use them. You can also complain to your regulator: in Saudi Arabia, the Saudi Data and AI Authority (SDAIA); in the UAE, the UAE Data Office; in Qatar, the National Cyber Security Agency; in Bahrain, the Personal Data Protection Authority; in Oman, the Ministry of Transport, Communications and Information Technology; in Kuwait, the Communication and Information Technology Regulatory Authority (CITRA); in Egypt, the Personal Data Protection Center.
California and other US states
Under the California Consumer Privacy Act (as amended by the CPRA), you can ask to know what personal information we collected about you, to delete it and to correct it. You won't be treated differently for using these rights. You can use an authorised agent; we may ask them for proof.
In the last 12 months we have collected: identifiers (the random ID, IP address; if you sign in, your email and a keyed hash of your Apple or Google account ID), internet activity (server logs), the content of the questions you send to the cloud and of the earlier messages of that chat (which can include any personal information you choose to write in them, and which we hold in memory only, while we answer), and, when you ask about bills, financial information (bill summaries), and when you buy or restore a plan, commercial information (the store's proof of your purchase), for the purposes above. We get them from you and your app. We disclose them only to the service providers on Who processes data for us, for those purposes. We don't sell or share personal information (as the CCPA defines those words), and haven't in the last 12 months. We don't use sensitive personal information to infer anything about you.
Residents of other US states with privacy laws (such as Virginia, Colorado, Connecticut, Texas and Oregon) have similar rights. If we decline your request, you can appeal by replying to our answer; if we turn down your appeal, you can contact your state's attorney general.
Everyone else
Wherever you live, you can ask us any of the above, and we'll do our best to help.
Children
Rejynx is for adults. You must be 18 or older to use it. We don't knowingly process personal data of anyone under 18. If you think a child is using Rejynx, tell us at hello@raheed.dev and we'll delete what we hold.
Security
We protect data with: HTTPS for every connection; questions and answers sealed between your phone and our server's process; a strict check that refuses any bill field outside the list above; a server that keeps no copy of what you ask, and only a small account database, on a disk Oracle encrypts, with your email encrypted again with our own key and your Apple or Google ID kept only as a keyed hash; request and rate limits; the app's database encrypted with a key kept in your phone's secure storage, and backups off unless you turn them on; your own key in the phone's secure storage; no third-party tools inside the app; and deleted chats and bills overwritten on your phone. No system is perfectly secure. If a breach affects your data, we'll tell you and the regulators as the law requires.
Automated decisions
We don't make decisions about you by automated means that have legal or similarly significant effects. The app's reading of bills (on your phone) and Auto's choice of model and provider aren't decisions about you. AI answers can be wrong: check anything important (see the Terms of Service).
Changes to this policy
When we change this policy we'll post the new version here with a new date. If a change matters, such as something new leaving your phone, we'll tell you in the app before it takes effect, and ask for your consent again where the law requires.
This policy is written in English. Under India's DPDP Act, you can ask for it in any language of the Eighth Schedule of the Constitution.
Contact
Raheed Mujawar, Gogol, Aquem, Goa 403601, India. Email hello@raheed.dev. Grievance Officer (India): Raheed Mujawar, hello@raheed.dev. EU representative: None yet: Rejynx isn't offered in the EU or EEA yet. UK representative: None yet: Rejynx isn't offered in the UK yet.