Who processes data for us

Every company that can receive anything from Rejynx, named: our hosting and the AI providers that work for us, the companies that receive data as themselves (Apple and Google, including for sign-in; your UPI app) and the one that hosts our email. For each, what it gets, when, why and for how long, and each AI provider's own words on keeping and training on it.

Updated 27 September 2026

Most of Rejynx runs on your phone, and none of these companies can see what's there. Our rule is that what leaves your phone goes to our server only sealed, and to another company only when a feature can't work without it; then that company is named here, with what it gets, when, why and how long it keeps it. This page lists only what the code sends. The Privacy Policy explains the rest, and the app lists the same companies in Settings → Where your data goes. No company receives anything from Rejynx for analytics, crash reports, advertising, tracking or telemetry.

Subprocessors

These companies process personal data on our behalf, under contract.

CompanyWhat it does for usWhat it receivesWhenWhereHow long it keeps it
Oracle (Oracle Cloud Infrastructure)Hosts our server: a virtual machine, its disk and its networkEverything that passes through our server, while it passes: questions, chats, bill summaries, purchase checks and sign-ins (the identity token Apple or Google gave, then a session) arrive sealed, with the phone's random ID inside, and are opened only in our server's memory; beside them, a one-way code from that ID and the app's key (plain request headers) and your IP address. On its disk, which Oracle encrypts at rest (AES-256): our server's small database (accounts, with emails encrypted again with our own key and Apple or Google IDs only as keyed hashes; sessions' hashes; plans; each purchase's keyed hash with the phones and accounts that use it; each day's counts), and its logs (the web server's access and error logs, with IP addresses and request lines; our server's own error lines, which it writes without questions, answers, purchases, tokens, IP addresses or IDs)Whenever the app talks to our server: a question for the cloud, a check of your plan, signing in or out, deleting an account, the provider list, the plans' limitsSingapore (region ap-singapore-1)Questions and purchases: never stored (the web server may put a large request, still sealed, in a temporary file on the disk until the request ends). The database: as the Privacy Policy says (an account until it's deleted, each day's counts until the day ends). Logs: see the Privacy Policy
Groq, Inc.Runs the AI model that answers; first choice on AutoRejynx's instructions (with today's date and any bill summaries, those from your SMS included, never those from your Gmail), the chat's messages, the model's name and our account's key, over HTTPS. It sees our server's address, not yours, and no random ID. Never your messages themselves, your transactions or your balancesA question the phone can't answer, on Auto or when you pick GroqUnited States (data it retains is kept in Google Cloud in the US)See What each AI provider says: nothing. Zero data retention is on for our account, so it doesn't log or store what it receives, or its answers. Doesn't train on it
Cloudflare, Inc. (Workers AI)Runs the AI model that answers; second choice on AutoThe same as GroqWhen Groq is busy or down, or when you pick CloudflareCloudflare's data centres worldwide (US company)See What each AI provider says: stored only with a Cloudflare storage service, which we don't use; no retention period is given. Doesn't train on it
OpenRouter, Inc.Passes the question to a model host and returns its answer; third choice on AutoThe same as Groq, with the request's routing settingsWhen Groq and Cloudflare are busy or down, or when you pick OpenRouterUnited States, and the model host it picksSee What each AI provider says: prompts and answers not kept unless the account turns that on (to be confirmed off). Keeps request metadata, such as token counts and timing, and the category of a small sample of prompts, not linked to any account. Doesn't train on it
OpenRouter's model hostsRun the model OpenRouter picks (with the free models, it can change from question to question)The same as Groq, from OpenRouterWhen OpenRouter answersVaries with the hostOur server asks OpenRouter, on every request, for hosts that keep nothing (zdr: true) and don't collect data (data_collection: "deny"). When no such host is free, OpenRouter doesn't answer, rather than use another. That's the hosts' own promise as OpenRouter knows it, not a guarantee
Zoho Corporation (Zoho Mail)Hosts our mailbox, hello@raheed.dev and hello@raheed.devThe emails you send us: your address, what you write and anything you attach, and our replies. A report on an answer (Report, under it) is such an email, which starts with only where the answer came fromWhen you email us, or send a reportIndia (Zoho's India data centre)As long as we keep the email: 12 months after the conversation ends
Oracle Cloud Infrastructure, Singapore (the same server as the Rejynx API)Serves our websiteStandard access logs (IP address, time, page, user agent)When you visit the website14 days

Which AI providers are switched on is a server setting. On Auto, our server tries them in the order above and moves on when one is busy, failing or silent before its first word; if you pick one in the model menu, only that one is used. The line under each answer names the model and its provider, and "What left my phone" says which provider each question went to.

Our server sends each provider only what it needs to answer, with our account's key: no user ID, IP address, device ID or app name. The makers of the models (for example OpenAI for gpt-oss, or Google for Gemma) receive nothing: the providers run the models themselves.

What each AI provider says

What each provider's own published policy says about keeping what our server sends it (a question, the chat and any bill summaries) and training on it, briefly, with a link to the whole policy. We can't check these from outside: they're each company's promise, under its agreement with us.

Groq

  • Keeping it: nothing. Zero data retention is on for our account (below): "When ZDR is enabled, Groq will not retain customer data for system reliability and abuse monitoring." (Your Data in GroqCloud) So Groq doesn't log or store what our server sends it, or its answers.
  • Training on it: "Groq is not permitted to use Inputs or Outputs for training or fine-tuning any AI Model Services or other models, unless explicitly granted permission or instructed by Customer." We don't. (Groq Services Agreement, section 4.2)
  • What we turned on: "All customers may enable Zero Data Retention (ZDR) in Data Controls settings." It's a setting on our Groq account, not something a request can ask for, and it's on: on 27 September 2026 Groq's console showed it enabled for the whole account ("input and output data will not be logged") and for its inference APIs. It covers only our account: with your own Groq key, your account's settings apply (below).

Cloudflare (Workers AI)

  • Training on it: "Cloudflare does not use your Customer Content to (1) train any AI models made available on Workers AI or (2) improve any Cloudflare or third-party services, and would not do so unless we received your explicit consent." (Workers AI: Data usage)
  • Keeping it: the same page says only that "Your Customer Content for Workers AI may be stored by Cloudflare if you specifically use a storage service (e.g., R2, KV, DO, Vectorize, etc.) in conjunction with Workers AI." We use no storage service with it, and our server calls Workers AI directly, not through Cloudflare's AI Gateway (whose logs, on by default, hold prompts and answers). Cloudflare doesn't promise in so many words that it keeps nothing, and gives no retention period. It offers no zero-data-retention setting to turn on.

OpenRouter

  • Keeping it: "OpenRouter does not store your prompts or responses, unless you opt in", and both options are off by default (we're confirming they're off on our account). But "OpenRouter does store metadata (e.g. number of prompt and completion tokens, latency, etc) for each request," and "samples a small number of prompts for categorization", which, for an account not opted in, "is stored completely anonymously and never associated with your account or user ID." (Data collection)
  • Training on it: "OpenRouter does not use your Inputs or Outputs for model training." But it also says: "OpenRouter cannot control Model Provider-side training once user data is transmitted to a training-permitted Model Provider." (OpenRouter's privacy policy)
  • What we turn on, on every request: data_collection: "deny" ("use only providers which do not collect user data") and zdr: true ("the request will only be routed to endpoints that have a Zero Data Retention policy"). (Provider selection)

OpenRouter's model hosts

  • Which hosts keep or train on prompts is each host's own policy, and OpenRouter labels them: "Some model providers may log prompts, so we display them with a Data Policy tag on model pages. This is not a definitive source of third party data policies, but represents our best knowledge." (Provider selection)
  • We use OpenRouter's free models, and OpenRouter says that "Most free endpoints train on, or may publish, the prompts they receive," and that "Many free endpoints retain prompts, so enforcing ZDR can filter all of them out." (OpenRouter help: free endpoints and data policies) Our settings above leave those hosts out. When no host that keeps nothing is free, OpenRouter answers with an error rather than use another, and the app tells you so.
  • So with OpenRouter, "keeps nothing and doesn't train" is the host's own promise as OpenRouter knows it, not a guarantee OpenRouter can give.

Also receiving your data, as themselves

These companies receive something only because a feature you use needs them. They act under their own terms and privacy policies, as independent companies, not on our behalf.

CompanyWhat it getsWhenWhyHow long it keeps it
Apple (Sign in with Apple)Only if you sign in with Apple, on iPhone: your phone's sign-in on Apple's own sheet, which asks only for your email (you can hide it behind a private relay address). When you delete an account made with Apple: from our server, the one-time code Apple's sheet just gave your phone, and a secret signed with our Sign in with Apple key, to swap the code for tokens and revoke them at once. Our server also fetches Apple's public keys, with nothing about youWhen you sign in, and when you delete your accountTo tell our server who you are, so your plan follows you across phones; and when you delete your account, to take back Rejynx's access, as Apple asksApple holds your Apple Account, and that you use it with Rejynx until you delete the account or remove Rejynx in your Apple Account's settings, under its own privacy policy. We keep no Apple token
Google (Sign in with Google)Only if you sign in with Google: your phone's sign-in on Google's own sheet. On iPhone, for your email and a sign-in only (openid, email), and the phone swaps the sign-in's one-time code at Google's token endpoint. On Android, Credential Manager's Sign in with Google, which takes no scopes: Google gives the app your name and profile picture with your email, in the ID token that goes to our server sealed; our server reads only your Google ID and email from it, and keeps neither the name nor the picture. Our server fetches Google's public keys, with nothing about youWhen you sign inAs for AppleGoogle holds your Google Account, and that you use it with Rejynx, until you remove Rejynx in your Google Account's connections, under its own privacy policy. We keep no Google token
Apple (the App Store)From our server: the original ID of your App Store transaction, nothing else. It's Apple's own ID for the purchase Apple sold youWhen the app checks your plan: a purchase or restore, about once a day while you have a plan, when its date passes, after you manage your subscription, and when you sign in or out. Only when our server has an App Store key; without one, the check is made on our server alone and Apple gets nothingTo confirm the plan is active, renewed, refunded or cancelledApple already holds the purchase as the store that sold it, and keeps its records under its own privacy policy. We keep only the plan and when it ends, never the transaction
Google (Google Play)From our server: the purchase token Google Play gave the app, nothing elseAs for AppleAs for AppleGoogle already holds the purchase as the store that sold it, and keeps its records under its own privacy policy. We keep only the plan and when it ends, never the token
Apple (iCloud)Only if you turn on Settings → Back up to iCloud: the app's whole database, encrypted (your bills, chats, settings, and Money's transactions, balances and budgets), in your iCloud backup; and a copy of its key in your iCloud Keychain, which Apple encrypts end to end, so Apple can't open the databaseEach time your iPhone backs up, while backups are onSo you can restore Rejynx on a new iPhoneAs long as you keep the backup, under Apple's terms for iCloud. If a device stops backing up, Apple "reserves the right to delete any backups associated with that device" after 180 days (iCloud Terms and Conditions). The key's copy is in iCloud Keychain, which Apple end-to-end encrypts: "Apple doesn't have the encryption keys for these categories" (iCloud data security overview). Turning backups off in the app deletes that copy
Google (Android backup)Only if you turn on Settings → Back up to Google: the app's whole database, encrypted, and its key, only in a backup encrypted end to end with your screen lock (with no screen lock, nothing)When Android backs up (usually overnight, while charging), while backups are onSo you can restore Rejynx on a new Android phoneGoogle keeps only the latest backup, and "If you don't use your device for 57 days, the data you backed up (except photos or videos) is also erased" (Google One Help). Turning backups off in the app leaves Rejynx out of the next backup
Google (Gmail)Only if you connect Gmail: your phone's requests with your own sign-in: the search for bill emails and each message it reads. Our server isn't involved, and nothing goes back to Google. Nothing read from your Gmail goes to our server or an AI provider, the bills found in it includedEach time the app opens, while Gmail is connectedTo find your bills in your own mailboxGoogle already holds your mailbox, and keeps its own records of these requests under its privacy policy
Your UPI app (the one you choose)The payee's UPI ID and name, the amount, and a short note (such as "HDFC 9012 bill"), handed over on the phoneWhen you tap PayTo make the payment you then confirm thereUnder its own terms and the UPI system's rules, with your bank and the payee. Rejynx gets nothing back

Involved, but receiving nothing about you

CompanyRoleWhat it sees
HostingerRuns the DNS for our server's current address (rejynx.raheed.dev)Look-ups of our server's name, normally from your network's DNS resolver rather than your phone. No content
Let's Encrypt (Internet Security Research Group)Issues our HTTPS certificateNothing about you
Expo (EAS)Builds the app from our codeNo user data. The app doesn't contact Expo while you use it (no over-the-air updates, no push notifications)
Oven (Bun)Makes the runtime our server runs onNothing: Bun's crash reports are turned off (DO_NOT_TRACK=1), so our server sends Oven nothing

With your own AI key

If you use your own key, the provider you chose (Groq, Cloudflare or OpenRouter) receives your questions, the chat and any bill summaries (never those from your Gmail) straight from your phone, with your IP address, under your account and your agreement with it. What it keeps follows your account's settings, not ours: our zero data retention at Groq doesn't cover your key. It isn't our subprocessor, and our server isn't involved. The line under each answer names your provider.

Changes

We'll update this page at least 30 days before a new subprocessor starts receiving personal data, except when we must change quickly to keep Rejynx running safely; then we'll update it as soon as we can. Business customers with a Data Processing Agreement can object to a new subprocessor as that agreement describes.