Skip to content

Privacy Policy

Last updated: 2026-08-22

This policy explains what personal data Reeve collects, why, who else sees it, how long we keep it, and what you can do about all of that. It covers the website at reeve.page, the free scan, the Care dashboard and the emails we send, and it forms part of our Terms of Service at /terms. The trust page at /legal says much of this in fewer words, and /imprint says who we are.

1. Who we are, and the two different roles we play

Reeve, Vladyslav Tkachenko, pr. Neskorenih, 26A, 61146 Kharkiv, Ukraine, is responsible for the personal data described in this policy. You can reach us at hello@reeve.page.

There are two relationships here and it matters which one you are in. For your account, your billing record, the addresses you ask us to scan or watch, and how you use the dashboard, we decide what is collected and why: we are the controller, and this policy is our notice to you.

For the contents of your database we decide nothing at all. Care copies your database because you told it to, on a schedule you chose, using a credential you gave us. Whatever personal data sits in there (your users' records) is yours. We are your processor, and what we may and may not do with it is Annex A of the Terms at /terms, not this policy.

We are therefore not the controller of your users' personal data, and we do not answer their requests directly. If one of them contacts us, we tell you and step back.

2. What we collect

By category, and what is actually in each one:

  • Account data: your email address, your name if you give one, your language, your time zone, your notification preferences, and whether you sign in with a link or with Google. Signing in with Google gives us your Google account identifier and email address, and nothing else.
  • Billing data: your plan, subscription status, billing currency and interval, trial end date, and the identifiers PayPro Global gives us for your customer and subscription records. Card numbers never reach us; PayPro Global is the merchant of record and holds them.
  • App data: the web addresses you submit, their domain names, what we detect they are built with, the grade and findings of each scan, uptime probe results, and metadata about each backup such as when it ran, how large it is, and whether it verified.
  • Findings: what a scan observed. Where a secret is found we store only its type, its severity and a masked hint such as the last four characters. We never store the value of any key or credential we find, anywhere, ever.
  • Credentials: the read-only database credential you give us, encrypted, and the optional Storage credential if you have connected your uploaded files. Neither is ever stored in a form that can be read out of the database.
  • Customer content: the copies of your database, and of your uploaded files where you have connected them. Encrypted, and governed by Annex A of the Terms rather than by this policy.
  • Security and technical data: a one-way hash of your IP address rather than the address itself, your browser's user-agent string, a device hash used to notice a sign-in from somewhere new, session records, and an activity log of what was done in your account and when.
  • Support data: the messages you send us by email or in the chat, and our replies.
  • Website usage: pages viewed, referring page, approximate country, browser and device type, collected by our own analytics installation without cookies.
  • Free-scan visitor data, if you use the scanner without an account: the address you scanned, the hashed IP address, your confirmation that you own it and when you gave it, and, only if you ask for the detailed findings, your email address.

3. Why we use it

We do not sell your personal data. We do not share it for anyone else's advertising. We do not build a profile of you across other websites, and there is no advertising technology anywhere in Reeve.

  • To provide what you asked for: run scans, take and verify backups, run restores, watch your apps, and tell you when something changes.
  • To sign you in, keep the session secure, and confirm sensitive actions out of band by email.
  • To take payment, manage your subscription, and meet our tax and accounting duties.
  • To send the emails the service is largely made of: backup confirmations, incident alerts, trial and billing notices, and security notices about your account.
  • To send product news and tips, unless you have turned them off.
  • To keep the service working and secure: rate limiting, abuse prevention, debugging, and the internal alerts that tell us a job has failed.
  • To understand in aggregate which pages and features are used.
  • To answer your support messages.
  • To comply with the law, and to establish, exercise or defend legal claims.

4. Our legal bases for using it

If the EU or UK GDPR applies to you, these are the bases we rely on:

  • Performance of a contract, Article 6(1)(b), covers everything needed to give you what you signed up for: your account, billing, backups, restores, monitoring and service emails, and the free scan you requested.
  • Legitimate interests, Article 6(1)(f), covers keeping the service secure and available, preventing abuse of the free scanner, aggregate usage statistics, the internal alerts that tell us a job failed, and improving the product. We have weighed these against your interests: the data involved is minimal, your IP address is hashed rather than kept, and none of it is used to target you. You may object at any time under section 11.
  • Legal obligation, Article 6(1)(c), covers tax and accounting records, and responding to lawful requests from authorities.
  • Consent, Article 6(1)(a), covers product news and tips, and signing in with Google if you choose that instead of a link. You can withdraw consent at any time in Settings or through the unsubscribe link, without affecting what was done before you withdrew it.

5. Cookies and similar technologies

Reeve sets a small number of first-party cookies and no third-party ones. There is no advertising cookie, no social plugin and no cross-site tracker anywhere on the site, which is why you are not asked to dismiss a consent banner.

  • i18n_redirected: remembers the language you chose. About a year.
  • reeve_currency: remembers the currency you chose in the pricing section. About a year.
  • nuxt-color-mode: remembers light or dark. About a year.
  • __Host-care_session: signs you in to the dashboard. Strictly necessary: without it there is no account access. It expires with the session.
  • __Host-care_oauth_state and __Host-care_oauth_intent: set only while a Google sign-in is in progress, to prevent request forgery. They last minutes.

6. Analytics

Our website analytics is Umami, which we run ourselves on our own server. It sets no cookies, records no IP address, and cannot follow you to any other website. Nothing about it leaves our infrastructure, and no analytics company receives anything.

The dashboard records what happens inside your own account (which pages you opened, which actions you took) in the same activity log you can read yourself under Settings. That is first-party, it is not shared, and it is what section 10 gives a retention period for.

You can block or delete cookies in your browser. Blocking the session cookie will stop you signing in; blocking the others only costs you your preferences.

7. Who else sees your data

The list is short on purpose. These are the only outside companies involved, and each sees only what its job needs:

  • Cloudflare: stores the encrypted backup copies, in R2 with the EU jurisdiction setting. What it holds is ciphertext it cannot read.
  • PayPro Global: takes payment as merchant of record. It receives your email address and payment details directly from you; we never see a card number.
  • Resend, delivering through Amazon SES: sends our transactional email. It receives your address and the message.
  • Google: only if you choose to sign in with Google, and only for that.
  • Telegram: our own operational alerts go to a private channel there. Those messages carry domain names, grades and error causes. One of them, the notice that someone has joined the scanner mailing list, also carries the email address that joined; we are removing that, and until we have, it is disclosed here rather than left unsaid.

8. Support, disclosures and business changes

Our support chat runs on Libredesk, which we host ourselves on our own server. No outside chat company sees your messages, which is precisely why none appears in the list above.

We may also disclose personal data where the law requires it, or to establish, exercise or defend a legal claim.

If the business is ever sold or merged, personal data may transfer with it. We would tell you, and this policy would keep applying until replaced by one that is no less protective.

If we add a provider, it appears at /legal before it handles anything of yours, and business customers get 30 days' notice under Annex A of the Terms at /terms.

9. Where your data is, and transfers abroad

The service runs on our own servers in Ukraine, USA, EU, rather than on a cloud platform. Backup copies are stored in Cloudflare R2 with the EU jurisdiction setting, so they stay under EU rules wherever the request comes from.

Some of the providers named above are outside the EEA and the UK. Where personal data goes to a country without an adequacy decision from the European Commission, we rely on the European Commission's Standard Contractual Clauses, with the UK International Data Transfer Addendum where UK data is involved, and we assess each transfer before relying on them. Backup copies are always encrypted before they travel, and the keys stay with us.

Write to hello@reeve.page if you want the details of the mechanism relied on for a particular transfer.

10. How long we keep things

These are the actual periods. They are enforced by the software rather than by a promise, except where this section says otherwise:

  • Backup copies: as many restore points as your plan includes, currently 30 on Care and 90 on Care Pro and Care Max. Older copies are deleted automatically as new ones arrive.
  • After you remove an app, or when a subscription ends: restore points and the encrypted credential are kept 30 days, then permanently deleted.
  • If you delete your account: everything goes immediately and your account record is anonymised. There is deliberately no 30-day grace for a full account deletion.
  • Activity log and dashboard events: 24 months.
  • Uptime incidents: 24 months. The raw probe results behind them are kept 48 hours; only the daily summary lasts longer.
  • Payment webhook records: 90 days. They exist so the same payment notice is never processed twice.
  • Sessions: until they expire or you sign out. “Sign out everywhere” ends all of them at once.
  • Support messages: kept while your account exists. Deleting your account removes your name and email address from them straight away. Deleting the message bodies themselves is not yet automated; it is an operational task today, and we would rather tell you that than publish a period we do not enforce.
  • Free-scan results and scanner mailing-list entries: kept until you ask us to delete them. There is no automatic expiry on the scanner side yet. We are adding one; until then this is the honest answer, and writing to hello@reeve.page gets any of it deleted.
  • Unsubscribe records: kept indefinitely, as an irreversible hash of the address. It is the only way to be certain we never email someone again after they have asked us not to.

11. Your rights

Wherever you live, you can ask us what we hold about you, ask us to correct it, and ask us to delete it, and we will not treat you differently for asking. Two of those are self-service: Settings has a one-click export of everything we hold about you as a JSON file, and a delete-account button that genuinely deletes.

Under the EU and UK GDPR you have the right to access your data, to have it corrected, to have it erased, to restrict how we use it, to object to processing based on our legitimate interests, to receive your data in a portable format, and to withdraw consent at any time. We do not take decisions about you by automated means that produce legal or similarly significant effects.

You may complain to a supervisory authority: in the EU, the one where you live or work or where you think the problem happened; in the UK, the Information Commissioner's Office. We would rather you told us first at hello@reeve.page, but that is entirely your choice.

Under the California Consumer Privacy Act as amended by the CPRA, you have the right to know what personal information we collect and why, to obtain a copy of it, to correct it, to delete it, and not to be discriminated against for exercising any of those rights. We do not sell personal information and we do not share it for cross-context behavioural advertising, so there is no opt-out to offer; we do not use sensitive personal information to infer characteristics about you. Make a request at hello@reeve.page or through Settings. An authorised agent may make one for you with proof that you authorised them, and we verify a request against the email address on the account.

Under PIPEDA, if you are in Canada, you may access the personal information we hold about you, challenge its accuracy, and complain to the Office of the Privacy Commissioner of Canada.

If you are in Brazil, the LGPD gives you equivalent rights to confirmation, access, correction, anonymisation, portability and deletion, and to information about who we share data with. The same address reaches us.

We answer within one month. If a request is genuinely complex we may take up to two further months, and we will tell you why within the first month. We do not charge for any of this.

12. Children

Reeve is for adults. You must be 18 to use it, and it is neither designed for nor directed at children.

We do not knowingly collect personal data from anyone under 18. If you believe a child has given us data, write to hello@reeve.page and we will delete it.

That is about your relationship with us. What your own app collects (including, potentially, from children) is yours to handle, and if your database holds such data then the copies we keep for you will contain it. That is one of the things Annex A of the Terms at /terms exists to govern.

13. How we protect it

Described generally on purpose: enough for you to judge it, not enough to be a map for anyone else.

  • Every backup copy and every stored credential is encrypted with AES-256-GCM before it leaves the machine that made it.
  • Each customer has their own encryption key. That key is itself encrypted under a master key which exists only in the server environment, never in the database, never in the code, never inside a backup of the database. A recovery copy of the master key is held offline.
  • There is exactly one place in the software that can decrypt anything, and plaintext is wiped from memory once used.
  • The credential we hold for routine database backups can only read. We verify that when you give it to us and refuse anything stronger. The credential needed for a restore of your database is asked for at the moment of the restore and never stored. The optional credential for uploaded files can write, because Supabase issues no read-only one for Storage; it is used only against your Storage buckets, and you can delete it whenever you like.
  • All traffic uses TLS. The dashboard session cookie is host-scoped, marked secure, and not readable by scripts.
  • We store a one-way hash of your IP address rather than the address itself.
  • Findings never contain the value of a secret, only its type, its severity, and a masked hint.
  • Access to production is limited to those who need it, and what happens in your account is written to an activity log that you can read.

14. If something goes wrong

No system is perfectly secure and we do not claim ours is. If you find a problem in Reeve itself, please write to hello@reeve.page; there is also a security.txt at reeve.page/.well-known/security.txt. We answer quickly, and we do not go after people who report things in good faith.

If we confirm a breach affecting your personal data, we tell you directly by email within 72 hours of confirming it: what happened, what was affected, what we are doing, and what you should do. Not buried in a changelog.

Where the law requires it we also notify the relevant supervisory authority, within 72 hours of becoming aware.

If the breach affects personal data we hold for you as a processor (a copy of your database), Annex A of the Terms at /terms sets out what we owe you, and it is you who decides whether your own users need to be told.

15. Artificial intelligence and automated decisions

We do not use your personal data, your database contents or your findings to train any machine-learning model, ours or anyone else's. No part of the service sends your data to an AI provider. There is no AI in the processing path at all.

The grade an app receives is a fixed arithmetic rule applied to what the scan found, and the weights behind it are published on our website. It is not a prediction about you, and it is not profiling.

The fix instructions Reeve shows you are written by us and stored in our own database. You may choose to paste one into an AI coding tool that you use; that is your tool and your choice, and what it does with the text is governed by its terms rather than ours.

16. Changes to this policy

If we change this policy materially, we email everyone with an account at least 30 days before the change takes effect, and say plainly what changed.

Smaller corrections take effect when published, and the date at the top of this page changes with them.

We keep previous versions and will send you one on request.

17. Contacting us

Questions, requests or complaints about this policy: hello@reeve.page. By post: Reeve, Vladyslav Tkachenko, pr. Neskorenih, 26A, 61146 Kharkiv, Ukraine.

We have not appointed a data protection officer. We are not a public authority, our core activity is not large-scale monitoring of individuals, and we do not process special category data at scale, so one is not required. That address reaches the people who actually make these decisions.

Whether we must appoint a representative in the EU or the UK depends on where we are established, which is still being finalised. Once it is settled, this section will name one or explain why none is required.

Related pages: our Terms of Service and the data processing agreement at /terms, the plain-language trust page at /legal, and who operates Reeve at /imprint.

This English version is the authoritative text; translations are provided for convenience only.