Terms of Service
Last updated: 2026-08-22
These terms are the agreement between you and Reeve, Vladyslav Tkachenko for your use of Reeve (the website at reeve.page, the free security scan, and the paid Care subscription). By using any part of Reeve you accept them, so please read them. How we handle personal data is set out separately in our Privacy Policy at /privacy, which forms part of this agreement, and Annex A at the end of these terms is the data processing agreement that applies whenever we hold a copy of your database.
1. Who we are, and who may use Reeve
Reeve is operated by Reeve, Vladyslav Tkachenko, pr. Neskorenih, 26A, 61146 Kharkiv, Ukraine. In these terms “we”, “us” and “Reeve” mean Reeve, Vladyslav Tkachenko, and “you” means the person or organisation using the service. Full operator details are on our imprint page at /imprint.
You accept these terms when you request a scan, create an account, or start a subscription, whichever happens first. If you do not accept them, please do not use Reeve.
You must be at least 18 years old and legally able to enter into a contract. Reeve is not designed for or directed at children, and we do not knowingly provide it to anyone under 18.
If you use Reeve on behalf of a company, an agency or another organisation, you confirm that you are authorised to accept these terms for it, and “you” means that organisation as well as you personally.
Some clauses depend on whether you are a consumer (an individual acting outside your trade, business or profession). Where that matters, we say so. Nothing in these terms takes away rights that consumer law in your country gives you and does not let you give up.
2. What Reeve is, and what it is not
Reeve does two things. The free scan looks at a web address you give us from the outside and reports what an anonymous visitor could already see. Care is a paid subscription that keeps watching an app you own, takes regular copies of its database, and helps you put things right when they break.
The scan is passive. We read what your app already serves to the public: the JavaScript it loads, the headers it returns, whether certain well-known paths answer, whether a storage bucket lists its contents, what certificate it presents, and when its domain registration expires. We do not log in, we do not change anything, we do not attempt to break anything, and we do not download the contents of anyone's files or database.
A scan is an automated external check, not a security audit. It can miss things, and it can report something that turns out to be deliberate on your part. A clean result does not mean your app is safe. What you do about your app remains your decision.
What Care covers, and what it does not:
- Backups cover your database: its tables, their contents and the structure needed to put them back. They also cover the files your users uploaded to Supabase Storage, if you have connected them. They do not cover anything else your app keeps outside those two places.
- Backups are only possible for the database systems we support, which today means PostgreSQL as provided by Supabase. If your app keeps its data somewhere else we will tell you plainly rather than pretend to copy it.
- Watching means we request your app's public address on a schedule and record whether it answered and how quickly. It is not a check that your app is working correctly for a signed-in user.
- Re-scans repeat the free scan on the schedule your plan sets, and tell you when a result changes.
- Fixes are instructions you apply yourself. Where your plan includes priority support, we can help you apply one after you ask us to and approve it. Nothing in your app is ever changed without your instruction.
3. Your account
Care needs an account. You sign in with a one-time link sent to your email address, or with Google if you prefer. There is no password.
That makes your email inbox the key to your Reeve account. Keep it secure, and use it only from devices and mail providers you trust. If you think someone else has reached your inbox or your account, write to us at hello@reeve.page straight away and use “sign out everywhere” in Settings.
Sensitive actions (restoring a database, downloading a copy, adding or changing a database key, removing an app, changing your plan, cancelling and deleting your account) need a second confirmation from a link we email you. This is deliberate: a stolen browser session on its own is then not enough to destroy or take away your data.
Please keep the email address and other details on your account accurate. Any notice we have to give you goes to that address.
You are responsible for what is done through your account, except where it happens because of a failure on our side.
4. Permission to scan, and permission to connect
You may only ask Reeve to scan or watch an app that you own, or one whose owner has explicitly permitted you to test it. This is the one rule we cannot be flexible about. Every scan asks you to confirm it, and we record that confirmation together with the time and a one-way hash of your IP address.
By submitting an address you confirm that this is true, and you authorise us to carry out the technical operations described in section 2 against it.
By giving us a database credential you authorise us to connect to that database with it, on the schedule your plan sets, to read its contents and structure, and to keep the resulting copy encrypted for as long as your plan's retention allows. During a restore you authorise us to write to the database using the credential you supply at that moment. If you also give us a Storage credential, you authorise us to list and read the files in that project's buckets on the same schedule, and to upload copies back into those buckets during a restore you have asked for.
You must not submit systems belonging to someone else. Where we believe an address was submitted without permission we may refuse it, delete the result, and suspend the account behind it.
We may limit how often you can scan, and we refuse addresses that are not public internet hosts: the scanner declines private and internal addresses by design.
5. Credentials
The credential Care uses for routine database backups must be able to read and nothing else. We verify this when you give it to us and refuse a credential that can write or delete, or one with administrative rights. If you choose the guided option, we create such a role for you and store only that role's credential; the administrator password you type is used once, in memory, and never stored.
Credentials are encrypted before they are stored. Each customer has their own encryption key, which is itself encrypted under a key held only in the server environment. Section 13 of the Privacy Policy at /privacy describes the arrangement in more detail.
A restore has to write, so the read-only credential cannot perform one. We ask you for a credential with the rights needed at the moment of each restore, use it for that restore only, and never store it.
The credential for uploaded files is a different thing, and we would rather set it out here than have you discover it later. Supabase issues no read-only credential for Storage, so the key that can list and read your files can also write to them. That is why this part of Care is optional, why we ask for it separately, and why we use it for two things only: reading your files on your backup schedule, and uploading copies back during a restore you asked for. It is encrypted the same way the database credential is, it is never used against your database, and you can delete it from Settings at any time, with or without the copies it produced.
Your database remains yours to look after: who else has access to it, what your app writes into it, and rotating any credential you believe may be compromised. If you rotate a credential you have given us, please tell us at hello@reeve.page so that backups do not quietly stop.
6. Plans, payment, trial, renewal, cancellation and refunds
Care is a subscription, sold monthly or annually in the currency shown at checkout. Prices, and whether tax is included, are shown before you pay. What each plan includes (how often backups run, how many restore points are kept, how many apps you may add and which features are available) is shown at reeve.page and in your dashboard, and forms part of this agreement.
Payment is handled by PayPro Global, Inc., which acts as merchant of record and is therefore the seller for your purchase. Your payment is a contract with PayPro Global, subject to its purchasing terms and refund policy at https://payproglobal.com/legal/, and PayPro Global collects and remits any VAT or sales tax. Your card details never reach us. These terms govern the service itself.
Where a free trial is offered, it runs for the number of days stated at checkout and requires a payment method up front. Nothing is charged during the trial. We email you before it ends (currently three days before and again one day before), naming the amount and the date. If you have not cancelled by the end of it, the subscription begins and the first payment is taken.
Subscriptions renew automatically at the end of each period until you cancel, at the price then in force. We give you at least 30 days' notice by email before any price increase affects you.
You can cancel at any time from Settings: one click, plus the email confirmation that protects every important action. There are no retention flows, no phone calls and no forms. Cancellation takes effect at the end of the period you have already paid for, and we do not pro-rate a part-period.
When a subscription ends, for any reason:
- Watching, re-scans and backups stop.
- The restore points you already have are kept for 30 days, so that changing your mind costs you nothing, and are then permanently deleted.
- The encrypted database credential is deleted at the same time, as is the Storage credential if you gave us one.
- Deleting your account instead of cancelling deletes all of it immediately, with no 30-day window.
7. Changing plan, failed payments, and your right to withdraw
Moving to a larger plan takes effect immediately, and PayPro Global charges the difference for the remainder of the period. Moving to a smaller plan takes effect at your next renewal, and nothing is deleted before then. Changing your billing interval also takes effect at the next renewal. Your billing currency is fixed when you first subscribe and cannot be changed afterwards; to be billed in another currency, cancel and subscribe again.
If a smaller plan would leave you with more apps than it allows, you get a short grace period to choose which to keep active. If you do not choose, the most recently added apps are paused rather than deleted, and one click reactivates them when a slot frees up.
If a payment fails, PayPro Global retries it and emails you. If it keeps failing we may suspend Care for your apps, and the wind-down in section 6 applies.
If you are a consumer in the EU, the UK or another country giving you an equivalent right, you may withdraw from your subscription within 14 days of it starting, without giving a reason. Because Care starts working immediately, you are asked at checkout to agree that we begin during that period and to acknowledge that you lose the right to withdraw once the service has been fully performed. If you withdraw part-way through, we may charge a proportionate amount for what was delivered up to that point.
Beyond your statutory rights, we keep the promise published on our trust page at /legal: if Care materially failed you (a backup we told you was verified was not there when you needed it, or the service was broken for a meaningful part of a billing period), write to hello@reeve.page and we refund that period. One email, no forms, no argument.
8. Acceptable use
You agree not to do any of the following, and not to help anyone else do them:
- Scan, probe, watch or connect to any system you do not own or have explicit permission to test.
- Use a Reeve scan or report as a step towards attacking, gaining access to, or disrupting any system.
- Give us a credential you are not entitled to give us, or ask us to hold data you have no right to hold.
- Ask us to copy content that is unlawful where you or we are, or that you have no right to store.
- Work around rate limits, quotas or the ownership confirmation, including by using several accounts.
- Resell, sublicense or white-label Reeve, or present it as your own service, without a written agreement with us.
- Copy, decompile or reverse engineer the service, except so far as the law says you may.
- Interfere with the service or with anyone else's use of it, including by sending automated traffic beyond what the interface offers.
9. Enforcement of acceptable use
We may investigate a suspected breach, and we may suspend or end your access under section 14.
Scanning systems without permission is not only a breach of these terms; depending on where you and the system are, it may be a criminal offence. We cooperate with lawful requests from the authorities, and we may report serious cases to them.
If your use of the free scanner is abusive rather than merely heavy, we may block it without notice. Rate limits are applied to everyone and are not a judgement about you.
10. Your content, and the licences we each grant
Your Customer Data (the addresses you submit, the contents of your database and the copies we take of it, your account details and the findings recorded against your apps) belongs to you. Using Reeve gives us no ownership of any of it.
You grant us a non-exclusive, worldwide licence to host, copy, encrypt, transmit and display Customer Data strictly so far as is needed to provide the service to you, to keep it secure, and to comply with the law. That licence lasts only while we hold the data, and ends when it is deleted. We do not use Customer Data to train models, and we do not sell it or share it for anyone's marketing.
Where Customer Data contains personal data about other people (your app's users, whose records sit inside a database copy), you are the controller of that data and we are your processor. Annex A governs it.
We grant you, for as long as your subscription is active, a non-exclusive, non-transferable right to use the service and to use the reports, findings, fix instructions and grade badges it produces for you, for your own purposes, including publicly. The share badge is meant to be shared.
If you send us feedback or ideas, we may use them without owing you anything. That does not give us any right to your Customer Data.
11. Our intellectual property
Reeve (the software, the checks and the way they classify what they find, the grading, the dashboard, the text, the design, and the name and logo) belongs to us or to our licensors. Nothing in these terms transfers any of it to you.
The fix instructions we generate are provided for you to use on your own apps. Everything else remains ours.
Reeve is built on open-source software, which is licensed to you under its own terms rather than these.
12. Other people's services
Reeve works alongside services we do not control: the platform your app was built with, the database and hosting behind it, PayPro Global for payment, Google if you sign in with it, and the providers listed in our Privacy Policy at /privacy. Your relationship with each of them is governed by their terms, not ours.
We are not responsible for what those services do, and a change on their side can stop part of Reeve working; a database provider changing how connections are made, for example, can interrupt backups until we adapt to it. We tell you when we know.
A scan describes what we observed from outside at a moment in time. It is not a statement about any third party's security, compliance, or fitness for your purpose.
13. Availability, changes and support
We work to keep Reeve available and to run every scheduled job on time, but we do not promise any particular level of availability. There is no service level agreement and none is implied. We monitor your app's uptime; we do not guarantee our own.
We may change, add to or withdraw features. Where a change materially reduces what your plan includes, we tell you by email at least 30 days beforehand, and you may cancel and receive a refund of the unused part of what you have paid.
We may take the service down for maintenance, usually briefly, and where we can, at a quiet time for you.
Support is by email and, where offered, live chat during the hours published in the dashboard. Response times are what we aim for, not commitments.
14. Suspension and termination
You may stop using Reeve whenever you like. You can cancel a subscription, remove an app, or delete your account entirely, all from Settings.
We may suspend or end your access if you materially breach these terms (in particular sections 4 and 8), if a payment fails and is not put right, if the law requires us to, or if continuing would expose us or someone else to real risk. Except where the problem is serious or urgent, we tell you first and give you a fair chance to put it right.
We may also discontinue the service as a whole. If we do, we will give you at least 60 days' notice, refund the unused part of anything you have paid, and leave you time to download your copies before they are deleted.
What happens to your data when this agreement ends is set out in section 6 and in Annex A.
Sections which by their nature should continue (10 as to ownership, 11, 15, 16, 17, 18 and 21) survive the end of this agreement.
15. What we do not promise
Except as these terms expressly state, and except for rights consumer law gives you that cannot be excluded, Reeve is provided as it is and as available. We give no implied warranty of merchantability, fitness for a particular purpose, or non-infringement.
In particular we do not promise that a scan will find every problem or that what it reports is exhaustive; that a fix instruction will work in your app; or that your app will remain available, secure or lawful because you use Reeve.
Backups are a safety net, not a guarantee. A copy can only contain what your database contained at the moment it was taken, and only what the credential you gave us was able to read. A restore can only succeed while your database still accepts the copy; if its structure has moved on we will tell you rather than restore part of it and call it done.
Please keep your own backups as well. We mean that sincerely, and section 16 is written on the assumption that a careful operator does not rely on any single provider, including us.
16. Limitation of liability
Nothing in these terms limits liability for death or personal injury caused by negligence, for fraud or fraudulent misrepresentation, or for anything else that cannot lawfully be limited. If you are a consumer, nothing here affects your statutory rights.
Subject to that, neither of us is liable to the other for indirect or consequential loss, loss of profit, loss of revenue, loss of goodwill, loss of anticipated savings, or business interruption, however it arises.
Subject to the first paragraph, our total liability to you for all claims connected with this agreement in any twelve-month period is limited to the greater of the amount you paid us for the service in the twelve months before the event giving rise to the claim, and 100 EUR. Where you have paid us nothing (the free scan), that figure is 100 EUR.
This allocation of risk is part of why the service costs what it does. If it does not work for your situation, we are open to agreeing something different in writing; write to hello@reeve.page.
17. Indemnity (business customers only)
This section does not apply to you if you are a consumer.
You will indemnify us against claims, losses and reasonable costs arising from your use of Reeve against a system you did not own or have permission to test; from content in a database you asked us to copy; from your breach of section 4 or section 8; or from your infringement of anyone's rights.
We will tell you promptly about any such claim, will not settle it without your agreement (which you will not unreasonably withhold), and will let you conduct the defence with our reasonable cooperation at your cost.
18. Governing law and disputes
This agreement is governed by the law of Ukraine.
Please write to us first at hello@reeve.page. Most problems are a misunderstanding, and we would far rather solve one than argue about it. If we have not reached agreement within 30 days, either of us may go to court.
If you are a business customer, the courts of Kharkiv, Ukraine have exclusive jurisdiction.
If you are a consumer, you may bring proceedings either in the courts of Kharkiv, Ukraine or in the courts of the country where you live, and you keep the protection of the mandatory law of that country. We will bring proceedings against a consumer only in the courts of the country where they live.
Consumers in the EU may also use the European Commission's online dispute resolution platform at https://ec.europa.eu/consumers/odr. We are not obliged to use, and do not undertake to use, an alternative dispute resolution body.
There is no arbitration clause in this agreement, and nothing in it waives your right to bring a claim in court or to take part in collective proceedings where the law allows them.
19. Copyright complaints
Almost nothing on Reeve is public: your findings, your copies and your account are visible only to you. The exceptions are shared scan result pages and the grade badge images they produce, which show a web address, a grade and counts of what was found.
If you believe something published through Reeve infringes your copyright, write to hello@reeve.page with your contact details; identification of the work; the exact address of the material you object to; a statement that you believe in good faith that the use is not authorised; a statement that your information is accurate and that you are the rights holder or authorised to act for them; and your signature, electronic or physical.
We will remove or disable access to material we consider infringing, tell the person who posted it where we can, and end the accounts of repeat infringers.
20. Changes to these terms
We may change these terms, because the service changes or because the law does.
If a change materially affects your rights or obligations and you have an account, we email you at least 30 days before it takes effect. If you do not accept it, you may cancel before that date and we refund the unused part of anything you have paid.
Corrections, clarifications, and changes that only affect new customers take effect when they are published, and the date at the top of this page changes with them.
Continuing to use Reeve after a change takes effect means you accept it. We keep previous versions and will send you one on request.
21. General
If a court finds part of these terms unenforceable, the rest continues to apply and that part applies as far as it lawfully can.
If we do not enforce something straight away, we do not lose the right to enforce it later.
We may transfer this agreement to another company as part of a merger, acquisition or sale of assets, on notice to you, provided your rights are not reduced. You may not transfer it without our written agreement.
These terms, the Privacy Policy at /privacy, Annex A, and the description of the plan you bought are the whole agreement between us about Reeve, and replace anything said beforehand. Nobody other than you and us may enforce them.
Neither of us is liable for a failure caused by something genuinely beyond our control (a failure at a provider we depend on, an act of war, or a general failure of infrastructure) for as long as it lasts. If it lasts more than 30 days, either of us may end the agreement and we refund the unused part of what you have paid.
Notices to you go to the email address on your account. Notices to us go to hello@reeve.page, and by post to Reeve, Vladyslav Tkachenko, pr. Neskorenih, 26A, 61146 Kharkiv, Ukraine.
These terms are written in English. Translations are offered for convenience, and where they differ the English text applies.
Questions about these terms: hello@reeve.page. Who operates Reeve: /imprint. How we handle data: /privacy. Sub-processors, retention periods and our security commitments in plain language: /legal.
Annex A: Data Processing Agreement
This annex applies whenever we process personal data on your behalf, in practice whenever Care holds a copy of your database. It forms part of these terms, and it is what Article 28 of the EU and UK General Data Protection Regulation requires to be agreed in writing. Where anything in the rest of these terms conflicts with this annex on a data protection question, this annex prevails.
A1. Roles and scope
For personal data inside the databases we copy for you, you are the controller and we are your processor. For your own account, billing and usage data we are the controller, and the Privacy Policy at /privacy covers that separately.
In this annex, “data protection law” means the EU General Data Protection Regulation, the UK GDPR and the UK Data Protection Act 2018, and any other data protection law that applies to either of us.
You confirm that you have a lawful basis for the personal data in your app, that your own privacy notice accounts for using a processor such as us, and that you are entitled to instruct us to process it.
A2. Subject matter, duration, nature and purpose
- Subject matter: taking, storing, verifying and restoring encrypted copies of your database and, where you have connected it, of the files your users uploaded, and the technical support around that.
- Duration: for as long as your subscription is active, plus the retention window in A8.
- Nature and purpose: reading your database automatically on a schedule, and where connected listing and reading the files in your Storage buckets, encrypting and storing the result, verifying its integrity, deleting it when retention expires, and, only when you ask, writing a copy back during a restore.
- Types of personal data: whatever your database contains, typically your users' account records, contact details and whatever your app stores about them. Where you have connected uploaded files, it also includes whatever those files contain, which may be photographs, identity documents or invoices. We neither select it nor inspect it.
- Categories of data subject: your users, your customers, your staff, and anyone else who appears in your database.
- Special category data: we do not ask for it and cannot tell whether it is present. If your database holds any, the additional requirements attaching to it remain yours.
A3. What we undertake
- We process personal data only on your documented instructions. Configuring a schedule, asking for a restore and asking for a download are such instructions; these terms are the rest of them.
- We tell you if we believe an instruction breaches data protection law, and we may decline to act on it.
- Everyone with access is bound by an obligation of confidentiality, and access is limited to those who need it to run the service.
- We apply the technical and organisational measures described in A5.
- We assist you, so far as we reasonably can and taking into account the nature of the processing, with data subject requests, with security, with breach notification, and with data protection impact assessments and prior consultations.
- We make available the information you reasonably need to show that we meet these obligations.
- If the law requires us to process personal data otherwise than on your instructions, we tell you first unless the law forbids it.
A4. Sub-processors
You give us general authorisation to engage sub-processors. The current list is published at /legal and named in the Privacy Policy at /privacy.
We impose data protection obligations on each sub-processor that are no less protective than these, and we remain responsible to you for what they do.
We will tell you by email at least 30 days before adding or replacing a sub-processor that handles your Customer Data. If you object on reasonable data protection grounds within that period, we will work with you to find a solution, and if we cannot, you may cancel and we refund the unused part of what you have paid.
A5. Security measures
The measures we take are described in section 13 of the Privacy Policy at /privacy, which is incorporated here. We may update them, provided the level of protection is not reduced.
In summary: every copy and every stored credential is encrypted with AES-256-GCM before it leaves the machine that made it; each customer's data is encrypted under a key of their own, which is itself encrypted under a key held only in the server environment and never in the database or in code; the credential we hold for routine database backups can only read, and the optional Storage credential is used only against your Storage buckets; all traffic uses TLS; and access is limited, logged and visible to you in your own activity log.
A6. Requests from your users
If someone contacts us about personal data inside a copy of your database, we will not answer them on the substance. We will tell you promptly and leave it with you, because it is your data and your relationship with that person.
The dashboard gives you the copies themselves, so you can find, correct or remove a record in your own database and the change will be in the next copy. We do not edit copies already taken; they age out under A8. If you need a specific copy deleted sooner, write to hello@reeve.page and we will delete it.
A7. Personal data breach
If we become aware of a personal data breach affecting personal data we process for you, we will tell you without undue delay and in any event within 72 hours of confirming it: what happened, which categories of data and roughly how many records are affected, what we believe the consequences are, and what we are doing about it. The same 72 hours is the commitment published on our trust page at /legal.
We will help you meet your own notification duties. Telling you is not an admission of fault by either of us.
A8. Deletion and return of data
You can download any copy we hold, at any time, from the dashboard. That is how your data is returned to you, and it is available for as long as the copy is.
Copies are deleted automatically as they fall outside your plan's retention. When you remove an app or your subscription ends, copies and the encrypted credential are kept for 30 days so that changing your mind costs you nothing, and are then permanently deleted. Deleting your account deletes them immediately.
We keep no copies after that, except where the law requires it, and anything retained on that basis stays encrypted and remains subject to this annex.
A9. Audit
We will provide the information you reasonably need to verify our compliance with this annex, including completing a security questionnaire, once in any twelve-month period, and more often if a supervisory authority requires it or after a breach affecting your data.
An on-site audit requires 30 days' notice, must be at a reasonable time, must not disrupt the service or affect other customers, is subject to confidentiality, and is at your cost. It may never extend to another customer's data.
A10. International transfers
Where we or a sub-processor transfer personal data out of the EEA or the UK, we rely on a valid transfer mechanism: an adequacy decision where one applies, and otherwise the European Commission's Standard Contractual Clauses (Module Two for controller to processor, or Module Three where data goes on to a sub-processor), together with the UK International Data Transfer Addendum where UK data is involved. Those clauses are incorporated into this annex by reference and prevail over it if they conflict.
Backup copies are stored in Cloudflare R2 with the EU jurisdiction setting, so they remain under EU rules wherever a request comes from. The Privacy Policy at /privacy names where the rest of the service runs.
We carry out and document a transfer impact assessment where one is required.
A11. Liability and precedence
The limitation of liability in section 16 applies to this annex, except where data protection law does not permit it, in particular each party's own liability towards a data subject or a supervisory authority.
If this annex conflicts with the rest of these terms on a data protection question, this annex prevails. If it conflicts with the Standard Contractual Clauses, those clauses prevail.
This English version is the authoritative text; translations are provided for convenience only.