Privacy Policy
Refyn is built as an instrument, not an advertising network. We operate under strict data minimization: we do not store facial images, we do not monetize user insecurity, and we do not run third-party tracking pixels on personal habit surfaces.
Images submitted for protocol evaluation are processed purely in-memory and discarded. Zero blob storage, zero CDN persistence.
User credentials are protected with 12-round bcrypt salted hashing. All traffic is enforced over strict TLS 1.3 transport.
You own your data. Account termination triggers irreversible foreign-key cascading deletions across all database tables.
1. Foundational Commitment: Zero Facial Image Persistence
Refyn operates strictly on appearance habits, biomechanics, and evidence evaluation. To protect user autonomy and eradicate data breach exposure:
- Ephemeral In-Memory Handling: Any image uploaded for feature inspection is loaded exclusively into volatile RAM for the duration of the serverless execution and permanently purged upon request completion.
- No Cloud Storage or CDNs: Refyn maintains no Amazon S3, Google Cloud Storage, or blob database storage for user photos. Images are never written to disk or recorded in application access logs.
- No Biometric Hash Databases: We do not extract, store, or cross-match biometric facial geometry or facial recognition templates.
2. Data We Collect and Retain
We collect solely the minimal structured data required to provide routine continuity:
- Account Credentials: If you register an account, we store your email address and an irreversibly salted bcrypt password hash. For OAuth users, we store the provider identifier and profile email.
- Protocol Configurations: Selected exercises, routine positions, frequency goals, and daily completion logs (timestamps and completion booleans).
- Guest Mode: Unauthenticated users store protocol preferences exclusively within browser
localStorage. No telemetry or profile records are transmitted to Refyn servers in guest mode.
3. AI Model Interaction & Inference Telemetry
When utilizing Refyn Coach:
- Text queries are transmitted to foundation model APIs (including Google Gemini) solely to parse physiological inquiries and match relevant exercises from our peer-reviewed library.
- We do not transmit user identity records, email addresses, or demographic markers to foundation model providers.
- AI Coach outputs are constrained by structured system safety directives prohibiting attractiveness scoring, demographic judgment, or diagnosis.
4. Age Restrictions & Minor Protection Policy
In compliance with global online safety mandates and Google Generative AI safety guidelines:
- 18+ Age Gate for Image Features: Any photographic analysis feature enforces a strict 18-year age minimum verified against account profile declarations.
- 13+ Platform Minimum: The general habit tracking platform requires a minimum age of 13 years. We do not knowingly collect or maintain data from individuals under 13.
5. Third-Party Advertising & Tracking Pixels
Refyn does not sell, license, or monetize user data. We do not install third-party tracking pixels (such as Meta Pixel, TikTok Pixel, or Google Remarketing Tags) on authenticated user habit screens, ensuring your personal routine data remains private.
6. User Rights: Data Export & Cascading Deletion
In accordance with GDPR (Articles 17 & 20) and CCPA/CPRA:
- Data Portability: You may request a machine-readable JSON export of your routine protocols and completion history at any time.
- Right to Erasure: When you delete your Refyn account, our database immediately executes an atomic cascading delete across users, routines, routine items, and completion records. No ghost records remain in live storage.
7. Security & Compliance Contact
For inquiries regarding Refyn's privacy architecture or to exercise statutory privacy rights, contact our engineering team directly at: