Refyn Safety & Privacy Governance

Privacy Policy

Refyn is built as an instrument, not an advertising network. We operate under strict data minimization: we do not store facial images, we do not monetize user insecurity, and we do not run third-party tracking pixels on personal habit surfaces.

Last Updated & Verified: September 2026 · Version 1.2
Zero Photo Storage

Images submitted for protocol evaluation are processed purely in-memory and discarded. Zero blob storage, zero CDN persistence.

Cryptographic Security

User credentials are protected with 12-round bcrypt salted hashing. All traffic is enforced over strict TLS 1.3 transport.

Cascading Deletion

You own your data. Account termination triggers irreversible foreign-key cascading deletions across all database tables.

1. Foundational Commitment: Zero Facial Image Persistence

Refyn operates strictly on appearance habits, biomechanics, and evidence evaluation. To protect user autonomy and eradicate data breach exposure:

  • Ephemeral In-Memory Handling: Any image uploaded for feature inspection is loaded exclusively into volatile RAM for the duration of the serverless execution and permanently purged upon request completion.
  • No Cloud Storage or CDNs: Refyn maintains no Amazon S3, Google Cloud Storage, or blob database storage for user photos. Images are never written to disk or recorded in application access logs.
  • No Biometric Hash Databases: We do not extract, store, or cross-match biometric facial geometry or facial recognition templates.

2. Data We Collect and Retain

We collect solely the minimal structured data required to provide routine continuity:

  • Account Credentials: If you register an account, we store your email address and an irreversibly salted bcrypt password hash. For OAuth users, we store the provider identifier and profile email.
  • Protocol Configurations: Selected exercises, routine positions, frequency goals, and daily completion logs (timestamps and completion booleans).
  • Guest Mode: Unauthenticated users store protocol preferences exclusively within browser localStorage. No telemetry or profile records are transmitted to Refyn servers in guest mode.

3. AI Model Interaction & Inference Telemetry

When utilizing Refyn Coach:

  • Text queries are transmitted to foundation model APIs (including Google Gemini) solely to parse physiological inquiries and match relevant exercises from our peer-reviewed library.
  • We do not transmit user identity records, email addresses, or demographic markers to foundation model providers.
  • AI Coach outputs are constrained by structured system safety directives prohibiting attractiveness scoring, demographic judgment, or diagnosis.

4. Age Restrictions & Minor Protection Policy

In compliance with global online safety mandates and Google Generative AI safety guidelines:

  • 18+ Age Gate for Image Features: Any photographic analysis feature enforces a strict 18-year age minimum verified against account profile declarations.
  • 13+ Platform Minimum: The general habit tracking platform requires a minimum age of 13 years. We do not knowingly collect or maintain data from individuals under 13.

5. Third-Party Advertising & Tracking Pixels

Refyn does not sell, license, or monetize user data. We do not install third-party tracking pixels (such as Meta Pixel, TikTok Pixel, or Google Remarketing Tags) on authenticated user habit screens, ensuring your personal routine data remains private.

6. User Rights: Data Export & Cascading Deletion

In accordance with GDPR (Articles 17 & 20) and CCPA/CPRA:

  • Data Portability: You may request a machine-readable JSON export of your routine protocols and completion history at any time.
  • Right to Erasure: When you delete your Refyn account, our database immediately executes an atomic cascading delete across users, routines, routine items, and completion records. No ghost records remain in live storage.

7. Security & Compliance Contact

For inquiries regarding Refyn's privacy architecture or to exercise statutory privacy rights, contact our engineering team directly at:

privacy@refyn.app · Refyn Systems Inc.