Privacy Policy

Effective Date: February 10, 2026  |  Service Provider: Rhoe, LLC-FZ (UAE)  |  Product: REEN — reen.tech


1. Introduction

This Privacy Policy describes how Rhoe, LLC-FZ (“we”, “us”) collects, uses, stores, and protects your personal data when you use REEN (“the Service”).

We are committed to protecting your privacy and complying with applicable data protection laws, including:


2. Data Controller

Rhoe, LLC-FZ

Meydan Free Zone, Dubai, UAE

Email: [email protected]

For GDPR purposes, Rhoe, LLC-FZ is the data controller for personal data processed through the Service.


3. Data We Collect

3.1. Account Data

DataPurposeLegal Basis (GDPR)
UsernameAccount identificationContract performance
Password (hashed)AuthenticationContract performance
Email (if provided)Account recovery, notificationsConsent / Legitimate interest
WebAuthn credentialsPasskey authenticationContract performance

3.2. User-Generated Content

DataPurposeLegal Basis (GDPR)
Plans, tasks, subtasksGant project managementContract performance
Conference messagesAI Conference conversationsContract performance
Uploaded filesConference attachmentsContract performance

3.3. Automatically Collected Data

DataPurposeLegal Basis (GDPR)
IP addressSecurity, abuse preventionLegitimate interest
Request logsDebugging, securityLegitimate interest
Audit log (actions)Security, accountabilityLegitimate interest

3.4. Data We Do NOT Collect


4. How We Use Your Data

We use your data exclusively for:

  1. Providing the Service — account management, content storage, conference messaging
  2. Security — authentication, abuse prevention, audit logging
  3. Service improvement — aggregated, anonymized usage analytics (e.g., feature adoption rates)
  4. Legal compliance — responding to lawful requests from authorities

We do NOT use your data for:


5. AI-Specific Data Practices

5.1. Research Mode

Our ARGUS pipeline processes publicly available research papers using AI models operated by us (Rhoe, LLC-FZ) with our own API keys. Your browsing of Research content does not send your data to any AI provider.

5.2. AI Conference

Important: Third-Party AI Data Flow. When you use AI Conference with reen-cli, your device sends prompts and receives responses directly from the AI provider(s) you choose (e.g., Anthropic, OpenAI, Google), using your own API keys and under your separate agreement with those providers. We do not control, intercept, or intermediate these API calls. However, the text of conference messages (including AI-generated responses) is transmitted to and stored by the Service as part of the conversation history described in this Policy. You are responsible for reviewing and accepting the terms and privacy policies of your chosen AI providers.

5.3. No Training on Your Data

We do not use any user content (plans, tasks, conference messages, uploaded files) to train, fine-tune, or improve AI models. This applies to both our internal pipeline and third-party AI services.


6. Data Storage and Security

6.1. Infrastructure

6.2. Security Measures

6.3. Data Transfers

Your data may be transferred to and processed in the United States (hosting infrastructure). For EU users, this transfer is conducted under Standard Contractual Clauses (SCCs) as appropriate.


7. Data Retention

Data TypeRetention PeriodDeletion
Account dataUntil account deletionDeleted on request
Plans and tasksUntil deleted by user or account deletionUser can delete anytime
Conference messagesUntil conference deleted by user or account deletionUser can delete anytime
Audit logs12 monthsAuto-pruned after retention period
Request logs30 daysAuto-rotated
Uploaded filesUntil deleted by user or account deletionUser can delete anytime

After account deletion, all associated data is permanently removed within 30 days. Backup copies (if any) are purged within 90 days.


8. Data Sharing

We do not sell your personal data. We may share data only in these circumstances:

RecipientPurposeData Shared
Railway (hosting)InfrastructureEncrypted data at rest
Law enforcementLegal obligationAs required by UAE law or valid legal process

We do not share data with AI model providers, advertising networks, data brokers, or analytics platforms.


9. Cookies and Local Storage

9.1. What We Use

The Service uses localStorage (not cookies) to store:

ItemPurposeDuration
auth_token (JWT)Session authenticationUntil logout or expiry
UI preferencesTheme, language, sidebar statePersistent

9.2. What We Do NOT Use

Since we do not use cookies for tracking purposes, cookie consent banners are not required under current regulations. If this changes, we will update this policy.


10. Your Rights

10.1. All Users

You have the right to:

10.2. EU/EEA Users (GDPR)

In addition to the above, you have the right to:

10.3. California Users (CCPA)

You have the right to:

10.4. UAE Users (PDPL)

Under the UAE Personal Data Protection Law, you have the right to:


11. Children’s Privacy

The Service is not directed to children under 16. We do not knowingly collect personal data from children. If we discover that a child under 16 has provided personal data, we will delete it promptly.


12. Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices or applicable law. Material changes will be communicated via the Service interface or email (if provided). Your continued use of the Service after changes constitutes acceptance.


13. Contact and Data Requests

For privacy inquiries, data access requests, or to exercise any of your rights:

Email: [email protected]

Company: Rhoe, LLC-FZ

Address: Meydan Free Zone, Dubai, UAE

We will respond to data requests within 30 days (or sooner as required by applicable law).

Last updated: February 12, 2026