Privacy Policy

Last updated: July 12, 2026

Introduction

Redy ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application and web services (collectively, the "Service").

By using Redy, you agree to the collection and use of information in accordance with this policy. We will not use or share your information with anyone except as described in this Privacy Policy.

Information We Collect

Account Information

When you create an account, we collect:

  • Email address
  • Name (optional)
  • Profile photo (optional)
  • Authentication credentials (securely hashed)

Vault Data

Information you add to your vault, including:

  • Item details (name, description, category, brand, model)
  • Purchase information (date, price, retailer)
  • Warranty and service records
  • Documents and images you upload (receipts, manuals, photos)

Email Integration Data

If you connect your email account (Gmail, Outlook, or other providers), we access:

  • Email metadata: Subject lines, sender addresses, and dates to identify purchase receipts
  • Email content: Body text of emails that appear to contain receipts or order confirmations
  • Attachments: PDF receipts, invoices, and confirmation documents

Important: We only process emails that match our receipt detection patterns. We do not read, store, or analyze your personal correspondence, social emails, or any other non-commercial communications.

Usage Data

We automatically collect:

  • Device information (type, operating system, app version)
  • Log data (access times, pages viewed, app crashes)
  • IP address (for security and fraud prevention)

How We Use Your Information

We use your information to:

  • Provide the Service: Store and organize your vault items, process documents, send warranty reminders
  • Email Receipt Import: Automatically detect and extract purchase information from connected email accounts to populate your vault
  • Account Management: Authenticate users, manage subscriptions, provide customer support
  • Improve the Service: Analyze usage patterns to enhance features and fix bugs
  • Communication: Send important notifications about your account, warranty expirations, and service updates
  • Security: Detect and prevent fraud, abuse, and security threats

Email Data Processing (Gmail, Outlook)

What We Access

When you connect your Gmail or Outlook account, we request read-only access to:

  • Search and filter emails matching receipt/order patterns
  • Read email content to extract purchase details
  • Download attachments (PDFs, images) that appear to be receipts

What We Extract

From receipt emails, we extract only:

  • Product/item name and description
  • Purchase price and currency
  • Purchase date
  • Merchant/retailer name
  • Order/confirmation numbers
  • Warranty information (if present)

What We Don't Do

  • We do NOT store full email content after processing
  • We do NOT read personal, social, or non-commercial emails
  • We do NOT share email data with third parties
  • We do NOT use email content for advertising
  • We do NOT sell or monetize your email data

Data Retention

We only retain extracted receipt data (item name, price, date, merchant) that you approve for import into your vault. Raw email content is processed in memory and immediately discarded.

Data Storage & Security

We implement industry-standard security measures:

  • Encryption: All data is encrypted in transit (TLS 1.3) and at rest (AES-256)
  • Authentication: Secure OAuth 2.0 for email connections; tokens are encrypted
  • Infrastructure: Production application data is stored with Supabase in the EU (AWS eu-central-1, Frankfurt); the production API runs on Render in the EU (Frankfurt). Non-production/staging environments may run in other regions and do not process customer production data.
  • Access Controls: Strict access policies; employee access logged and audited
  • Backups: Regular encrypted backups with geographic redundancy

Website Data (redy.co)

  • Error monitoring: the website uses Sentry to capture technical errors (including IP address and browser metadata) on the basis of legitimate interest in operating a reliable service; no advertising or cross-site tracking is performed.
  • Contact form: submissions (name, email, message) are transmitted to us for handling your request and are not used for any other purpose.
  • Cookies: the website sets a single functional cookie (i18n_redirected) to remember your language choice. No analytics or advertising cookies are set.
  • Fonts are self-hosted; no font requests are sent to third parties.

Data Sharing & Third Parties

We do NOT sell your personal data. We may share data only with:

  • Service Providers: Service providers that process data on our behalf: Supabase (database, authentication, file storage — EU region), Render (application hosting — EU region for production), Cloudflare (edge network, DDoS/WAF protection of public traffic), Stripe (payment processing; raw card data never reaches us), SendGrid (transactional email), and Sentry (web error monitoring, with PII scrubbing). Our mobile apps additionally use Google Firebase for push notifications, crash reporting, and app analytics (screen views and usage events). Observability telemetry (request traces and application metrics — not end-user content) is processed by Grafana Cloud when enabled; it is not currently enabled in production.
  • AI Processing: AI and document processing: Google Cloud Vision (OCR on uploaded receipt/document images) and Google Gemini (text extraction and AI-assist features, which can include receipt, document, and product-passport content). This data is not used to train models. Product-usage analytics events may be processed in Google BigQuery; address lookups use Google Maps.
  • Legal Requirements: When required by law, court order, or to protect our rights
  • Family Members: Items you explicitly choose to share with household members

Your Rights (GDPR & CCPA)

You have the right to:

  • Access: Request a copy of all data we hold about you
  • Correction: Update or correct inaccurate information
  • Deletion: Request deletion of your account and all associated data
  • Portability: Export your vault data in standard formats (JSON, CSV)
  • Disconnect: Revoke email access at any time from Settings
  • Opt-out: Disable marketing communications

To exercise these rights, visit Settings > Privacy in the app, or contact us at privacy@redy.co.

Data Retention

  • Active Accounts: Data retained while your account is active
  • Deleted Accounts: Data permanently deleted within 30 days of account deletion request
  • Email Tokens: OAuth tokens revoked immediately when you disconnect email
  • Backups: Purged from backups within 90 days of deletion

Children's Privacy

Redy is not intended for children under 13 (or 16 in the EU). We do not knowingly collect personal information from children. If you believe we have collected data from a child, please contact us immediately.

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes via email or in-app notification. Continued use of the Service after changes constitutes acceptance of the updated policy.

Contact Us

If you have questions about this Privacy Policy or our data practices, please contact:

Redy

Email: privacy@redy.co

Support: support@redy.co