Last updated: 9 September 2026
Two things are still outstanding on this page:
Everything else on this page reflects RemindU's actual data practices as implemented in the product today. This page should still be reviewed by a qualified solicitor before RemindU is relied on commercially or processes real customer payments at scale — see FINAL_AUDIT.md.
This Privacy Policy explains how personal data is collected, used, stored, shared and protected when you use RemindU (the “Service”), a web application that helps small businesses track customer enquiries and follow-ups. It is written to comply with the UK General Data Protection Regulation (“UK GDPR”) and the Data Protection Act 2018.
This policy applies to everyone whose personal data RemindU processes: people who create a RemindU account (“Account Holders”), and — where an Account Holder enters details about their own customers — those customers too. Section 14 explains which parts of this policy apply to you if you fall into the second group.
For the personal data described in Section 4(a)–(c) below, the data controller is:
[TO BE ADDED — registered legal name and address, on completion of Companies House registration], trading as RemindU (“RemindU”, “we”, “us”).
Contact: [TO BE ADDED — privacy contact email]
For the personal data described in Section 4(d) (data an Account Holder enters about their own customers), RemindU acts as a data processor, and the Account Holder's business is the data controller. See Section 3.
RemindU plays two different roles under UK GDPR, depending on whose data is involved:
(a) Account Holder data
When you sign up, we collect your name, email address, and a bcrypt-hashed version of your password (we never store or can retrieve your actual password). We also collect your business name, business type, and the reply-tone preference you set during onboarding.
(b) Billing data
If you subscribe to a paid plan, our payment processor, Stripe, Inc. (“Stripe”), collects and processes your card and billing details directly — RemindU never receives or stores your full card number. We store only a Stripe customer and subscription reference, your plan tier, and subscription status.
(c) Technical and usage data
Our hosting provider automatically logs standard web request data (IP address, browser user-agent, timestamps, and the page requested) for security and operational purposes. We set a single essential session cookie to keep you logged in — see Section 9.
(d) Data entered by an Account Holder about their own customers
If you are an Account Holder, you may type or paste in details about your own enquiries and customers, or forward an email to your unique RemindU inbox address for the same purpose: names, email addresses, phone numbers, the content of an enquiry, an estimated value, notes, and follow-up dates. RemindU stores this data on your behalf and does not decide what you choose to enter or forward. A forwarded email is held for your review and is not turned into a customer record until you approve it. If you are the person whose details were entered or forwarded this way by someone else's business, see Section 14.
(e) Optional AI-related data
If you switch on AI assistance in Settings, the enquiry text and customer details relevant to that request are sent to Anthropic, PBC (“Anthropic”) to generate suggested extractions or draft replies. This is off by default. See Section 6.
| Purpose | Data used | Lawful basis |
|---|---|---|
| Creating and running your account | Account Holder data (4a) | Performance of a contract (Art. 6(1)(b)) |
| Billing and subscription management | Billing data (4b) | Performance of a contract; legal obligation (tax/accounting records) |
| Security, fraud prevention, debugging | Technical/usage data (4c) | Legitimate interests (Art. 6(1)(f)) — keeping the Service secure and working |
| Providing the enquiry-tracking Service itself | Customer data you enter (4d) | Performance of our contract with you (as processor, on your instructions) |
| Optional AI extraction/drafting | AI-related data (4e) | Consent — only when you explicitly enable it (Art. 6(1)(a)) |
We do not use your data for advertising, and we do not sell personal data to any third party.
By default, RemindU extracts enquiry details and drafts responses using a built-in rule-based system that runs entirely within our own infrastructure — no data leaves RemindU for this. Every feature works fully with AI switched off.
If you choose to enable AI, one of two things happens depending on your plan:
In both cases, the relevant enquiry text and customer details are sent to Anthropic solely to generate a suggested output. Nothing generated is ever sent to a customer automatically — a human always reviews and copies the draft before anything is sent. No decision with a legal or similarly significant effect on any individual is ever made by AI alone (see Section 10).
We use a small number of third-party service providers (“sub-processors”) to operate RemindU. Each is only given the data it needs to perform its function, and none may use your data for its own purposes.
| Provider | Purpose | Data involved |
|---|---|---|
| Vercel Inc. | Application hosting | All data, in transit and in server memory while a request is processed |
| Supabase, Inc. (on AWS, EU-West/Ireland) | Database storage | All data described in Section 4, at rest |
| Stripe, Inc. | Payment processing | Billing data (4b), including card details, which we never see |
| Anthropic, PBC | AI extraction/drafting (only if enabled) | The specific enquiry/customer text relevant to that AI request (4e) |
| Twilio SendGrid, Inc. | Receiving emails forwarded to your RemindU inbox address (only if used) | The forwarded email itself (4d) — this is plain email routing, not a Google/Gmail account connection |
| Resend, Inc. | Sending password-reset and email-verification messages | Your email address and name (4a) — the minimum needed to deliver the message |
We may also disclose personal data if required by law, court order, or to protect the rights, property or safety of RemindU, our users, or the public.
Our database is hosted in the EU (Ireland). Vercel, Stripe and Anthropic are US-based providers who may process data in the United States or other countries outside the UK. Where this happens, we rely on the transfer mechanisms each provider has in place to protect UK and EU personal data — typically Standard Contractual Clauses with the UK International Data Transfer Addendum, or an equivalent adequacy or certification mechanism. You can ask us for more detail on the safeguards used for a specific provider.
RemindU sets exactly one cookie: a signed, httpOnly session cookie used solely to keep you logged in. This is strictly necessary for the Service to function and is exempt from consent requirements under the Privacy and Electronic Communications Regulations (PECR). We do not currently use any analytics, advertising, or tracking cookies. If that changes, we will update this policy and ask for your consent first, where required.
RemindU does not make any decision about you, or about your customers, using automated means alone that produces legal effects or similarly significantly affects anyone. Optional AI features only ever produce a suggested draft or suggested field values that a human reviews before anything is acted on or sent.
We keep your Account Holder data and the customer data you have entered for as long as your account exists. If your subscription lapses or is cancelled, your account and its data are not automatically deleted — access is simply paused until you resubscribe, request deletion, or export it (see Section 12).
If you delete your account, your business record, users, customers, enquiries, and their activity history are permanently and immediately deleted from our production database. Billing records may be retained for longer where we are legally required to keep them — currently up to six years, in line with UK tax and accounting record-keeping requirements — and Stripe retains its own transaction records under its own retention policy.
Under UK GDPR, you have the right to:
You can exercise most of these rights yourself, at any time, from Settings: exporting a full copy of your data, or permanently deleting your account. For anything else, or if you cannot access Settings, email us at [TO BE ADDED — privacy contact email]. We will respond within one calendar month, as required by Article 12(3) UK GDPR (extendable by a further two months for complex requests, in which case we will tell you why).
To complain to the regulator: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. Helpline: 0303 123 1113. Website: ico.org.uk.
We use industry-standard measures appropriate to the risk, including: passwords hashed with bcrypt and never stored in plain text; encryption in transit (HTTPS/TLS) for all traffic; AES-256-GCM encryption at rest for any AI API key you supply; strict per-business data isolation enforced on every database query; and signed, httpOnly, secure session cookies. No method of storage or transmission is completely secure, and we cannot guarantee absolute security, but we take reasonable steps to protect your data and will notify affected users and the ICO of any data breach as required by law.
If a business using RemindU has entered your name, contact details, or enquiry into the Service as their customer, you are not a RemindU Account Holder, and RemindU is not the controller of that data — the business you enquired with is (see Section 3). Please direct any request about your data to that business in the first instance. If you are unable to reach them, contact us at [TO BE ADDED — privacy contact email] and we will assist as their processor, including by putting you in touch with them or, where appropriate, actioning a request they have approved.
RemindU is a business tool intended for use by adults running a business. It is not directed at, and we do not knowingly collect personal data from, children.
We may update this policy as the Service changes. We will update the “Last updated” date above, and if a change is material, we will also notify Account Holders by email or an in-app notice before it takes effect.
For any question about this policy or your data: [TO BE ADDED — privacy contact email].