Privacy Policy

Last updated: March 1, 2026

Our Core Promise

REXI operates on a zero-retention architecture. Your documents are processed in volatile memory and permanently deleted the moment your analysis is complete.

Information We Collect

We collect minimal information necessary to provide our service:

  • Document Content: Temporarily processed for analysis only. Never stored permanently.
  • Usage Analytics: Anonymous, aggregated data about feature usage to improve our service.
  • Technical Data: Browser type, device info for compatibility and debugging.

How We Use Your Information

Your information is used exclusively to:

  • Analyze documents and generate risk reports
  • Improve our AI models (using only anonymized patterns, never your actual documents)
  • Ensure service reliability and security

Data Security

We implement industry-leading security measures:

256-bit Encryption

All data in transit is encrypted

Zero Retention

Documents deleted after analysis

No Ad Tracking

Your data is never sold or shared

GDPR Compliant

Privacy by design architecture

Third-Party Services

We use select third-party services to power our platform:

  • AI Processing: Google Gemini and Mistral AI for document analysis
  • Infrastructure: Vercel for hosting, Supabase for secure data storage

All third-party providers are contractually bound to protect your data and comply with applicable privacy laws.

Your Rights

You have the right to:

  • Access any personal data we hold about you
  • Request deletion of your data
  • Opt out of analytics collection
  • Lodge a complaint with a supervisory authority

Global Privacy Compliance (GDPR, CCPA, LGPD)

REXI operates internationally and strictly complies with major data protection frameworks:

  • EU/UK GDPR: We operate strictly as a Data Processor. We enforce Standard Contractual Clauses (SCCs) for any cross-border data transfers to the United States.
  • CCPA/CPRA (California): We do not "sell" or "share" your personal information. You have the absolute right to request deletion and opt-out of analytics.
  • LGPD (Brazil): We ensure robust, lawful processing of data for Brazilian residents under the explicit consent and legitimate interest bases.

Data Protection Officer (DPO)

To execute your Right to Erasure or request an SCC Data Processing Addendum (DPA), contact: dpo@rexi.pro

Contact Us

For privacy-related questions or to exercise your rights, contact us at:

privacy@rexi.pro

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date.