Privacy Policy
Last updated: 26 June 2026
Reminderly is a WhatsApp-first productivity assistant operated by Matpack Industries ("Reminderly", "we", "us"). This policy explains what personal data we collect when you use Reminderly, how we use it, who else can see it, and the rights you have over it. Plain English; no dark patterns.
1. What data we collect
1.1 Information you give us directly
- WhatsApp phone number — required so the bot can message you back. We never share this.
- Your name and timezone — captured during onboarding so reminders fire at the right local time.
- Content you send the bot — reminders, to-dos, habits, notes, and any voice messages you record. This is exactly what you'd type if you used a typical reminder app.
1.2 Information from connected services (optional)
If you connect Google Calendar or Outlook Calendar, we receive:
| Service | What we receive | Why |
|---|---|---|
| Google Calendar | Read/write access to events on your connected Google account; your Google account's email address | To sync events into Reminderly, detect pending meeting invitations, and create events you ask us to schedule |
| Outlook Calendar (Microsoft Graph) | Read/write access to events on your Outlook account; your account's email address | Same as Google |
We do NOT request access to your email inbox. Meeting invitations are detected from the calendar itself (events you haven't responded to yet), not by reading email content. Reminderly never sees your Gmail or Outlook mail.
1.3 Information collected automatically
- Diagnostic logs — server-side request/error logs (no message bodies) for debugging.
- Crash reports via Sentry — stack traces only, no personal content.
- Aggregate usage counts — total reminders fired, broadcast counts, etc., to operate the service and improve it.
2. How we use your data
- To fire your reminders, todos, habit broadcasts, morning briefs, weekly reports — all the bot's core jobs.
- To sync your calendar events into Reminderly and flag pending invitations.
- To send transactional WhatsApp messages from you to the bot and vice versa (via Meta).
- To process voice notes you send (transcribed by Groq Whisper; the audio is processed transiently and not retained after transcription).
- To process complex commands using Anthropic's Claude AI for natural-language understanding. We send only the specific message you typed; we don't send your full history.
- To accept payment if you upgrade to a paid plan — handled by Razorpay (India) or Stripe (international). We never see your card details.
3. Legal bases for processing (GDPR)
If you are in the UK, EU, or EEA, the General Data Protection Regulation requires us to have a legal basis for each use of your personal data. Ours are:
- Performance of a contract — to run the service you signed up for: storing and firing your reminders, todos and habits, syncing a calendar you connect, and sending the bot's messages.
- Consent — for optional features you switch on, such as connecting Google or Outlook Calendar. You can withdraw consent at any time (disconnect the calendar, or message
stop) without affecting processing done before you withdrew. - Legitimate interests — to keep the service secure, prevent abuse and spam, debug failures, and improve the product, balanced against your rights and freedoms.
- Legal obligation — to comply with applicable law, for example retaining payment records for tax and accounting.
4. Google API Services User Data Policy — Limited Use disclosure
Reminderly's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We use Google Calendar data only to provide and improve the calendar-sync and invitation-detection features visible to you in Reminderly.
- We do not transfer Google user data to any third party except as necessary to provide the service (the infrastructure providers listed in section 5) or as required by law.
- We do not use Google user data for advertising, including retargeting, personalised advertising, or interest-based advertising.
- We do not allow humans at Reminderly to read Google user data, except (a) with your explicit consent for a specific message, (b) for security/abuse investigations, (c) to comply with law, or (d) for aggregate/anonymous internal operations after anonymisation.
5. Who else sees your data — third-party processors
We use a small number of infrastructure providers to run Reminderly. Each processes data only on our instructions:
| Provider | What they process | Where |
|---|---|---|
| Supabase (database) | All your stored data (reminders, todos, habits) encrypted at rest by Supabase. OAuth tokens and Vault passwords are additionally encrypted by Reminderly with a key the database never sees. | Tokyo, Japan (ap-northeast-1) |
| Render (app hosting) | Server-side execution; transient request data | Oregon, US |
| Meta | WhatsApp message delivery | Global |
| Anthropic (Claude API) | Individual messages sent for natural-language parsing, under Anthropic's commercial API terms (API inputs are not used to train their models) | US |
| Groq (voice transcription) | Voice note audio, transcribed and not retained after transcription | US |
| Razorpay / Stripe | Payment processing for paid plans | India / Global |
| Sentry | Error stack traces (no message content; PII filtered out) | US |
| Cloudflare | Hosting of reminderly.ai marketing site | Global |
6. International data transfers
Reminderly is operated from India, and the providers above process data in several countries — your data may be processed in or moved between Japan (database), the United States (app hosting, AI parsing, voice transcription, error monitoring, international payments), and India and other countries (Indian payments, WhatsApp delivery, CDN). When data leaves your country, we rely on appropriate safeguards: each provider acts only as our processor under a data processing agreement, and transfers are made under recognised mechanisms such as the European Commission's Standard Contractual Clauses or an adequacy decision where one applies. You can ask us for more detail on a specific provider at any time.
7. We do NOT
- Sell your data to anyone.
- Show ads or use your data for advertising.
- Train AI models on your reminders, todos, or calendar.
- Read your email content (we don't have permission to).
- Share your phone number with anyone outside the providers above.
8. Data retention
Your reminders, todos, habits, and calendar tokens are kept for as long as your Reminderly account is active. Voice note audio is deleted immediately after transcription. Diagnostic logs roll off after 30 days. When you delete your account, all your data is removed from our database within 30 days; backups roll off within 90 days.
9. Your rights
You can take these actions yourself at any time:
- Disconnect a calendar — message the bot:
disconnect <email>. The OAuth token is deleted immediately. - Stop receiving messages — message
stop. All proactive sends pause. - Export your data — email hello@reminderly.ai; we'll send a JSON dump within 30 days.
- Delete your account — email hello@reminderly.ai; we'll permanently delete all your data within 30 days and confirm.
- Revoke Google or Microsoft access directly from Google account permissions or Microsoft account permissions.
If you are in the UK, EU, or EEA, the GDPR also gives you the right to:
- Access the personal data we hold about you.
- Rectification — have inaccurate or incomplete data corrected.
- Erasure ("right to be forgotten") — have your data deleted.
- Restriction — ask us to pause processing in certain cases.
- Portability — receive your data in a structured, machine-readable format and have it transferred where technically feasible.
- Object to processing based on our legitimate interests.
- Withdraw consent at any time, for anything we process on the basis of consent.
- Lodge a complaint with your local data protection authority. We'd appreciate the chance to resolve it first, but this right is yours regardless.
To exercise any of these, email hello@reminderly.ai. We verify the request comes from you (usually via your registered WhatsApp number) and respond within 30 days, free of charge.
10. California privacy rights
If you are a California resident, you may have rights under the California Consumer Privacy Act (as amended by the CPRA), including the right to know what personal information we collect and how it is used, to access and delete it, to correct inaccurate information, and to not be discriminated against for exercising these rights. We do not sell or share your personal information (as those terms are defined under California law), and we do not use it for cross-context behavioural advertising. To exercise a California right, email hello@reminderly.ai.
11. Security
Your data lives in a Postgres database (Supabase) that is reachable only from our own servers, using a secret service key that is never exposed to any browser or app. The most sensitive fields — calendar OAuth tokens and Vault passwords — are additionally encrypted by Reminderly before they are stored, with a key the database itself never holds. All traffic to and from our services uses HTTPS / TLS. WhatsApp webhook calls are verified using Meta's HMAC signatures, and payment webhooks are signature-verified. Admin and owner endpoints require authentication, with rate limiting on sign-in. No internet service is unbreakable; our aim is to make a breach hard to achieve, fast to detect, and straightforward to recover from.
12. Children
Reminderly is not directed at children under 13. We don't knowingly collect data from anyone under that age. If you believe a minor has signed up, email us and we'll delete the account.
13. Changes to this policy
If we make a material change to this policy, we'll send you a one-time WhatsApp notification with a summary of the change at least 14 days before it takes effect. Minor wording fixes don't trigger a notice.
14. Contact
Questions about this policy, data requests, or anything else:
Email: hello@reminderly.ai
Operator: Matpack Industries
Service: reminderly.ai