Privacy Policy

Last updated: 22 May 2026

Reminderly is a WhatsApp-first productivity assistant operated by Matpack Industries ("Reminderly", "we", "us"). This policy explains what personal data we collect when you use Reminderly, how we use it, who else can see it, and the rights you have over it. Plain English; no dark patterns.

The short version. We store the minimum needed to run the reminder bot for you — your phone number, what you ask us to remember, your timezone, and (only if you connect a calendar) the OAuth tokens to read your calendar events. We don't sell your data, we don't show ads, and we don't read your email content.

1. What data we collect

1.1 Information you give us directly

1.2 Information from connected services (optional)

If you connect Google Calendar or Outlook Calendar, we receive:

ServiceWhat we receiveWhy
Google CalendarRead/write access to events on your connected Google account; your Google account's email addressTo sync events into Reminderly, detect pending meeting invitations, and create events you ask us to schedule
Outlook Calendar (Microsoft Graph)Read/write access to events on your Outlook account; your account's email addressSame as Google

We do NOT request access to your email inbox. Meeting invitations are detected from the calendar itself (events you haven't responded to yet), not by reading email content. Reminderly never sees your Gmail or Outlook mail.

1.3 Information collected automatically

2. How we use your data

3. Google API Services User Data Policy — Limited Use disclosure

Reminderly's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

4. Who else sees your data — third-party processors

We use a small number of infrastructure providers to run Reminderly. Each processes data only on our instructions:

ProviderWhat they processWhere
Supabase (database)All your stored data (reminders, todos, habits) encrypted at rest by Supabase. OAuth tokens and Vault passwords are additionally encrypted by Reminderly with a key the database never sees.Tokyo, Japan (ap-northeast-1)
Render (app hosting)Server-side execution; transient request dataOregon, US
MetaWhatsApp message deliveryGlobal
Anthropic (Claude API)Individual messages sent for NLU parsing; not stored by Anthropic per their API termsUS
Groq (voice transcription)Voice note audio, transcribed and not retained after transcriptionUS
Razorpay / StripePayment processing for paid plansIndia / Global
SentryError stack traces (no message content; PII filtered out)US
CloudflareHosting of reminderly.ai marketing siteGlobal

5. We do NOT

6. Data retention

Your reminders, todos, habits, and calendar tokens are kept for as long as your Reminderly account is active. Voice note audio is deleted immediately after transcription. Diagnostic logs roll off after 30 days. When you delete your account, all your data is removed from our database within 30 days; backups roll off within 90 days.

7. Your rights

You can at any time:

8. Security

OAuth tokens are stored in our Supabase database, which uses Postgres Row-Level Security and is accessed only through our server-side service role key (never exposed to client browsers). All traffic to and from reminderly.ai uses HTTPS / TLS. WhatsApp webhook calls are verified using HMAC signatures from Meta. Admin endpoints require an API key.

9. Children

Reminderly is not directed at children under 13. We don't knowingly collect data from anyone under that age. If you believe a minor has signed up, email us and we'll delete the account.

10. Changes to this policy

If we make a material change to this policy, we'll send you a one-time WhatsApp notification with a summary of the change at least 14 days before it takes effect. Minor wording fixes don't trigger a notice.

11. Contact

Questions about this policy, data requests, or anything else:

Email: hello@reminderly.ai
Operator: Matpack Industries
Service: reminderly.ai