Legal
Privacy policy
Last updated: October 8, 2026
This policy explains what information Reins collects, how it is used, and the choices you have. It covers the
Reins apps for Android, iOS, macOS, Windows and Linux when they are used with our hosted service at
app.reins2fa.com, and this website, reins2fa.com. If you use the apps with a
server that someone else runs from Reins's open-source code, that server's operator is responsible for the
data on it; what the apps themselves do, including everything in Google user data,
is the same.
- Who we are
- The short version
- What our server stores
- What passes through without being stored
- Google user data
- What stays on your phone
- This website and the waitlist
- Service providers and other parties
- Logs
- How long we keep data
- Your choices and rights
- Children
- Security
- Changes and contact
Who we are
Reins and the hosted Reins service are operated by Daniil Katulevskiy, an individual developer in California, USA ("we", "us"). For anything about privacy, write to privacy@reins2fa.com.
The short version
- Reins lets AI tools ask to act on your accounts. You approve each request on your phone, or set up standing permissions and Autopilot to approve some of them for you.
- Your phone keeps the credentials for your connected services (Google, GitHub, Telegram and others) and makes the calls to those services itself.
- Our server relays requests and the answers you approve between your AI tools and your phone. Relayed content is held in memory for at most 10 minutes and is never written to disk or logs.
- What we do store about your activity is encrypted on your phone with a key we do not have.
- We do not sell data, show ads, or use analytics, tracking or advertising identifiers in the apps, on the server or on this website.
What our server stores
Your account
You sign in through our sign-in provider, WorkOS, with Google, Apple, GitHub, Microsoft or a code sent to your email. We store your email address, your name if your sign-in provider gives it, the WorkOS account identifier, and your sign-in sessions. We also store the devices you signed in with: device name, type, identifier and when each was last used.
Your encrypted keys and password vault
Your phone creates your account's encryption keys and encrypts them before they reach us, together with a hash used to check them. Items you keep in the Reins password vault are encrypted on your devices; we store them but cannot read them.
An encrypted copy of your phone's Reins data
So that another phone of yours can take over, your phone uploads an encrypted copy of its Reins data: your connected accounts and their sign-in tokens, standing permissions, settings and activity history. It is encrypted on your phone with your account's key, which never leaves your devices in a form we can use. We store the ciphertext and cannot read it.
Your approval phone
Which phone approves your requests, and its push token from Google Firebase Cloud Messaging (Android) or Apple Push Notification service (iOS), so that we can wake it when a request arrives.
Your AI connections
For each AI tool or computer you connect: the client's name and host (for example "Claude",
claude.ai), the name you gave the connection, when it was created and last used, a hash of its
refresh token, and the registration details the client sent (client name, redirect addresses).
What passes through without being stored
- Requests and results. When an AI tool asks to do something, our server receives the request with its details (for example the email it wants to send) and holds it in memory until your phone answers, or at most 10 minutes. What your phone returns (for example the messages you allowed it to read) passes through to that AI tool the same way. Neither is written to disk or to logs.
- Sealed answers to your computer. Credentials and answers your phone sends to the Reins desktop app are encrypted to that computer's key. We relay them but cannot read them.
- What your phone reports. Which kinds of services you connected (for example "gmail", without the address), and the names and tool lists of MCP servers you added, so that AI tools see the right tools. This is kept in memory and replaced each time your phone reports.
- Large files. Files too large to pass through a request (for example a large attachment or a release asset) are stored on our server's disk for that one operation and deleted when it finishes, and in any case within one hour. For these operations, and for very large results from MCP tools, your phone may ask our server to make one request on its behalf, including the authorization header that request needs. We use that header for that request only and never store or log it.
Google user data
If you connect a Google account in the Reins app, the app asks Google for the following access. Each is used only for the purpose listed.
| Access | What Reins does with it |
|---|---|
Gmail: read your emailgmail.readonly |
Search for, read, and download attachments of the messages an AI tool you connected asks for, once you approve that request. |
Gmail: send email on your behalfgmail.send |
Send an email an AI tool wrote, once you approve its recipients and content. |
Google Calendar: see your calendars and eventscalendar.readonly |
List your calendars and the events an AI tool asks about, once you approve. |
Google Calendar: see and edit eventscalendar.events |
Create or update an event an AI tool proposes, once you approve it. |
Google Contacts: see your contactscontacts.readonly |
Look up the contacts an AI tool asks for, once you approve. |
How Google data is handled
- Your phone talks to Google directly. Google's sign-in tokens are stored only on your phone, encrypted, and in the encrypted copy described above, which we cannot read. Our server never uses them.
- Used only for features you can see and control. Reins accesses Google data only to carry out a request from an AI tool that you connected, after you approve it on your phone, or under a standing permission or Autopilot setting that you turned on. The result goes from your phone, through our server (in memory, at most 10 minutes, never written to disk or logs), to that AI tool.
- Kept on your phone. Your phone's activity history records each request and what was returned, so that you can review it. It is encrypted on your phone and in the encrypted copy.
- Not sold, not used for ads. We do not sell Google user data, use it for advertising, retargeting or interest-based ads, or use it to determine creditworthiness or for lending.
- Not transferred to anyone other than the AI tool you chose to send it to, as part of the request you approved, except when necessary to comply with the law or for security (for example to investigate abuse), or as part of a merger or acquisition with notice to you.
- Not read by people. No one at Reins reads your Google data, unless you ask us to and give explicit permission for specific messages (for example for support), it is necessary for security purposes, or the law requires it.
- Not used to train AI. We do not use Google user data to develop, improve or train generalized or non-personalized artificial intelligence or machine learning models. Autopilot is a personal model that runs only on your phone, and nothing it learns leaves your phone.
- The AI tool you choose (for example Claude by Anthropic or ChatGPT by OpenAI) receives only what you approve, and handles it under its own terms and privacy policy.
Reins's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
You can disconnect Google at any time in the Reins app (Integrations), which removes Google's tokens from your phone, and you can revoke Reins's access in your Google Account at myaccount.google.com/connections.
What stays on your phone
The credentials for your connected services, your standing permissions, your activity history, and everything about Autopilot (its model, your past decisions and what it learned from them) are stored on your phone, encrypted with a key protected by the Android Keystore or the iOS Keychain. Apart from the encrypted copy described above, none of it is sent to us. The apps contain no analytics, crash-reporting or advertising software. Autopilot's model files are downloaded from this website, which sees that download like any other web request.
The apps ask for phone permissions only when you turn on a feature that needs them: notifications (to show requests), Face ID or fingerprint (to confirm approvals), the camera on iPhone (only to scan a pairing code, nothing is recorded), and, if you connect them, your phone's calendar and contacts. The Android app downloaded from this website can also, if you connect it, read and send text messages; the Google Play version cannot. Calendar, contacts and text messages are read or changed only to carry out requests you approve, in the same way as described for Google data above.
This website and the waitlist
This website sets no cookies, uses no browser storage, and loads nothing from other companies. If you join the waitlist, we store your email address, which form you used, and when. Your IP address is used to limit abuse of the form. We use the list only to tell you about Reins, and you can ask us to remove you at any time.
Service providers and other parties
- OVHcloud hosts our server in the United States.
- WorkOS handles sign-in. It receives your email address, name and the sign-in method you use, under its own privacy policy.
- Google Firebase Cloud Messaging (Android) and Apple Push Notification service (iOS) deliver wake-up messages to your phone. A message contains only a request identifier and type, never request content.
- Cloudflare provides DNS for our domains and delivers this website.
- Services you connect (Google, GitHub, Telegram, GitLab, Codeberg, Bitbucket, MCP servers you add) are contacted by your phone directly, under their own terms and privacy policies. The large-file case above is the only time our server contacts them for you.
- AI tools you connect receive the results you approve, under their own policies.
We may disclose information if the law requires it, and only what it requires.
Logs
Our server software writes operational logs without tokens, request contents or message contents. Failed sign-in attempts are logged with the IP address they came from. Our web server keeps access logs (IP address, time, requested address with secrets removed, browser user agent) for 14 days. Links for large files work as passwords, so they are never logged.
How long we keep data
| Data | Kept |
|---|---|
| Account, devices, encrypted keys, vault and encrypted copy | Until you delete your account |
| AI connections | Until you remove them, or delete your account |
| Refresh tokens | 30 days, or until the connection is removed |
| Requests and results | In memory, at most 10 minutes |
| Sign-in and pairing sessions | In memory, a few minutes |
| Large files | Until the operation finishes, at most 1 hour |
| Web server logs | 14 days |
| Server backups | 14 days |
| Waitlist | Until you ask to be removed, or the waitlist ends |
Your choices and rights
- Delete your account and everything we store about it, in the app (Settings → Delete account) or by email: see reins2fa.com/delete-account.
- Disconnect any service or AI tool at any time in the Reins app. Signing out or uninstalling the app deletes the data on that phone.
- Access, correct, export, delete, or object. Depending on where you live (for example in the EU, the UK or California), you have the right to access, correct, delete or receive a copy of your personal information, to restrict or object to its use, and to complain to your data protection authority. Write to privacy@reins2fa.com; we answer within 30 days and will not treat you differently for asking.
We process your information to provide the service you signed up for (performance of a contract) and to keep it secure and prevent abuse (legitimate interests). We do not sell or share personal information for cross-context behavioral advertising, as those terms are defined in California law. Our server is in the United States; if you use Reins from elsewhere, your information is processed there.
Children
Reins is not directed to children. You must be at least 13 years old, or the minimum age at which you can agree to online services in your country if that is higher, to use it. If you believe a child has given us personal information, write to us and we will delete it.
Security
Approvals require your phone's screen lock or biometrics. Credentials on your phone are encrypted with a key protected by the Android Keystore or the iOS Keychain. Our server uses TLS, stores refresh tokens only as hashes, and never receives your connected services' credentials in a form it can read. No system is perfectly secure; the security model explains what our server can and cannot see. Report security problems as described in SECURITY.md.
Changes and contact
We will post changes to this policy on this page and update the date at the top. If a change materially affects how we use your information, we will tell you in the app or by email before it takes effect.
Daniil Katulevskiy, California, USA · privacy@reins2fa.com