Legal

Privacy policy

Last updated: October 8, 2026

This policy explains what information Reins collects, how it is used, and the choices you have. It covers the Reins apps for Android, iOS, macOS, Windows and Linux when they are used with our hosted service at app.reins2fa.com, and this website, reins2fa.com. If you use the apps with a server that someone else runs from Reins's open-source code, that server's operator is responsible for the data on it; what the apps themselves do, including everything in Google user data, is the same.

  1. Who we are
  2. The short version
  3. What our server stores
  4. What passes through without being stored
  5. Google user data
  6. What stays on your phone
  7. This website and the waitlist
  8. Service providers and other parties
  9. Logs
  10. How long we keep data
  11. Your choices and rights
  12. Children
  13. Security
  14. Changes and contact

Who we are

Reins and the hosted Reins service are operated by Daniil Katulevskiy, an individual developer in California, USA ("we", "us"). For anything about privacy, write to privacy@reins2fa.com.

The short version

What our server stores

Your account

You sign in through our sign-in provider, WorkOS, with Google, Apple, GitHub, Microsoft or a code sent to your email. We store your email address, your name if your sign-in provider gives it, the WorkOS account identifier, and your sign-in sessions. We also store the devices you signed in with: device name, type, identifier and when each was last used.

Your encrypted keys and password vault

Your phone creates your account's encryption keys and encrypts them before they reach us, together with a hash used to check them. Items you keep in the Reins password vault are encrypted on your devices; we store them but cannot read them.

An encrypted copy of your phone's Reins data

So that another phone of yours can take over, your phone uploads an encrypted copy of its Reins data: your connected accounts and their sign-in tokens, standing permissions, settings and activity history. It is encrypted on your phone with your account's key, which never leaves your devices in a form we can use. We store the ciphertext and cannot read it.

Your approval phone

Which phone approves your requests, and its push token from Google Firebase Cloud Messaging (Android) or Apple Push Notification service (iOS), so that we can wake it when a request arrives.

Your AI connections

For each AI tool or computer you connect: the client's name and host (for example "Claude", claude.ai), the name you gave the connection, when it was created and last used, a hash of its refresh token, and the registration details the client sent (client name, redirect addresses).

What passes through without being stored

Google user data

If you connect a Google account in the Reins app, the app asks Google for the following access. Each is used only for the purpose listed.

AccessWhat Reins does with it
Gmail: read your email
gmail.readonly
Search for, read, and download attachments of the messages an AI tool you connected asks for, once you approve that request.
Gmail: send email on your behalf
gmail.send
Send an email an AI tool wrote, once you approve its recipients and content.
Google Calendar: see your calendars and events
calendar.readonly
List your calendars and the events an AI tool asks about, once you approve.
Google Calendar: see and edit events
calendar.events
Create or update an event an AI tool proposes, once you approve it.
Google Contacts: see your contacts
contacts.readonly
Look up the contacts an AI tool asks for, once you approve.

How Google data is handled

Reins's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

You can disconnect Google at any time in the Reins app (Integrations), which removes Google's tokens from your phone, and you can revoke Reins's access in your Google Account at myaccount.google.com/connections.

What stays on your phone

The credentials for your connected services, your standing permissions, your activity history, and everything about Autopilot (its model, your past decisions and what it learned from them) are stored on your phone, encrypted with a key protected by the Android Keystore or the iOS Keychain. Apart from the encrypted copy described above, none of it is sent to us. The apps contain no analytics, crash-reporting or advertising software. Autopilot's model files are downloaded from this website, which sees that download like any other web request.

The apps ask for phone permissions only when you turn on a feature that needs them: notifications (to show requests), Face ID or fingerprint (to confirm approvals), the camera on iPhone (only to scan a pairing code, nothing is recorded), and, if you connect them, your phone's calendar and contacts. The Android app downloaded from this website can also, if you connect it, read and send text messages; the Google Play version cannot. Calendar, contacts and text messages are read or changed only to carry out requests you approve, in the same way as described for Google data above.

This website and the waitlist

This website sets no cookies, uses no browser storage, and loads nothing from other companies. If you join the waitlist, we store your email address, which form you used, and when. Your IP address is used to limit abuse of the form. We use the list only to tell you about Reins, and you can ask us to remove you at any time.

Service providers and other parties

We may disclose information if the law requires it, and only what it requires.

Logs

Our server software writes operational logs without tokens, request contents or message contents. Failed sign-in attempts are logged with the IP address they came from. Our web server keeps access logs (IP address, time, requested address with secrets removed, browser user agent) for 14 days. Links for large files work as passwords, so they are never logged.

How long we keep data

DataKept
Account, devices, encrypted keys, vault and encrypted copyUntil you delete your account
AI connectionsUntil you remove them, or delete your account
Refresh tokens30 days, or until the connection is removed
Requests and resultsIn memory, at most 10 minutes
Sign-in and pairing sessionsIn memory, a few minutes
Large filesUntil the operation finishes, at most 1 hour
Web server logs14 days
Server backups14 days
WaitlistUntil you ask to be removed, or the waitlist ends

Your choices and rights

We process your information to provide the service you signed up for (performance of a contract) and to keep it secure and prevent abuse (legitimate interests). We do not sell or share personal information for cross-context behavioral advertising, as those terms are defined in California law. Our server is in the United States; if you use Reins from elsewhere, your information is processed there.

Children

Reins is not directed to children. You must be at least 13 years old, or the minimum age at which you can agree to online services in your country if that is higher, to use it. If you believe a child has given us personal information, write to us and we will delete it.

Security

Approvals require your phone's screen lock or biometrics. Credentials on your phone are encrypted with a key protected by the Android Keystore or the iOS Keychain. Our server uses TLS, stores refresh tokens only as hashes, and never receives your connected services' credentials in a form it can read. No system is perfectly secure; the security model explains what our server can and cannot see. Report security problems as described in SECURITY.md.

Changes and contact

We will post changes to this policy on this page and update the date at the top. If a change materially affects how we use your information, we will tell you in the app or by email before it takes effect.

Daniil Katulevskiy, California, USA · privacy@reins2fa.com