Skip to main content
Remli
Remli

Privacy Policy

Version 0.1.2 · Effective 2026-08-25

Remli ("Remli," "we," or "us") is operated by Bohdan Tkach, doing business as Remli LLC (formation pending). Remli is a hosted service — your documents live on our server, not only on your device. This policy explains what we collect, why, who else sees it, and what control you have. We store real personal paperwork — IDs, medical records, insurance, financial documents — so we've written this to describe what actually happens in the app, including its limits, rather than generic boilerplate. Questions: email [email protected].

Who this applies to

Remli is for adults 18 and older. We don't knowingly allow anyone under 18 to create an account, and if we learn an account belongs to someone under 18 we'll close it.

What we collect

  • Account information. Email address, a hashed password (never stored or logged in plain text), and, if you enable SMS two-factor authentication or verify your phone at sign-up, your phone number.
  • The documents you upload and what Remli derives from them: rendered page images and thumbnails, OCR'd text, the title/date/tags/summary/category (AI-suggested or entered by you), any people or organizations you associate with a document, and the original filename.
  • Redaction records (Sensitive mode only): a log of what type of sensitive value was detected and masked (for example, a masked tail like •••6789) — never the underlying value itself.
  • Assistant chat history. Messages you send to Remli's chat widget and its replies are stored in full so you can reopen a conversation. If you ask the assistant to view pages of a document (which requires your explicit approval each time), those page images are sent to OpenAI as part of that conversation, the same as an upload analysis would.
  • Activity needed to run the service: an audit log of events (for example, "imported file X," "sent 3 page image(s) to OpenAI"), sign-in attempts and lockouts, saved searches, and per-call OpenAI token counts (used to estimate your cost on the Usage page). The audit log records that an event happened, not document content or extracted values.
  • Records of your agreement to this policy and to the Terms of Service — which version you accepted, when, and through which flow — kept so both of us can establish what was agreed.
  • Technical data ordinary web servers collect, like request logs. Remli does not run analytics, tracking pixels, or ad scripts of any kind. The only cookie Remli sets is your session cookie, used solely to keep you signed in.

Who we share it with

We do not sell your information, and we do not share it for advertising. The only outside parties are the ones a feature you actively use requires:

  • OpenAI. Every document you upload is sent to OpenAI's API for analysis — up to 8 rendered page images (configurable), the locally extracted text, the original filename, and page count. There is no privacy mode that keeps a document from being sent to OpenAI. In Sensitive mode, Remli first runs automated pattern detection (for SSNs, card numbers, routing numbers, and similar) and blacks out or replaces what it finds before that request goes out. This detection is best-effort, not a guarantee — unusual formats, OCR errors, and handwriting can cause a sensitive value to slip through undetected, even in Sensitive mode. OpenAI processes this data under its own API terms; as of this writing OpenAI does not use API data to train its models by default, but that is OpenAI's policy, not a guarantee we can make on their behalf.
  • Twilio. If you enable SMS two-factor authentication or verify your phone during sign-up, Remli sends your phone number and a one-time code to Twilio to deliver the text. Twilio never receives document content, your password, or any other account data.

We may also disclose information if required by law (for example, a valid court order), or to protect the security of the service or its users. When we receive a legal demand for user information, we will do our best to protect our users' constitutional privacy rights — including scrutinizing the demand's validity and scope and, where the law allows, notifying the affected user before disclosing anything — but we ultimately have to comply with valid legal obligations.

How it's stored and protected

Document files (originals, previews, thumbnails) are encrypted at rest with AES-256-GCM. All traffic to Remli is encrypted in transit (HTTPS/TLS). Passwords are hashed with scrypt, never stored or displayed in plain text. Every account is isolated from every other account at the application level — one user cannot see another user's documents, searches, or settings.

One honest limit: derived metadata — titles, tags, and the extracted text that powers full-text search — is not individually encrypted; it is protected by the server's own security controls rather than file-level encryption. And no online service can guarantee absolute security, so we won't pretend otherwise: we limit what we collect, restrict who can reach it, and recommend you keep your original documents or an independent copy of anything you cannot afford to lose (our Terms of Service says the same thing plainly).

Your choices and rights

  • Access and export. You can export your documents and their metadata (JSON/CSV) at any time from Settings.
  • Deleting a document is immediate and permanent: the file, its previews, and its derived data are removed right away. A copy may still exist in a backup snapshot taken before the deletion, until that backup is later rotated or overwritten.
  • Deleting your account works differently: it starts a 30-day grace period. Your account is immediately signed out everywhere and unusable, but nothing is destroyed yet — signing back in within 30 days and confirming restores everything exactly as it was. After 30 days, an automatic purge permanently deletes your documents, files, audit log, chat history, agreement records, and account record. We do this so an accidental or coerced deletion request (or a compromised session) doesn't destroy irreplaceable documents before you have a chance to notice and undo it.
  • Privacy mode. Every document is sent to OpenAI for analysis, but you choose, per document, whether Remli first runs automated sensitive-value detection and redaction — see the limits of that detection above.
  • California residents have the right to request access to, or deletion of, personal information we hold about you, and the right not to be discriminated against for exercising that right. We don't sell personal information, so there's nothing to opt out of on that front. Contact us at the email below to exercise any of these rights.

How long we keep data

We keep your documents and account data for as long as your account is active. Deleted documents are removed immediately as described above. A deleted account enters the 30-day grace period described above, then is permanently purged, including its audit log and chat history.

Changes to this policy

This policy is versioned. If we make a material change to how Remli handles your information, we'll publish a new version here with a summary of what changed and ask you to accept it the next time you use Remli. We keep a record of every published version and of which version you accepted.

Contact

Questions, requests, or concerns about your data: email [email protected] or call 253-777-3821.