Privacy
Privacy Policy
This policy explains how Rein handles information submitted through its community services.
Information we collect
Community registration collects email, field or industry, region, consent records, and an optional name. Contributor applications additionally collect application choices, optional professional links, and profile-publication preference. Resource submissions collect contact details and information about a public URL. When a public form is submitted, we also collect the submitting device’s IP address. We never request a street address in these flows.
How we use information
We use information to communicate about community activity, administer applications, review public resources, operate events through external registration services, enforce safety rules, prevent submission abuse, maintain an audit record, and measure cumulative community growth. We do not treat registration as legal membership or sell these records.
AI-assisted processing
Contributor application and resource-review workflows may use the OpenAI API. For applications, we send participation reasons, contribution interests, related “Other” text, general location, and industry. We do not send email addresses or professional profile links, and the system does not visit those links.
OpenAI states that API data is not used to train its models by default. Request content may be retained in abuse-monitoring logs for up to 30 days, subject to the account’s data controls. We do not record or automatically transcribe Contributor conversations.
Retention and the all-time count
Raw IP addresses collected for form rate limiting are deleted within seven days. Closed applications that do not become Contributors are retained for 12 months, then names, emails, locations, links, application text, and Agent output are deleted. Community Participant information is retained until unsubscribe or a valid deletion request. Public People profiles are removed immediately when publication consent is withdrawn.
The all-time member count never decreases. When personal data is deleted, the system keeps only a non-identifying count event. If a deleted identity later submits again, the system may not be able to recognize the prior record.
Service providers and security
Supabase provides database, authentication, image storage, and retention scheduling; Resend provides transactional email; OpenAI supports administrative review; and external event platforms manage event registration. We restrict administrative access, keep credentials on the server, and keep raw IP addresses in short-lived server-side rate-limiting records protected by database access controls.
Your choices
You may unsubscribe from community communication, request deletion or correction, or withdraw public-profile consent. Legal or safety obligations may require limited retention, while the non-identifying cumulative count remains.
