reflctPrivacy policy

How Reflct handles your data

Reflct keeps what it makes for you, not a permanent copy of your message history.

Last updated: August 21, 2026
00 / 10The short version
The everyday sync

Reflct Sync analyzes your history locally on your Mac. Reflct saves the insights it creates for you and the specific excerpts it shows you, not a permanent copy of your conversations.

How access works

You point the app at your Messages folder using the standard macOS picker. macOS holds that grant, not us, and you can take it back at any time. Reflct does not use or require Full Disk Access. It only ever reads. Nothing in Messages is changed, moved, or deleted.

What a read is

A read is the paid thing you ask for by name. Reflct borrows the messages that read needs from your Mac, builds the read, then deletes what it borrowed. A borrowed window cannot be stored without a deletion deadline, at most 24 hours out, and it is normally cleared within minutes of the read finishing. Every borrow is a line on your privacy page with the time it was deleted. Lines a read quotes stay inside that read until you delete it. What a read touches depends on which read you buy, and each one says so before you pay.

What Pro changes

Pro is the one standing permission. The Mac app syncs recent message content so your daily pages have something to read while your Mac is asleep. It is not filed away in a permanent archive: by default what the server keeps is a rolling three-day window, and each day drops out once it ages past that.

What Reflct keeps

What it made for you: counts, timing, insights, the specific excerpts it shows, and the Reads you bought. They stay in your account until you delete the item that owns them.

What Reflct never does

We do not sell your data, and there are no ads. We do not use your messages, content or metadata, to train AI models, and the AI providers we send work to do not train on them either.

Seeing it, and ending it

Your privacy page shows processing text Reflct is holding and why it is there. Stored threads, the Pro rolling window, and temporary Read borrows are shown with their permissions and deletion state. Insights and excerpts stay with the page or Read that owns them. In Reflct Sync you can exclude a person; in Reflct you can delete created items or your account.

The receipts live on your privacy page, and the switches live in your account settings.

The full policy

Reflct, operated by Reflct Inc ("we," "our," or "us"), is a personal cognitive tool that helps you capture, organize, and reflect on your thoughts. This policy explains what data we collect, how we use it, and the choices you have.

We built Reflct for ourselves first. We treat your data the way we'd want ours treated: with care, minimalism, and respect.

We do not use your messages (content or metadata) to train AI models, and the AI providers we rely on do not train on the data we send through their APIs. Anthropic, which powers Reflct's reading, does not train on API inputs and normally deletes API inputs and outputs within 30 days. Limited safety, legal, and contractual exceptions may apply.

01 / 10How Reflct reads your messages

On Free, Reflct Sync analyzes your history locally on your Mac. It sends the specific outputs Reflct uses: counts, timing, dates, contact names, relationship insights, and the specific excerpts selected for a Reflct surface. It does not upload or retain a permanent copy of your conversation history. Reflct keeps what it makes for you, not a permanent copy of your message history.

  • What the free sync sends: the outputs a Reflct feature needs, such as counts, timing, dates, contact identifiers, derived relationship insights, and a specific excerpt when Reflct shows that excerpt back to you.
  • What the sync will not carry: an unrestricted copy of a conversation or a permanent message archive. The payloads are purpose-built and size-limited to the insight or excerpt a feature needs. Privacy filters and your excluded-people settings run before those outputs leave the Mac.
  • How you grant access: you point the app at your Messages folder using the standard macOS folder picker. The app is sandboxed, and macOS enforces that boundary. Reflct does not use or require Full Disk Access. Access is read-only: Reflct never writes to, edits, or deletes anything in Messages.
  • What changes on Pro: upgrading grants a standing permission for Reflct Sync to send recent message content for Pro features. By default Reflct keeps that processing text in a rolling three-day window; each day is removed as it ages out. A small allowlist of internal team accounts is excepted. The upgrade screen states this before checkout, and canceling stops new Pro sync.
  • What a read borrows: buying a read is the other way content moves, and it works on any plan. The order you paid for is the authorization. How much it covers depends on the read: a read about one relationship covers that conversation and nothing else, a read about you draws on several of your conversations, and the reads that count your own habits draw on all of them. Each read states its scope before you pay. The messages it needs are borrowed from your Mac for that one job and deleted when it finishes. A borrowed window cannot be stored without a deletion deadline, at most 24 hours out, and a sweep job clears anything that reaches it. Your privacy page lists your recent borrows with the time each was deleted. Short passages a read quotes are saved into the read and the pages built from it, and stay there until you delete them.
  • What is kept afterwards: durable storage of message text is separate from the insights, excerpts, pages, and Reads Reflct makes for you. By default, processing text is limited to a Pro rolling window or a temporary Read borrow, both carrying deletion deadlines. Every day in the rolling window is stamped to delete three days after the day those messages happened, and a sweep runs every half hour to clear the days that are past it. Created items stay until you delete them.
02 / 10What we collect

Account information

When you sign up, we collect your phone number or email address for authentication. We may also store a display name if you provide one.

Voice recordings and transcriptions

Reflct's core experience involves voice capture. When you record, audio is streamed to a third-party transcription service (currently Deepgram) for real-time speech-to-text conversion. The resulting transcriptions are stored in your account.

We do not permanently store raw audio files on our servers. Audio is processed in real-time and discarded after transcription.

Conversations and content

Text you enter, conversations with the Reflct agent, and any content generated from your inputs (summaries, insights, patterns) are stored in your account and associated with your user profile.

Integrated services and browser extension

Reflct can sync data from third-party services you connect, with your explicit permission. Each connection is opt-in and can be revoked at any time from the Sources page in the app.

The Reflct Chrome extension stores your Reflct API key and sync state locally in your browser so it can connect to your account. It uses your existing browser sessions for Claude.ai, ChatGPT, and LinkedIn, but it does not collect or send your passwords or third-party session cookies to Reflct.

  • AI conversations: Claude.ai and ChatGPT conversation titles, timestamps, message text, and related metadata, fetched by the Reflct Chrome extension from accounts you are already signed into.
  • LinkedIn network data: your first-degree LinkedIn connections and selected profile details, such as names, profile URLs, headlines, current roles, companies, work history, education, skills, connection dates, and profile email addresses when LinkedIn provides them. We do not collect LinkedIn passwords, session cookies, private messages, browsing history, or precise location.
  • Email (Google): email thread metadata and content, accessed via Google OAuth with read-only scope. We do not send email on your behalf.
  • Calendar (Google): calendar events, accessed via Google OAuth with read-only scope.
  • Local sources (Mac): the sandboxed Reflct Sync desktop app runs on your Mac with your permission. On Free it analyzes locally and sends only the purpose-built outputs a feature needs: counts, timing, identifiers, derived insights, and specific excerpts Reflct shows you. It does not upload a permanent copy of your conversation history. Pro can additionally sync recent message content under its rolling-window permission. The app can also sync Claude Code sessions from your Mac.
  • Instagram: direct message history, where you have authorized the connection.
  • Code activity (GitHub): commit metadata and repository activity from connected accounts.

Financial data

If you connect a bank or credit card account, Reflct uses Plaid to retrieve your transaction history (read-only). This includes merchant names, amounts, dates, categories, and account identifiers. Reflct does not access or store your online banking credentials. Plaid handles authentication directly with your financial institution and provides Reflct with a secure access token, which we encrypt at rest. Reflct cannot move money, initiate payments, or modify your accounts in any way. You can disconnect your accounts at any time from the Sources page, which immediately revokes Reflct's access.

Device and usage data

We collect limited product analytics to understand whether Reflct works and is useful: app opens, active session duration, page or feature usage, notification permission and open status, app version, platform, and basic device information. Signed-in product events use a pseudonymous account identifier so we can measure retention and diagnose failures. We do not send message text, read content, contact names, email addresses, share links, invite tokens, notification contents, or financial data to analytics providers.

Plausible provides aggregate, cookie-free website traffic reporting. PostHog provides explicitly instrumented product events. Statsig provides feature flags, experiments, and limited page/performance analytics. Automatic click, form-value, copied-text, and DOM-text collection is disabled. Session replay, when enabled, is limited to a reviewed allowlist of static public pages with input and text masking; private, personalized, invite, and share-token routes are excluded.

Bug reports and screenshots

In the iOS app, shaking your phone opens a problem-report form and captures the screen that was visible at that moment. Before sending, you can remove the screenshot and either type or dictate a note. We store the report, basic app and device details, and any attached screenshot with your account so we can investigate and respond.

Screenshots are kept in private file storage and are never posted to Discord. What goes to our private Discord channel to alert the Reflct team is the typed or transcribed note, the account it came from, and limited app, device, and screen context.

03 / 10How we use your data
  • Provide the service: transcribe your voice, generate insights, and power the Reflct agent.
  • Improve the product: we use aggregate reporting and pseudonymous product events to understand reliability, engagement, retention, and whether features are helping. We never use your data to train AI models, and we do not send it to providers that train on it. Where Reflct personalizes, it fits to your own activity and stays in your account.
  • Communicate with you: transactional messages like authentication codes. No marketing spam.
  • Support connected-source sync: keep track of sync status, avoid duplicate imports, and notify you when a connected source needs re-authentication.
04 / 10Third-party services

We rely on a small set of trusted infrastructure providers:

  • Supabase: database, authentication, and file storage. Data is hosted on AWS infrastructure.
  • Deepgram: real-time speech-to-text transcription. Audio is streamed there for conversion, is not retained by Deepgram after transcription, and is not stored by Reflct.
  • Anthropic: powers the Reflct agent and the reads. Conversations with the agent are sent to Anthropic's API for processing. Anthropic does not use API inputs to train models and normally deletes API inputs and outputs within 30 days; limited safety, legal, and contractual exceptions may apply.
  • OpenAI: generates embeddings (mathematical representations used for search and retrieval) of synced content. OpenAI does not use API inputs to train models.
  • OpenRouter: routes some page and read generation to additional model providers on our behalf. Every call we send through it is pinned to endpoints that neither collect nor retain the request.
  • Google (Gemini): in addition to being our OAuth provider, Gemini models process some agent conversations. Google does not use API inputs to train models.
  • ElevenLabs: text-to-speech, when you ask Reflct to read something aloud.
  • Plaid: read-only access to bank and credit card transaction history when you connect a financial account. Plaid acts as the secure bridge between Reflct and your financial institution. Plaid's privacy practices are described at plaid.com/legal.
  • Google: OAuth provider for Gmail and Google Calendar integrations, with read-only scopes.
  • Vercel: application hosting and edge delivery.
  • Plausible: privacy-focused, cookie-free web analytics.
  • PostHog: pseudonymous, explicitly instrumented product analytics. Automatic DOM interaction capture is disabled. Replay, if deliberately enabled, uses the public-page restrictions and masking described above.
  • Statsig: feature flags, experiments, limited page/performance analytics, and masked replay on a reviewed set of static public pages. Private app routes and dynamic invite/share routes are excluded from replay.
  • Discord: private team alerts for customer-support bug reports. These alerts contain the report note, the account it came from, and limited app and device context, but never the attached screenshot.

We do not sell your data to anyone. We do not share your personal content with third parties beyond what is necessary to operate the service as described above.

For Chrome Web Store data disclosures, the Reflct extension collects personally identifiable information, personal communications, and website content only to provide the sync features you enable. We do not use extension-collected data for advertising, creditworthiness, resale, or unrelated purposes.

05 / 10Data storage and security

Your data is stored in a PostgreSQL database hosted by Supabase on AWS infrastructure in the United States. All data is encrypted in transit (TLS) and at rest. Access to production data is restricted and requires multi-factor authentication.

Row-Level Security (RLS) policies ensure that you can only access your own data. No other user can read your conversations, transcriptions, financial transactions, or insights.

Sensitive third-party credentials, such as Plaid access tokens and OAuth refresh tokens for connected accounts, are additionally encrypted at the application layer using AES-256-GCM before being stored, with the encryption key held separately from the database.

A copy of our full security policy is available on request. Email support@reflct.ai.

06 / 10Your rights

You have the right to:

  • Access your data: everything in Reflct is visible to you in the app.
  • Export your data: you can download an export from your account settings. It covers your synced AI conversations and a summary of what else is on file. For anything beyond that, email us and we will put it together.
  • Exclude a person: in the Mac app you can exclude someone. Syncing for them stops right away, in group threads as well as one to one. The Mac app also offers to delete what it already sent, checked by default: the message text, the counts and timing, and the pages derived from them, for your one to one thread with that person. Group threads that person is also in are not covered by that deletion today, because those messages belong to the other people in the thread as well. A read you already bought about that person is not deleted by excluding them, because the order is its own record of what you asked for. You can delete it yourself from your privacy page.
  • Delete your data: you can delete your account from your account settings, which removes your messages, your pages, your reads and the embeddings built from them in that session, or you can ask us to do it. We process deletion requests we handle by hand within 30 days.
  • Correct your data: if something is inaccurate, let us know and we'll fix it.
07 / 10Data retention

We retain your data for as long as your account is active. Deleting your account from your settings runs the removal immediately. Anything left to handle by hand, including a deletion you ask us for by email, we complete within 30 days, except where the law requires us to keep it.

Reflct's detailed product-event ledger is normally retained for 180 days and runtime performance details for a shorter operational window. Longer-lived performance rollups contain aggregate counts and timings without user identifiers. Plausible's aggregate reports and provider-side product analytics follow their configured retention periods. Account deletion removes attributable Reflct analytics; if a provider copy needs manual handling, we complete that deletion within 30 days.

08 / 10Children's privacy

Reflct is not intended for use by anyone under the age of 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us and we will delete it.

09 / 10Changes to this policy

We may update this policy from time to time. If we make significant changes, we will notify you through the app or via email. Continued use of Reflct after changes constitutes acceptance of the updated policy.

10 / 10Contact

Questions about this policy or your data? Reach out at support@reflct.ai.