Legal

PRIVACY NOTICE

Privacy notice

This notice explains how Re0 handles personal data across the website, REST API, MCP service, CLI and console. Effective 2026-10-01. For the rights and obligations around using the service, see the terms of service.

1. What we collect

1.1Account information: email, sign-in method and third-party account identifier, display name and join date. We never receive or store the password you hold with a sign-in provider.

1.2Content you submit: the source configuration of a library (repository address, site address, uploaded files) and the content within it. Do not place sensitive personal information, credentials or keys in there.

1.3Call metadata: time, Library ID, endpoint and status code, calls consumed, the identifier of the API key used, and the IP and user agent needed for abuse prevention.

1.4Billing information: plan, billing period, call pack purchases and the transaction reference returned by the external payment provider. We store no card numbers, bank account numbers or payment credentials.

1.5Technical records: server-side error logs and security event records.

2. How we use it

2.1Providing the service: running retrieval, building and refreshing libraries, keeping you signed in and answering the requests you submit.

2.2Metering and reconciliation: billing per API call, settling call packs and publisher revenue share, and letting you trace every deduction in the console.

2.3Security and abuse prevention: spotting anomalous calls, protecting quota and account security, and investigating security incidents.

2.4Necessary communication: notices about your account, billing and changes to these documents. Marketing email is sent only if you opt in, and you can unsubscribe at any time.

2.5Legal bases: performing our contract with you, our legitimate interests in operating and protecting the service, and legal obligations; where consent is required, we rely on the consent you give.

3. What we do not do

3.1We do not use your private library content or your queries to train models.

3.2We do not sell personal information, and we do not trade or hand it to advertising networks.

3.3We do not use cookies or similar technology for cross-site advertising or profiling.

4. Sharing and third parties

4.1Payments, invoices and refunds are handled by an external payment provider; we receive only the transaction outcome and what reconciliation requires.

4.2Hosting, databases, object storage and the vector index run on infrastructure providers we engage, who may process data only on our instructions and not for their own purposes.

4.3Retrieval results from public libraries show callers the source, version and citation; private libraries are visible only within the workspace that owns them.

4.4We disclose what the law requires, and tell you in advance to the extent the law allows.

4.5In a merger, acquisition or transfer of assets this notice continues to apply to the data that moves with it, and we give notice before anything changes.

5. Retention

5.1Account information is kept while the account exists; after closure, private libraries and their indexes are deleted.

5.2Call metadata is retained per billing period for metering, reconciliation and review.

5.3Raw request logs are kept no longer than operations and security require.

5.4Accounting and audit records the law requires us to keep are retained for the statutory period and are not removed on closure.

6. Cookies

6.1We use only the cookies needed to keep you signed in, remember your interface language and gather basic visit statistics.

6.2You can clear or block cookies in your browser, but your sign-in state and some interface preferences will not survive.

7. Your rights

7.1You can access, correct, export or delete your data in the console. Deletion requests are completed within a reasonable period, except for records the law requires us to keep.

7.2You can object to or ask us to restrict processing based on legitimate interests, and withdraw consent you gave earlier; withdrawal does not affect processing carried out before it.

7.3To exercise those rights, or if you disagree with how we handle data, write to legal@re0.com. You also have the right to complain to your local data protection authority.

8. Security and international transfers

8.1Data is transmitted over TLS and encrypted at rest; internal access is granted on a least-privilege basis and recorded.

8.2Our servers and those of our infrastructure providers may sit outside your country or region; cross-border transfers use the safeguards applicable law allows.

8.3If a security incident affects personal data, we notify affected users and regulators within the deadlines applicable law sets.

8.4The service is offered to organisations and developers, not to children under 14, and we do not knowingly collect children’s personal information.

9. Changes and contact

9.1When this notice changes we update the effective date at the top of the page; material changes to how data is handled are announced in the product or by email in advance.

9.2For privacy requests, write to legal@re0.com; for security issues, write to security@re0.com.

For accounts, billing and refunds, see the Terms of service

This is the MVP-stage text and will be updated alongside the product scope before commercial launch. Where the Chinese version and any other language version diverge, the Chinese version governs.