Privacy Policy

Last updated: June 2026

1. Introduction

This Privacy Policy explains how ReqLens ("ReqLens", "we", "us"), a sole proprietorship based in India, collects, uses, and shares information when you use ReqLens (the "Service"). We act as the data controller for account data and, for content you submit, we process it on your behalf to provide the Service.

2. Information We Collect

  • Account information: name, email, and authentication identifiers.
  • Your Content: requirements, documents, and other material you submit to be processed by the Service, and the AI-generated output derived from it.
  • Billing information: processed by our payment provider; we receive subscription status and limited transaction metadata, not your full card details.
  • Usage and device data: product analytics events, log data, and basic device and browser information.
  • Cookies: essential cookies for sign-in and security, and, subject to your consent, analytics cookies.

3. How We Use Information

We use information to provide and operate the Service, generate AI output you request, authenticate you, process payments, provide support, secure the Service, understand product usage, and comply with legal obligations. We do not sell your personal information.

4. AI Processing

To generate output, the relevant portions of Your Content are sent to our AI sub-processor (Google Gemini API) for processing. We send only what is needed to fulfil your request. Your Content is not used to train AI models.

5. Sub-processors

We rely on the following providers to operate ReqLens, each processing data only as needed to provide its function. This list may be updated as our providers change.

  • Clerk: authentication and identity.
  • Supabase: database and storage hosting.
  • Railway: application hosting.
  • Google (Gemini API): AI processing of submitted content.
  • Paddle: payments and merchant-of-record services.

6. Sharing

We share information only with the sub-processors above, where required by law or legal process, or in connection with a business transfer. We do not share Your Content with third parties for their own marketing.

7. Data Retention

We retain account data and Your Content for as long as your account is active. When you delete your account, we deactivate and remove personal data and Your Content within a reasonable period, except where retention is required by law (for example, billing records).

8. Your Rights

Depending on your location (including under the EU/UK GDPR and India's DPDP Act), you may have rights to access, correct, delete, or export your personal data, and to object to or restrict certain processing. You can delete your account directly from account settings, or contact us to exercise other rights. We will respond within the time required by applicable law.

9. International Transfers

Your information may be processed in countries other than your own, including by the sub-processors listed above. Where required, we rely on appropriate safeguards for such transfers.

10. Security

We use reasonable technical and organizational measures, including encryption in transit and at rest, to protect information. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

11. Children

The Service is not intended for individuals under 18, and we do not knowingly collect their personal data.

12. Changes

We may update this Policy from time to time. Material changes will be notified through the Service or by email.

13. Contact

For privacy questions or to exercise your rights: support@reqlens.com