/reright

Privacy policy

Draft, not yet in force. Text in square brackets is filled in before publication.

Last updated: 30 September 2026.

reright is a service of interpt, Av. Nuno Alvares Pereira 52, 2300-532 Tomar, Portugal, VAT number PT253648920. You can reach us at support+reright@interpt.co. In these documents "interpt", "we" and "us" mean that business.

interpt is the controller of the personal data described below.

What we collect

The marketing site at reright.it sets no cookies, runs no analytics and loads no third-party scripts. The app sets a session cookie that is needed to keep you logged in. Your theme choice is kept in your browser storage and is not sent to us.

Why we use it and on what basis

Where your text is kept

Traffic between you and the service uses TLS. Draft text, context, diffs, targets, origins, final text and reject reasons are stored encrypted with AES-256-GCM. Each user has a separate data key. Those keys are stored wrapped by a master key that lives on the server outside the database, so the text fields in a copy of the database or of a backup cannot be read on their own. Other data is not encrypted in the database: your email address, your plan, the kind and status of each draft, timestamps, notification settings including any ntfy address and push endpoints, and billing status.

This is not end-to-end encryption. The server decrypts your text to show it to you and to check approvals, and interpt operates the server, so someone with full access to it could read your text. We limit that access to what running the service requires.

Approval checks use a keyed hash of the text, not the text itself.

Retention

We delete message text from the live database when its retention period ends, counted from the decision. On the Free plan the period is 1 day and it cannot be changed. On Starter, Pro and Unlimited you set it on the dashboard to any whole number of days from 1 to 90, and the default is 30. A draft that nobody decides expires after the same period, counted from when it was submitted, and its text is deleted then. Counts and billing records stay. The deletion job runs every hour and once each time the server starts.

If you move to the Free plan, the 1 day period applies from the next hourly purge after the move, so text older than one day is deleted then. The dashboard shows how many drafts that affects and asks you to confirm before you continue. Deleted text cannot be recovered.

Text is deleted from the live database at the retention you choose, and from every backup within 48 hours after that. Backups hold the database as it is, with the text fields encrypted as described above. There are two kinds. The database is streamed to Amazon S3 in Ireland, which keeps 24 hours of history and removes anything older than 2 days. A nightly copy on the server keeps only the newest copy and replaces it each night. Point-in-time recovery therefore only goes back about a day. A database restored from a backup is purged again when the server starts, before it answers any request.

When you delete your account, your data is removed from the live database right away and from backups within 48 hours. Any paid plan is cancelled first. We keep a list of one-way hashes of the email addresses of deleted accounts, so that restoring a backup does not bring a deleted account back. The list holds nothing else.

Who receives data

We use the providers on the subprocessor list. We do not sell personal data and we do not use your text to train models.

If you turn on push notifications, the notification goes through your browser vendor's push service. By default it holds the kind of draft and its target. If you turn on previews, it also holds the first line of the text. If you use ntfy, the message holds the kind, target and review link, never the text, even when previews are on.

If none of your devices has push turned on, we email you when a draft has waited longer than the delay you set, which is 15 minutes unless you change it. The email names the kind and target of the waiting drafts and never the text. You can set the delay to 0 to turn it off.

Transfers outside the EEA

Some providers, including Cloudflare and Stripe, may process data in the United States or other countries. Where they do, we rely on the European Commission's standard contractual clauses or an adequacy decision.

Your rights

Under the GDPR you can ask for access to your data, correction, deletion, restriction, a portable copy, and you can object to processing based on legitimate interest. You can delete your account and all its data yourself from the dashboard. For anything else write to support+reright@interpt.co. You can also complain to your national data protection authority.

Security incidents

If a breach affects your personal data in a way that creates risk for you, we will tell you and the authorities as the law requires.

Children

The service is for developers and is not aimed at children.

Changes

If we change this policy in a way that matters, we will email account holders before it applies.