Effective date: April 12, 2026

← Back to home

Privacy Policy

1. Introduction

This Privacy Policy ("Policy") describes how Alexander Carlson, operating as Rémis ("Rémis," "we," "us," or "our"), collects, uses, stores, protects, and discloses information obtained from users ("you," "your," or "User") of the Rémis platform, accessible at remis.business (the "Service"). Rémis is a sole proprietorship operated by Alexander Carlson, with a general locality in Indianapolis, Indiana, United States.

We are committed to protecting your privacy and handling your personal information with transparency and care. This Policy applies to all information collected through the Service, including our website, application interfaces, APIs, email communications, and any other channels through which you interact with Rémis.

By accessing or using the Service, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree with the practices described in this Policy, you should not access or use the Service. We encourage you to review this Policy periodically to stay informed about how we are protecting your information.

This Policy is incorporated into and subject to our Terms of Service. Capitalized terms not defined herein shall have the meanings ascribed to them in the Terms of Service.

2. Information We Collect

We collect various types of information in connection with the Service, including information you provide directly, information generated through your use of the Service, and information collected automatically. The categories of information we collect are described below.

2.1 Account Information

When you create an account on Rémis, we collect the following personal information:

  • Email address, which serves as your primary account identifier and is used for authentication, communication, and account recovery purposes.
  • Password, which is cryptographically hashed using industry-standard algorithms before storage. We never store your password in plaintext. Authentication is managed through Supabase, our authentication infrastructure provider.
  • Display name, if you choose to provide one. This is optional and used solely for personalization of your experience within the platform.

You are responsible for maintaining the accuracy of your account information and for keeping your login credentials secure. We strongly recommend using a unique, complex password for your Rémis account.

2.2 Company Profile Data

To generate AI-powered business reports and analyses, we collect company and organizational information that you voluntarily submit through our forms and interfaces. This may include, but is not limited to:

  • Company name and legal entity information.
  • Industry classification and sector information.
  • Employee headcount and organizational size metrics.
  • Annual revenue or revenue range.
  • Geographic location, including headquarters and operational regions.
  • Current technology stack, software systems, and infrastructure details.
  • Business pain points, operational challenges, and areas of concern.
  • Strategic goals, growth objectives, and transformation priorities.
  • Any additional business context you provide through free-text fields, questionnaires, or interactive assessment tools within the platform.

This company profile data is essential for the Service to generate meaningful, tailored reports and analyses. You should only submit information that you are authorized to share and that does not include sensitive personal data of third parties unless you have obtained appropriate consent.

2.3 Generated Content

Through your use of the Service, AI-generated content is created and stored in association with your account. This generated content includes, but is not limited to:

  • Business case reports, readiness assessments, and strategic analyses.
  • Vendor comparison reports and technology evaluation summaries.
  • ROI projections, cost-benefit analyses, and financial modeling outputs.
  • Compliance overviews and regulatory readiness assessments.
  • Implementation roadmaps, timelines, and action plans.
  • Any other reports, documents, or analytical outputs produced by the Service at your request.

Generated content is stored in your account and is accessible only to you unless you choose to share or export it. We retain generated content as described in Section 6 (Data Retention) of this Policy.

2.4 Usage Data

We automatically collect information about how you interact with the Service to improve functionality, enforce subscription limits, and enhance the user experience. Usage data includes:

  • Pages and features accessed within the platform.
  • Features used and the frequency of use.
  • Number of report generation runs consumed against your subscription allocation.
  • Timestamps of account activity, including login times, session durations, and feature interaction times.
  • Navigation paths and interaction sequences within the application.
  • Error logs and performance metrics related to your use of the Service.

2.5 Technical Data

When you access the Service, we automatically collect certain technical information from your device and browser, including:

  • Internet Protocol (IP) address, which may be used for security monitoring, fraud prevention, and approximate geographic location determination.
  • Browser type and version (e.g., Chrome, Firefox, Safari).
  • Device type and model (e.g., desktop, tablet, mobile).
  • Operating system and version.
  • Screen resolution and display characteristics.
  • Referring URL and the page from which you navigated to the Service.
  • Language preferences and time zone settings.

This technical data is collected through standard web server logging mechanisms and is used to ensure the security, compatibility, and optimal performance of the Service.

2.6 Payment Data

All payment processing for the Service is handled exclusively by Stripe, Inc. ("Stripe"), our third-party payment processor. When you subscribe to a paid plan or make a purchase through the Service:

  • Your credit card numbers, debit card numbers, bank account details, and other sensitive financial information are collected, processed, and stored directly by Stripe. Rémis does not receive, process, transmit, or store your full payment card or bank account information at any time.
  • Rémis receives and stores only limited transaction information from Stripe, including: transaction confirmation identifiers, subscription plan status (active, canceled, past due), billing cycle dates, and payment success or failure status.
  • Stripe's collection and use of your payment information is governed by Stripe's own Privacy Policy, available at https://stripe.com/privacy.

We encourage you to review Stripe's Privacy Policy to understand how your payment information is handled. Stripe is PCI DSS Level 1 certified, the highest level of certification available in the payment card industry.

3. How We Use Your Information

We use the information we collect for the following purposes, each of which constitutes a legitimate basis for processing under applicable privacy laws:

  • Service Operation: To operate, maintain, and provide the core features and functionality of the Service, including user authentication, account management, and platform accessibility.
  • Report Generation: To process your company profile data through AI providers in order to generate the business reports, analyses, assessments, and other outputs you request through the Service.
  • Billing and Subscription Management: To manage your subscription, process payments through Stripe, enforce usage limits associated with your plan tier, and maintain accurate billing records.
  • Platform Improvement: To analyze usage patterns, diagnose technical issues, and improve the performance, reliability, features, and user experience of the Service.
  • Communication: To send you transactional communications (such as account verification emails, password reset confirmations, payment receipts, and subscription status updates), as well as service-related announcements, policy updates, and security alerts.
  • Terms of Service Enforcement: To enforce our Terms of Service, detect and prevent fraud, abuse, or unauthorized access, and protect the rights, property, and safety of Rémis, our users, and the public.
  • Legal Compliance: To comply with applicable laws, regulations, legal processes, or enforceable governmental requests.

We do not sell, rent, lease, or trade your personal information to any third party for monetary or other valuable consideration. We do not use your company profile data, business information, or generated reports to train, fine-tune, or otherwise improve AI models. Your data is used solely and exclusively for the purpose of generating the outputs you request through the Service.

We may use anonymized, aggregated, and de-identified data that cannot reasonably be used to identify you for research, analytics, benchmarking, and service improvement purposes. Such anonymized data is not considered personal information under this Policy.

4. AI Processing Disclosure

Rémis uses artificial intelligence (AI) technology to generate reports, analyses, and assessments based on the company profile data you provide. It is important that you understand how your data is processed in this context.

4.1 Data Transmission to AI Providers

When you request a report or analysis, the relevant company profile data you have submitted is transmitted to third-party AI service providers via secure API connections. This data is sent for the sole purpose of generating the specific output you have requested. Currently, Rémis utilizes Anthropic's Claude API as its primary AI provider.

4.2 AI Provider Data Policies

We use AI providers under enterprise and commercial API agreements that include data protection provisions. Under these agreements and the providers' published policies, data submitted through API calls is not used by the AI providers to train, retrain, or improve their foundation models. The AI providers process the data solely to generate the requested output and may retain inputs and outputs only for limited periods as required for abuse monitoring, safety compliance, and legal obligations, in accordance with their respective enterprise data handling policies.

4.3 Web Research

Certain features of the Service may involve automated web research to gather publicly available information relevant to your report (such as industry benchmarks, vendor pricing, regulatory updates, and market data). During this process, only general research queries based on public topics are submitted to search providers. Your personal information, account details, and proprietary company data are not shared with, transmitted to, or made accessible to any websites, search engines, or data sources that are researched as part of this process.

4.4 Limitations of AI-Generated Content

AI-generated outputs may contain inaccuracies, outdated information, or errors. All reports and analyses are provided for informational purposes only and do not constitute professional, legal, financial, or compliance advice. You should independently verify all AI-generated content before relying on it for business decisions.

5. Data Storage & Security

We take the security of your information seriously and implement industry-standard technical and organizational measures to protect your data against unauthorized access, alteration, disclosure, or destruction.

5.1 Infrastructure and Hosting

The Service is hosted on industry-standard cloud infrastructure provided by reputable hosting providers. Our infrastructure is designed with security, availability, and scalability in mind. Data is stored in secure data centers located in the United States that maintain physical security controls, environmental safeguards, and access restrictions.

5.2 Authentication and Access Controls

User authentication is managed through Supabase, which implements industry-standard security practices including:

  • Cryptographic hashing of passwords using bcrypt or equivalent algorithms, ensuring that plaintext passwords are never stored.
  • Row-level security (RLS) policies enforcing per-user data isolation, meaning each user can only access their own data.
  • Secure session management with token-based authentication and automatic session expiration.
  • Encryption of data at rest within the database.

5.3 Data in Transit

All data transmitted between your browser and the Service, as well as between the Service and third-party providers, is encrypted using HTTPS with TLS (Transport Layer Security) protocols. We enforce HTTPS across all endpoints and do not permit unencrypted connections.

5.4 Access Restrictions

Access to user data is strictly limited to authorized personnel on a need-to-know basis. Administrative access to infrastructure and databases is protected by strong authentication mechanisms. We regularly review access permissions to ensure that only necessary personnel retain access to sensitive systems.

5.5 Security Limitations

While we implement reasonable security measures, no method of electronic transmission or storage is completely secure. We cannot guarantee absolute security of your information. You acknowledge that you provide your information at your own risk and that you are responsible for maintaining the security of your account credentials.

6. Data Retention

We retain your information for as long as necessary to fulfill the purposes described in this Policy, unless a longer retention period is required or permitted by law.

6.1 Active Accounts

While your account remains active, we retain all account information, company profile data, generated reports, usage data, and associated records necessary to provide the Service and maintain your account in good standing.

6.2 Account Deletion

Upon your request to delete your account, or upon account termination, we will process the deletion as follows:

  • Personal data (email address, name, account credentials): Permanently deleted within thirty (30) days of the deletion request.
  • Company profile data: Permanently deleted within thirty (30) days of the deletion request.
  • Generated reports and analyses: Permanently deleted within thirty (30) days of the deletion request. You are encouraged to export any reports you wish to retain before requesting account deletion.
  • Usage and technical data: De-identified and aggregated within thirty (30) days of the deletion request. Individual-level records are permanently deleted.
  • Payment records: Transaction records held by Stripe are retained by Stripe in accordance with Stripe's own data retention policies and applicable financial regulations. Rémis's internal records of transaction confirmations and subscription status are deleted within thirty (30) days.

6.3 Anonymized and Aggregated Data

We may retain anonymized, aggregated, and de-identified data indefinitely for research, analytics, and service improvement purposes. This data cannot reasonably be used to identify any individual user and is not subject to deletion requests.

6.4 Legal Obligations

Notwithstanding the above, we may retain certain information for longer periods if required by applicable law, regulation, or legal process, or if necessary to establish, exercise, or defend legal claims.

7. Cookies & Tracking Technologies

Cookies are small text files placed on your device by your web browser when you visit a website. We use cookies and similar technologies as described below.

7.1 Essential Cookies

We use strictly necessary cookies that are essential for the operation of the Service. These include session management cookies that maintain your authenticated state as you navigate the platform, as well as security cookies that help protect against cross-site request forgery (CSRF) and other common web vulnerabilities. These cookies are required for the Service to function and cannot be disabled without impairing core functionality.

7.2 Analytics Cookies

As of the effective date of this Policy, Rémis does not use analytics cookies or third-party analytics tracking services. If we introduce analytics cookies in the future, we will update this Policy and provide appropriate notice before deploying such cookies. Any future analytics cookies will be accompanied by a cookie consent mechanism that allows you to opt in or opt out.

7.3 Advertising Cookies

Rémis does not use advertising cookies, retargeting pixels, or any form of ad-related tracking technology. We do not participate in ad networks or serve targeted advertisements.

7.4 Do Not Track Signals

Some browsers transmit "Do Not Track" (DNT) signals to websites. Because there is no universally accepted standard for how to respond to DNT signals, we do not currently respond to DNT signals. However, as stated above, we do not engage in cross-site tracking or advertising-related tracking.

8. Third-Party Services

The Service integrates with and relies upon certain third-party service providers to deliver its functionality. Each of these providers operates under its own privacy policy and terms of service. We encourage you to review the privacy practices of each provider.

  • Supabase — Provides authentication, database hosting, and backend infrastructure. Supabase receives and stores your account credentials (hashed), account data, company profile data, and generated reports. Privacy Policy: https://supabase.com/privacy.
  • Stripe, Inc. — Processes all payment transactions. Stripe receives your payment card or bank account information directly. Rémis does not receive or store this information. Privacy Policy: https://stripe.com/privacy.
  • Anthropic (Claude API) — Provides AI processing capabilities for report and analysis generation. Anthropic receives company profile data transmitted via API calls for the purpose of generating requested outputs. Privacy Policy: https://www.anthropic.com/privacy.
  • Hosting Providers — The Service is deployed on cloud hosting infrastructure. These providers host the application code, serve web assets, and process incoming requests. They may have access to technical data such as IP addresses and request metadata in the course of providing hosting services.

We select third-party providers that maintain reasonable security practices and data protection measures. However, we are not responsible for the privacy practices or security of these third-party services. Your interactions with these providers are governed by their respective privacy policies.

9. Your Rights

Depending on your jurisdiction, you may have certain rights regarding your personal information. Rémis is committed to honoring these rights to the extent required by applicable law. You may exercise any of the following rights by contacting us at our LinkedIn page.

9.1 Right of Access

You have the right to request a copy of the personal information we hold about you. Upon verification of your identity, we will provide you with a summary of the categories of personal information collected, the purposes for which it is used, and the third parties with whom it has been shared.

9.2 Right to Correction

You have the right to request correction of any inaccurate or incomplete personal information we hold about you. You may update certain account information directly through the Service, or you may contact us to request corrections to information that cannot be modified through the platform.

9.3 Right to Deletion

You have the right to request deletion of your personal information, subject to certain exceptions. Upon receiving a verified deletion request, we will delete your personal information in accordance with the retention schedule described in Section 6 of this Policy. Please note that we may retain certain information as required by law or for legitimate business purposes, such as fraud prevention or dispute resolution.

9.4 Right to Export

You have the right to export your generated reports and analyses from the Service. The platform provides built-in export functionality that allows you to download your reports in standard formats. If you require assistance with data export, you may contact us at our LinkedIn page.

9.5 Right to Withdraw Consent

Where we process your personal information based on your consent, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing that occurred prior to the withdrawal. Please note that withdrawing consent may result in your inability to use certain features of the Service that require the processing of your information.

9.6 Exercising Your Rights

To exercise any of the rights described above, please send a written request to our LinkedIn page. In your request, please clearly describe the right you wish to exercise and provide sufficient information for us to verify your identity. We will respond to verified requests within thirty (30) days, or such shorter period as may be required by applicable law. We will not discriminate against you for exercising your privacy rights.

10. California Privacy Rights (CCPA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (collectively, "CCPA"). This section supplements the information provided in the rest of this Policy.

10.1 Categories of Personal Information

In the preceding twelve (12) months, we have collected the following categories of personal information as defined by the CCPA: identifiers (email address, name, IP address); commercial information (subscription and transaction records); internet or other electronic network activity information (usage data, browsing history within the Service); and professional or employment-related information (company profile data submitted by you).

10.2 Sale and Sharing of Personal Information

Rémis does not sell your personal information as defined by the CCPA. We do not share your personal information for cross-context behavioral advertising purposes. We have not sold or shared personal information in the preceding twelve (12) months.

10.3 Your CCPA Rights

As a California resident, you have the right to:

  • Know what personal information we collect, use, disclose, and sell about you.
  • Request deletion of your personal information, subject to certain exceptions.
  • Correct inaccurate personal information.
  • Opt out of the sale or sharing of personal information (though Rémis does not sell or share your information as defined by the CCPA).
  • Not be discriminated against for exercising your CCPA rights.
  • Limit the use and disclosure of sensitive personal information, if applicable.

To exercise your CCPA rights, please contact us at our LinkedIn page. You may also designate an authorized agent to make a request on your behalf, provided that the agent can demonstrate proper authorization.

11. International Users

Rémis is operated from the United States of America. If you are accessing the Service from outside the United States, please be aware that your information will be transferred to, stored in, and processed in the United States, where data protection laws may differ from those in your jurisdiction.

By using the Service, you consent to the transfer, storage, and processing of your information in the United States. If you do not consent to such transfer, you should not use the Service. We will take reasonable steps to ensure that your information is treated securely and in accordance with this Privacy Policy regardless of where it is processed.

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, please note that Rémis does not currently maintain Standard Contractual Clauses (SCCs) or other approved transfer mechanisms for cross-border data transfers. By using the Service, you acknowledge and accept the risks associated with the transfer of your data to the United States.

12. Children's Privacy

The Service is not intended for, directed at, or designed to be used by individuals under the age of eighteen (18). Rémis is a business-oriented SaaS platform, and we expect all users to be adults capable of entering into binding legal agreements.

We do not knowingly collect, solicit, or receive personal information from individuals under the age of eighteen (18). If we become aware that we have collected personal information from a minor, we will take prompt steps to delete such information from our records. If you are a parent or guardian and believe that your child under the age of eighteen (18) has provided personal information to Rémis, please contact us immediately at our LinkedIn page so that we can take appropriate action.

13. Changes to This Policy

We reserve the right to modify, amend, or update this Privacy Policy at any time at our sole discretion. When we make changes to this Policy, we will update the "Effective date" at the top of this page and take reasonable steps to notify you of material changes.

Notification of material changes may be provided through one or more of the following methods: a prominent notice within the Service, an email to the address associated with your account, or a notification upon your next login to the platform. We encourage you to review this Policy periodically to stay informed about our privacy practices.

Your continued use of the Service after any changes to this Policy become effective constitutes your acceptance of the revised Policy. If you do not agree with the terms of the updated Policy, you must discontinue your use of the Service and may request deletion of your account and personal information in accordance with Section 9 of this Policy.

14. Data Breach Notification

In the event of a security breach that results in the unauthorized access, acquisition, disclosure, or use of your personal information, Rémis is committed to responding promptly and transparently.

We will notify affected users of a qualifying data breach within seventy-two (72) hours of becoming aware of the breach, or as soon as reasonably practicable thereafter, via email to the address associated with the affected account. The notification will include, to the extent known at the time:

  • A description of the nature of the breach, including the categories of personal information affected.
  • The approximate date and time of the breach, or the period during which the breach is believed to have occurred.
  • A description of the measures we have taken or propose to take to address the breach and mitigate its potential adverse effects.
  • Recommendations for steps you can take to protect yourself, such as changing your password or monitoring your accounts.
  • Contact information for our support team to answer questions or provide additional information.

We will also notify applicable regulatory authorities as required by law. We maintain internal procedures for detecting, investigating, and responding to security incidents, and we will take all reasonable steps to contain and remediate any breach as quickly as possible.

15. Contact Information

If you have any questions, concerns, or requests regarding this Privacy Policy, our data practices, or the exercise of your privacy rights, please contact us at:

  • Email: our LinkedIn page
  • Operator: Alexander Carlson, operating as Rémis
  • Locality: Indianapolis, Indiana, United States

We will make reasonable efforts to respond to all legitimate inquiries within thirty (30) days. If you are not satisfied with our response, you may have the right to lodge a complaint with your local data protection authority, where applicable.

This Privacy Policy is governed by and construed in accordance with the laws of the State of Indiana, United States, without regard to its conflict of law provisions.