Effective date: July 18, 2026

← Back to home

Privacy Policy

1. Introduction

This Privacy Policy ("Policy") describes how Alexander Carlson, operating as Rémis ("Rémis," "we," "us," or "our"), collects, uses, stores, protects, and discloses information obtained from users ("you," "your," or "User") of the Rémis platform, accessible at remis.business (the "Service"). Rémis is a sole proprietorship operated by Alexander Carlson, with a general locality in Indianapolis, Indiana, United States. The Service is offered solely to customers in the United States.

We are committed to protecting your privacy and handling your personal information with transparency and care. This Policy applies to all information collected through the Service, including our website, application interfaces, APIs, email communications, and any other channels through which you interact with Rémis.

By accessing or using the Service, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree with the practices described in this Policy, you should not access or use the Service. This Policy is incorporated into and subject to our Terms of Service. Capitalized terms not defined herein shall have the meanings ascribed to them in the Terms of Service.

2. Information We Collect

We collect information you provide directly, information generated through your use of the Service, and information collected automatically. The categories are described below.

2.1 Account Information

When you create an account on Rémis, we collect your email address, which serves as your account identifier and is used for authentication and account-related communication. We do not collect or store passwords. The Service uses passwordless authentication: to sign in, our authentication provider (Supabase) sends a one-time secure sign-in link to your email address. Each sign-in therefore generates an authentication email to you. Because your email inbox is the key to your account, we recommend securing it carefully.

2.2 Company Profile Data

To generate AI-powered business reports and analyses, we collect company and organizational information that you voluntarily submit through our forms and interfaces. This may include, but is not limited to:

  • Company name and industry classification.
  • Employee headcount and annual revenue or revenue range.
  • Geographic location.
  • Current technology stack, software systems, and infrastructure details.
  • Business pain points, operational challenges, and areas of concern.
  • Strategic goals, growth objectives, and transformation priorities.
  • Any additional business context you provide through free-text fields, questionnaires, or interactive assessment tools within the platform.

This company profile data is essential for the Service to generate meaningful, tailored reports. You should only submit information that you are authorized to share and that does not include sensitive personal data of third parties unless you have obtained appropriate consent.

2.3 Generated Content

Reports, assessments, and other outputs generated through your use of the Service are stored in association with your account and are accessible only to you unless you choose to share or export them. Generated content persists until you delete it or request account deletion, as described in Section 6.

2.4 Purchase and Usage Data

We maintain records of your one-time credit pack purchases (transaction identifiers, amounts, and dates), your per-tool credit balances, credit consumption and restoration events, and usage information such as features accessed, timestamps of activity, and error logs related to your use of the Service.

2.5 Technical Data

When you access the Service, we automatically collect certain technical information from your device and browser, including your Internet Protocol (IP) address (used for security monitoring, rate limiting, and fraud prevention), browser type and version, device type, operating system, referring URL, and language and time zone settings. This technical data is collected through standard web server logging and security mechanisms.

2.6 Payment Data

All payment processing is handled exclusively by Stripe, Inc. ("Stripe"). Your credit card numbers and other sensitive payment details are collected, processed, and stored directly by Stripe; Rémis does not receive, process, transmit, or store your full payment card information at any time. Rémis receives and stores only limited transaction information from Stripe: transaction confirmation identifiers, purchase amounts, and payment success or failure status. Stripe's handling of your payment information is governed by Stripe's own Privacy Policy at https://stripe.com/privacy.

2.7 Lead Emails (Demo Visitors)

If you enter your email address on our demo page to request a link to get started, we store that email address (with its source page) in a leads table, separate from account data, and send you a single transactional email containing the requested link via our email provider, Resend. We do not use lead emails for marketing, and we will not send recurring or promotional email to lead addresses unless we first implement a compliant opt-in and unsubscribe mechanism and you consent. Lead emails are retained until you request their deletion (Section 6) and are never sold or shared for advertising.

3. How We Use Your Information

We use the information we collect for the following purposes:

  • Service Operation: To operate, maintain, and provide the core features and functionality of the Service, including passwordless authentication, account management, and platform accessibility.
  • Report Generation: To process your company profile data through our AI provider in order to generate the reports, analyses, and assessments you request.
  • Purchases and Credits: To process one-time purchases through Stripe, grant and track credits, restore credits after failed generations, and maintain accurate purchase records.
  • Requested Communications: To send you communications you have requested or that are necessary to the Service — sign-in links, purchase receipts (sent by Stripe), the demo link you request on the demo page, and important service or policy announcements.
  • Platform Improvement: To analyze usage patterns, diagnose technical issues, and improve the performance, reliability, and user experience of the Service.
  • Security and Enforcement: To enforce our Terms of Service, apply rate limits, detect and prevent fraud, abuse, or unauthorized access, and protect the rights, property, and safety of Rémis, our users, and the public.
  • Legal Compliance: To comply with applicable laws, regulations, legal processes, or enforceable governmental requests.

We do not sell, rent, lease, or trade your personal information to any third party. We do not use your company profile data, business information, or generated reports to train, fine-tune, or otherwise improve AI models. We may use anonymized, aggregated, and de-identified data that cannot reasonably be used to identify you for research, analytics, and service improvement; such anonymized data is not considered personal information under this Policy.

4. AI Processing Disclosure

Rémis uses artificial intelligence to generate reports, analyses, and assessments based on the company profile data you provide. It is important that you understand how your data is processed in this context.

4.1 Data Transmission to Our AI Provider

When you request a report or analysis, the relevant company profile data you have submitted is transmitted to Anthropic, PBC ("Anthropic") via secure API connections for the sole purpose of generating the requested output. Anthropic's Claude API is the Service's AI provider.

4.2 AI Provider Data Handling

We use Anthropic under its standard commercial API terms. Under those terms, data submitted through API calls is not used by Anthropic to train its models. Anthropic processes the data to generate the requested output and may retain inputs and outputs for limited periods for abuse monitoring, safety, and legal compliance, in accordance with its published data handling policies.

4.3 Web Research

Several tools use the AI provider's built-in web search capability to gather publicly available information relevant to your report (such as vendor pricing, industry benchmarks, and regulatory updates). Search queries are composed by the AI model during generation and may incorporate business context you provided — for example, your industry, location, the software you use, or your company name — where the model judges it relevant to the research. Searches are executed by the AI provider's search infrastructure; the websites returned as results do not receive your account details, and Rémis does not share your data directly with any search engine. If you do not want particular information used in this way, do not include it in your inputs.

4.4 Limitations of AI-Generated Content

AI-generated outputs may contain inaccuracies, outdated information, or errors, and vary from run to run. All reports and analyses are provided for informational purposes only and do not constitute professional, legal, financial, or compliance advice. You should independently verify all AI-generated content before relying on it for business decisions.

5. Data Storage & Security

We take the security of your information seriously and implement industry-standard technical and organizational measures to protect your data against unauthorized access, alteration, disclosure, or destruction.

5.1 Infrastructure and Hosting

The Service's application is hosted on Vercel, and its database and authentication are hosted on Supabase. Data is stored in secure data centers located in the United States that maintain physical security controls, environmental safeguards, and access restrictions.

5.2 Authentication and Access Controls

Authentication is passwordless and managed through Supabase:

  • Sign-in is via one-time secure email links; no passwords exist to be stolen or reused.
  • Row-level security (RLS) policies enforce per-user data isolation — each user can only access their own data.
  • Secure session management with token-based authentication and automatic session expiration.
  • Encryption of data at rest within the database.

5.3 Data in Transit

All data transmitted between your browser and the Service, as well as between the Service and third-party providers, is encrypted using HTTPS with TLS (Transport Layer Security) protocols. We enforce HTTPS across all endpoints and do not permit unencrypted connections.

5.4 Access Restrictions

Administrative access to infrastructure and databases is limited and protected by strong authentication mechanisms. Access to user data is limited to what is necessary to operate the Service.

5.5 Security Limitations

While we implement reasonable security measures, no method of electronic transmission or storage is completely secure. We cannot guarantee absolute security of your information. You acknowledge that you provide your information at your own risk and that you are responsible for maintaining the security of your email account, which is used to sign in.

6. Data Retention & Deletion

6.1 Retention Schedule

We retain information as follows:

  • Account data, company profile data, generated reports, credit balances, and purchase records: retained for as long as your account exists. There is no automatic expiration — your reports and credits persist until you delete reports individually or request account deletion.
  • Lead emails (Section 2.7): retained until you request deletion.
  • Security and audit logs: event logs used for security monitoring record IP addresses only in pseudonymized (hashed) form and are retained for a limited period consistent with the retention settings of our logging infrastructure.
  • Rate-limiting records: counters keyed to IP addresses expire automatically within minutes to hours of creation.
  • Payment records held by Stripe: retained by Stripe in accordance with Stripe's own data retention policies and applicable financial regulations.

6.2 Account Deletion (On Request)

Account deletion is not currently automated. To request deletion of your account and associated data, contact us through the channel listed in Section 15. Upon receiving and verifying a deletion request, we will manually and permanently delete your account data, including:

  • Personal data (email address, account records).
  • Company profile data you submitted through the Service.
  • Generated reports and analyses. You are encouraged to export any reports you wish to retain before requesting deletion — export is available from within the Service while logged in.
  • Usage records associated with your account (credit balances, purchase records we hold), except records we must retain for tax, accounting, fraud-prevention, or dispute-resolution purposes. Remaining credits are forfeited upon deletion.

The "Clear browser data" controls in the Service's settings remove only data stored in your own browser; they do not delete server-stored data.

6.3 Anonymized and Aggregated Data

We may retain anonymized, aggregated, and de-identified data indefinitely for research, analytics, and service improvement purposes. This data cannot reasonably be used to identify any individual user and is not subject to deletion requests.

6.4 Legal Obligations

Notwithstanding the above, we may retain certain information for longer periods if required by applicable law, regulation, or legal process, or if necessary to establish, exercise, or defend legal claims.

7. Cookies & Tracking Technologies

Cookies are small text files placed on your device by your web browser when you visit a website. We use cookies and similar technologies as described below.

7.1 Essential Cookies

We use strictly necessary cookies that are essential for the operation of the Service. These include session management cookies that maintain your authenticated state as you navigate the platform, as well as security cookies that help protect against cross-site request forgery (CSRF) and other common web vulnerabilities. These cookies are required for the Service to function and cannot be disabled without impairing core functionality.

7.2 Analytics

Rémis uses privacy-friendly, cookieless analytics (Vercel Web Analytics) to understand aggregate usage of the Service, such as page views and approximate visitor counts. This service does not set analytics or tracking cookies, does not track you across other websites, and does not collect personally identifiable information. We do not use advertising, retargeting, or cross-site tracking analytics. If we introduce analytics that rely on cookies in the future, we will update this Policy and provide a cookie consent mechanism that allows you to opt in or opt out before deploying such cookies.

7.3 Advertising Cookies

Rémis does not use advertising cookies, retargeting pixels, or any form of ad-related tracking technology. We do not participate in ad networks or serve targeted advertisements.

7.4 Do Not Track Signals

Some browsers transmit "Do Not Track" (DNT) signals to websites. Because there is no universally accepted standard for how to respond to DNT signals, we do not currently respond to DNT signals. However, as stated above, we do not engage in cross-site tracking or advertising-related tracking.

8. Third-Party Services

The Service integrates with and relies upon the following third-party service providers. Each operates under its own privacy policy, which we encourage you to review.

  • Supabase — Authentication, database hosting, and backend infrastructure. Supabase stores your account data, company profile data, generated reports, and credit records, and sends passwordless sign-in emails on our behalf. Privacy Policy: https://supabase.com/privacy.
  • Stripe, Inc. — Processes all payment transactions. Stripe receives your payment card information directly; Rémis does not. Privacy Policy: https://stripe.com/privacy.
  • Anthropic, PBC (Claude API) — AI processing for report and analysis generation, including model-directed web search. Anthropic receives the company profile data transmitted with each generation request. Privacy Policy: https://www.anthropic.com/privacy.
  • Vercel, Inc. — Hosts the application and provides cookieless web analytics (Section 7.2). As our host, Vercel processes incoming requests and associated technical data such as IP addresses and request metadata. Privacy Policy: https://vercel.com/legal/privacy-policy.
  • Upstash, Inc. — Provides the rate-limiting infrastructure that protects the Service from abuse. Upstash processes IP addresses in short-lived, automatically expiring counters. Privacy Policy: https://upstash.com/trust/privacy.
  • Resend — Delivers transactional email (the demo link email described in Section 2.7). Resend processes recipient email addresses and message content. Privacy Policy: https://resend.com/legal/privacy-policy.

We select third-party providers that maintain reasonable security practices and data protection measures. However, we are not responsible for the privacy practices or security of these third-party services. Your interactions with these providers are governed by their respective privacy policies.

9. Your Rights

Depending on your jurisdiction, you may have certain rights regarding your personal information. Rémis is committed to honoring these rights to the extent required by applicable law. You may exercise any of the following rights by contacting us at our LinkedIn page.

9.1 Right of Access

You have the right to request a copy of the personal information we hold about you. Upon verification of your identity, we will provide you with a summary of the categories of personal information collected, the purposes for which it is used, and the third parties with whom it has been shared.

9.2 Right to Correction

You have the right to request correction of any inaccurate or incomplete personal information we hold about you. You may update certain account information directly through the Service, or you may contact us to request corrections to information that cannot be modified through the platform.

9.3 Right to Deletion

You have the right to request deletion of your personal information, subject to certain exceptions. Deletion is performed manually as described in Section 6.2. We may retain certain information as required by law or for legitimate business purposes, such as fraud prevention or dispute resolution.

9.4 Right to Export

You may export your generated reports from within the Service while logged in, using the built-in download functionality. If you require assistance with data export, contact us before requesting account deletion — export tooling is not available after your data has been deleted.

9.5 Exercising Your Rights

To exercise any of the rights described above, please send a written request through the contact channel in Section 15. In your request, please clearly describe the right you wish to exercise and provide sufficient information for us to verify your identity. We will respond to verified requests as promptly as we reasonably can, and within any period required by applicable law. We will not discriminate against you for exercising your privacy rights.

10. California Privacy Rights (CCPA)

This section applies to California residents to the extent the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (collectively, "CCPA"), applies to Rémis. Rémis may not currently meet the CCPA's thresholds for a covered "business"; we nonetheless describe our practices here in the interest of transparency and will honor the rights below to the extent the CCPA applies.

10.1 Categories of Personal Information

In the preceding twelve (12) months, we have collected the following categories of personal information as defined by the CCPA: identifiers (email address, IP address); commercial information (purchase and credit records); internet or other electronic network activity information (usage data within the Service); and professional or employment-related information (company profile data submitted by you).

10.2 Sale and Sharing of Personal Information

Rémis does not sell your personal information as defined by the CCPA. We do not share your personal information for cross-context behavioral advertising purposes. We have not sold or shared personal information in the preceding twelve (12) months.

10.3 Your CCPA Rights

To the extent the CCPA applies, California residents have the right to: know what personal information we collect, use, and disclose; request deletion of personal information, subject to certain exceptions; correct inaccurate personal information; opt out of the sale or sharing of personal information (though Rémis does not sell or share personal information as defined by the CCPA); limit the use and disclosure of sensitive personal information, if applicable; and not be discriminated against for exercising these rights. To exercise these rights, contact us through the channel in Section 15. You may designate an authorized agent to make a request on your behalf, provided the agent can demonstrate proper authorization.

11. United States Only

The Service is operated from the United States, is offered solely to customers located in the United States, and is not directed to individuals in the European Economic Area, United Kingdom, Switzerland, or any other jurisdiction outside the United States. All data collected through the Service is stored and processed in the United States. If you access the Service from outside the United States despite this, you do so on your own initiative and acknowledge that your information will be transferred to, stored in, and processed in the United States, where data protection laws may differ from those in your jurisdiction.

12. Children's Privacy

The Service is not intended for, directed at, or designed to be used by individuals under the age of eighteen (18). Rémis is a business-oriented SaaS platform, and we expect all users to be adults capable of entering into binding legal agreements.

We do not knowingly collect, solicit, or receive personal information from individuals under the age of eighteen (18). If we become aware that we have collected personal information from a minor, we will take prompt steps to delete such information from our records. If you are a parent or guardian and believe that your child under the age of eighteen (18) has provided personal information to Rémis, please contact us immediately through the channel in Section 15 so that we can take appropriate action.

13. Changes to This Policy

We reserve the right to modify, amend, or update this Privacy Policy at any time. When we make material changes, we will update the "Effective date" at the top of this page and notify account holders by email to the address associated with their account. A change in the effective date alone, without notice, will not be used to impose material changes. We encourage you to review this Policy periodically.

Your continued use of the Service after any changes to this Policy become effective constitutes your acceptance of the revised Policy. If you do not agree with the terms of the updated Policy, you must discontinue your use of the Service and may request deletion of your account and personal information in accordance with Section 6.

14. Data Breach Notification

In the event of a security breach that results in the unauthorized access, acquisition, disclosure, or use of your personal information, we will notify affected users without unreasonable delay, and within any period required by applicable law, via email to the address associated with the affected account. The notification will include, to the extent known at the time:

  • A description of the nature of the breach, including the categories of personal information affected.
  • The approximate date or period of the breach.
  • The measures we have taken or propose to take to address the breach and mitigate its potential adverse effects.
  • Recommendations for steps you can take to protect yourself.
  • How to contact us with questions.

We will also notify applicable regulatory authorities as required by law, and will take all reasonable steps to contain and remediate any breach as quickly as possible.

15. Contact Information

If you have any questions, concerns, or requests regarding this Privacy Policy, our data practices, or the exercise of your privacy rights, please contact us at:

  • Contact: our LinkedIn page
  • Operator: Alexander Carlson, operating as Rémis
  • Locality: Indianapolis, Indiana, United States

We will make reasonable efforts to respond to all legitimate inquiries promptly. If you are not satisfied with our response, you may have the right to lodge a complaint with your local data protection authority, where applicable.

This Privacy Policy is governed by and construed in accordance with the laws of the State of Indiana, United States, without regard to its conflict of law provisions.