Legal

Privacy Policy

This policy explains how Repoke collects, uses, and protects your personal data in accordance with the General Data Protection Regulation (GDPR).

Effective date: 17 May 2026

Who we are

Repoke is an email-powered reminder service. We are the data controller responsible for the personal data you provide when using this service.

Data controller: Asad Maraqa, operating as Repoke, Finland
Contact: asadmarak@gmail.com

Data we collect

We collect only the data necessary to provide the reminder service. This falls into three categories:

Account data
  • Email address — used to identify your account and deliver reminders
  • Hashed password — stored using bcrypt; we never store your password in plain text
  • Email verification status and timestamp
Email content
  • Subject line of emails you send to our inbound address
  • The sender address of each inbound email (to match it to your account)
  • Email bodies are processed in memory to extract scheduling intent and are not stored
Guest trial data
  • Email address of unregistered senders — stored to track free trial usage (limit: 10 reminders)
  • Attempt count and timestamp of last attempt
  • This data is used solely to enforce the trial limit and is not linked to any account
Reminder logs
  • Trigger email metadata (sender address, subject line, received timestamp)
  • Scheduled send time and actual delivery time
  • Delivery status (pending, sent, failed) and any error messages
  • When AI parsing is used: a sanitised, anonymised excerpt of the email body (URLs, email addresses, and names removed; truncated to 300 characters) and the AI model's JSON response

We do not collect browser cookies beyond what is strictly necessary for authentication, we do not run advertising trackers, and we do not sell or share your data for marketing purposes.

How we use it

Delivering reminders

Scheduling and sending reminder emails at the time you specified, including replying to your original email thread.

Account authentication

Verifying your identity when you sign in and confirming your email address belongs to you.

AI timing extraction

When you use natural-language timing (e.g. "remind me Friday"), your email body is sent to an AI model to extract the intended time. See the AI processing section for details.

Service logs

Keeping a record of reminder runs so you can review delivery history and debug issues.

Service improvement

Aggregate, anonymised usage data (e.g. number of reminders sent per day) may be used to improve the service. This data cannot identify you.

AI processing

When you write natural-language timing in your email (e.g. "remind me before the call Friday"), we send the email body to an AI model to extract the intended time. This is the core of the AI scheduling feature.

What is sent to the AI: A sanitised excerpt of your email body — names, email addresses, URLs, phone numbers, account numbers, and monetary amounts are stripped before the text is sent, and it is truncated to 4,000 characters. We do not send your account details to the AI model.

AI provider: We currently use Google Gemini AI via the Google AI API. Google is headquartered in Mountain View, California, USA. Google does not use API data to train their models. You can review Google's data processing policies on their website.

Avoiding AI processing: All reminders are currently processed by AI to determine the timing. If you prefer not to have your email body processed by an AI model, personal details such as names, emails, and phone numbers are automatically redacted before the content is sent to the AI.

Retention of AI output: The sanitised prompt and the AI model's JSON response are stored in your reminder log so you can verify how the timing was parsed. The raw email body is never stored. You can view and delete this via your dashboard.

Third parties

We use a small number of sub-processors to operate the service. We have data processing agreements in place with each of them.

Google Gemini AIAI parsing of natural-language timing from email bodiesUSA
LangSmithMonitoring and debugging AI model calls (sanitised data only)EU
Email delivery providerSending reminder emails to your inboxEU / EEA
Database providerStoring account data, reminder configurations, and logsEU / EEA

We do not share your data with any other third parties. We never sell your data.

Data retention

Guest trial data90 days after last activity

If you use the service without an account, your email address and trial count are deleted 90 days after your last interaction. You can request earlier deletion by emailing asadmarak@gmail.com.

Account dataUntil you delete your account

Your email address and hashed password are kept for as long as your account is active. When you delete your account, this data is permanently erased within 30 days.

Reminder logs12 months

Delivery logs are automatically deleted 12 months after the reminder was sent or failed. You can delete individual logs at any time from your dashboard.

Email contentNever stored

The body of your inbound emails is processed in memory to extract scheduling intent and is never written to the database. Only the subject line and sender address are retained in reminder logs. When AI parsing is used, a sanitised excerpt (emails, URLs, and names removed; max 300 characters) is stored alongside the AI response so you can verify how the timing was interpreted.

Your rights

Under GDPR you have the following rights regarding your personal data. You can exercise them using our data request form or by emailing us at asadmarak@gmail.com. We will respond within 30 days.

Art. 15
Right of access

You can request a copy of all personal data we hold about you.

Art. 16
Right to rectification

You can ask us to correct inaccurate data we hold about you.

Art. 17
Right to erasure

You can ask us to delete your account and all associated personal data. We will action this within 30 days.

Art. 18
Right to restriction

You can ask us to restrict processing of your data while a dispute is resolved.

Art. 20
Right to data portability

You can download all your personal data as a JSON file directly from your dashboard using the Export data link in the top navigation.

Art. 21
Right to object

You can object to processing based on legitimate interest. We will stop unless we have compelling legitimate grounds.

Art. 77
Right to lodge a complaint

You have the right to lodge a complaint with your local data protection supervisory authority if you believe we have violated your rights.

Cookies

We use only strictly necessary cookies. No advertising or tracking cookies are set.

auth_tokenKeeps you signed in across page loadsSession / 7 days

Because we use only strictly necessary cookies, we are not required to show a cookie consent banner under the ePrivacy Directive. If we introduce non-essential cookies in the future, we will update this policy and add consent controls.

International transfers

Some of our sub-processors are based outside the European Economic Area (EEA). Our AI processing is handled by Google Gemini AI, which is based in the USA. Where data is transferred outside the EEA, we ensure appropriate safeguards are in place:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Adequacy decisions where applicable

You can request details of the specific safeguards in place by contacting us at asadmarak@gmail.com.

Changes to this policy

We may update this policy from time to time. When we make material changes, we will notify you by email at least 14 days before the changes take effect. The effective date at the top of this page will always reflect the current version. Continued use of the service after the effective date constitutes acceptance of the updated policy.

Contact us

For any privacy-related questions, data subject requests, or concerns, contact us at:

Email: asadmarak@gmail.com
Response time: Within 30 days (typically much sooner)

As this service is operated from Finland, the lead supervisory authority is the Tietosuojavaltuutettu (Office of the Data Protection Ombudsman) — tietosuoja.fi. If you are based in another EU/EEA country you may also contact your local data protection authority.