Legal
Privacy Policy
This policy explains how Repoke collects, uses, and protects your personal data in accordance with the General Data Protection Regulation (GDPR).
Effective date: 17 May 2026
Who we are
Repoke is an email-powered reminder service. We are the data controller responsible for the personal data you provide when using this service.
Contact: asadmarak@gmail.com
Data we collect
We collect only the data necessary to provide the reminder service. This falls into three categories:
- Email address — used to identify your account and deliver reminders
- Hashed password — stored using bcrypt; we never store your password in plain text
- Email verification status and timestamp
- Subject line of emails you send to our inbound address
- The sender address of each inbound email (to match it to your account)
- Email bodies are processed in memory to extract scheduling intent and are not stored
- Email address of unregistered senders — stored to track free trial usage (limit: 10 reminders)
- Attempt count and timestamp of last attempt
- This data is used solely to enforce the trial limit and is not linked to any account
- Trigger email metadata (sender address, subject line, received timestamp)
- Scheduled send time and actual delivery time
- Delivery status (pending, sent, failed) and any error messages
- When AI parsing is used: a sanitised, anonymised excerpt of the email body (URLs, email addresses, and names removed; truncated to 300 characters) and the AI model's JSON response
We do not collect browser cookies beyond what is strictly necessary for authentication, we do not run advertising trackers, and we do not sell or share your data for marketing purposes.
How we use it
Scheduling and sending reminder emails at the time you specified, including replying to your original email thread.
Verifying your identity when you sign in and confirming your email address belongs to you.
When you use natural-language timing (e.g. "remind me Friday"), your email body is sent to an AI model to extract the intended time. See the AI processing section for details.
Keeping a record of reminder runs so you can review delivery history and debug issues.
Aggregate, anonymised usage data (e.g. number of reminders sent per day) may be used to improve the service. This data cannot identify you.
Legal basis for processing
Under GDPR Article 6, we rely on the following legal bases:
Processing your account data and email content is necessary to provide the reminder service you signed up for. Without this processing we cannot deliver reminders.
Keeping reminder logs and basic security audit data is in our legitimate interest to maintain a reliable service and investigate abuse. We have assessed that this interest is not overridden by your rights.
When an unregistered sender emails our service address, we process their email to fulfil the reminder they requested and store their email address to enforce the free trial limit. This is in our legitimate interest to operate a fair trial system, and we have assessed that this interest is not overridden by the sender's rights. A privacy notice is included in our first reply to every guest.
We may retain certain data to comply with applicable laws and regulations.
AI processing
What is sent to the AI: A sanitised excerpt of your email body — names, email addresses, URLs, phone numbers, account numbers, and monetary amounts are stripped before the text is sent, and it is truncated to 4,000 characters. We do not send your account details to the AI model.
AI provider: We currently use Google Gemini AI via the Google AI API. Google is headquartered in Mountain View, California, USA. Google does not use API data to train their models. You can review Google's data processing policies on their website.
Avoiding AI processing: All reminders are currently processed by AI to determine the timing. If you prefer not to have your email body processed by an AI model, personal details such as names, emails, and phone numbers are automatically redacted before the content is sent to the AI.
Retention of AI output: The sanitised prompt and the AI model's JSON response are stored in your reminder log so you can verify how the timing was parsed. The raw email body is never stored. You can view and delete this via your dashboard.
Third parties
We use a small number of sub-processors to operate the service. We have data processing agreements in place with each of them.
We do not share your data with any other third parties. We never sell your data.
Data retention
If you use the service without an account, your email address and trial count are deleted 90 days after your last interaction. You can request earlier deletion by emailing asadmarak@gmail.com.
Your email address and hashed password are kept for as long as your account is active. When you delete your account, this data is permanently erased within 30 days.
Delivery logs are automatically deleted 12 months after the reminder was sent or failed. You can delete individual logs at any time from your dashboard.
The body of your inbound emails is processed in memory to extract scheduling intent and is never written to the database. Only the subject line and sender address are retained in reminder logs. When AI parsing is used, a sanitised excerpt (emails, URLs, and names removed; max 300 characters) is stored alongside the AI response so you can verify how the timing was interpreted.
Your rights
Under GDPR you have the following rights regarding your personal data. You can exercise them using our data request form or by emailing us at asadmarak@gmail.com. We will respond within 30 days.
You can request a copy of all personal data we hold about you.
You can ask us to correct inaccurate data we hold about you.
You can ask us to delete your account and all associated personal data. We will action this within 30 days.
You can ask us to restrict processing of your data while a dispute is resolved.
You can download all your personal data as a JSON file directly from your dashboard using the Export data link in the top navigation.
You can object to processing based on legitimate interest. We will stop unless we have compelling legitimate grounds.
You have the right to lodge a complaint with your local data protection supervisory authority if you believe we have violated your rights.
International transfers
Some of our sub-processors are based outside the European Economic Area (EEA). Our AI processing is handled by Google Gemini AI, which is based in the USA. Where data is transferred outside the EEA, we ensure appropriate safeguards are in place:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions where applicable
You can request details of the specific safeguards in place by contacting us at asadmarak@gmail.com.
Changes to this policy
We may update this policy from time to time. When we make material changes, we will notify you by email at least 14 days before the changes take effect. The effective date at the top of this page will always reflect the current version. Continued use of the service after the effective date constitutes acceptance of the updated policy.
Contact us
For any privacy-related questions, data subject requests, or concerns, contact us at:
Response time: Within 30 days (typically much sooner)
As this service is operated from Finland, the lead supervisory authority is the Tietosuojavaltuutettu (Office of the Data Protection Ombudsman) — tietosuoja.fi. If you are based in another EU/EEA country you may also contact your local data protection authority.