Privacy Policy
Last updated: 2026-08-30
Introduction
Remi ("Remi," "we," "us") operates remi.systems, a multi-tenant software service for web agencies, freelancers, and website-maintenance providers.
This Privacy Policy describes how we collect, use, store, share, and delete information when you use the Remi service, create an organization, add client websites, run scans, generate Remi Reports, and manage billing.
This page is provided for transparency about our product data practices. It is not legal advice.
Information we collect
Account and profile data: name, email address, authentication identifiers managed by Supabase Auth, and profile preferences you provide.
Organization data: agency or company name, branding details used on client-facing Remi Reports, organization membership, and tenant-scoped configuration.
Website monitoring data: client website URLs, scan schedules, scan results, health scores, issues, report records, and delivery history for Remi Reports sent on your behalf.
Protected-site access credentials: when you choose HTTP Basic Auth for a monitored site, Remi stores those credentials in encrypted form so scans can run. We do not support form login, SSO, MFA, OTP, or CAPTCHA-based site access in V1.
Billing data: subscription status, plan tier, and payment-related identifiers processed through Stripe. Remi does not store full payment card numbers.
Support and operational data: service logs, error records, correlation identifiers, and communications needed to operate, secure, and improve the service.
Public marketing interactions: limited information from visitors who use public pages such as the homepage, sample report, or free-scan entry points, consistent with the applicable product flow.
How we use information
Provide and operate the Remi service, including tenant-scoped website scans, scoring, report generation, scheduled automation, and billing.
Deliver agency-branded Remi Reports and related email notifications to recipients you configure.
Authenticate users, enforce organization membership boundaries, and protect tenant isolation.
Process subscriptions, invoices, payment failures, and account recovery in accordance with our billing and retention policies.
Detect, investigate, and prevent abuse, security incidents, and operational failures.
Improve reliability, support customers, and maintain audit records required to operate a commercial SaaS platform.
Health checks and report data
V1 health checks include reachability, HTTPS and SSL validity, SSL expiration, broken internal links, homepage PageSpeed results, and basic SEO metadata.
Scan and report content reflects the state of monitored websites at the time of each scan. Remi Reports are informational maintenance summaries and do not guarantee future uptime, security, or search performance.
Report and email content may include website URLs, issue summaries, scores, and agency branding you supply. Sensitive protected-site credentials are not included in client-facing reports.
Sharing and service providers
We do not sell personal information. We share data only as needed to operate Remi, comply with law, or protect the service.
Infrastructure and product processors may include Supabase (database, authentication, and storage), Vercel (application hosting), Stripe (billing), Resend (transactional email), and Google PageSpeed Insights (performance measurement).
Each processor receives only the data needed for its function and is used under contractual and security expectations appropriate to a commercial SaaS platform.
Retention and deletion
While your account is active and in good standing, Remi retains tenant-owned application data needed to provide the service.
If billing becomes unresolved, Remi follows a staged nonpayment lifecycle: automated scans and reports may pause, recovery access may continue for a period, stored protected-site credentials may be permanently deleted after extended nonpayment, and remaining tenant application data may be permanently deleted after longer unresolved nonpayment, subject to documented legal or accounting exceptions.
Export of tenant application data remains available while data is retained and is offered before voluntary account deletion.
Voluntary deletion removes tenant-owned application data according to the operational lifecycle defined for the product.
Security
Remi uses organization-scoped access controls, encrypted transport, encrypted storage for protected-site credentials, and backend-only use of privileged service credentials.
No method of transmission or storage is completely secure. We work to reduce risk through tenant isolation, least-privilege access, and operational monitoring.
Your choices
You can update profile and organization information within the product where those features are available.
Organization owners may request export of retained application data while export remains available.
You may stop using the service, manage billing through Stripe where applicable, and request account deletion according to product workflows.
Questions about this policy can be sent to support@remi.systems.
Changes to this policy
We may update this Privacy Policy when product, legal, or operational requirements change. Material updates will be reflected by a revised last-updated date on this page.
