Legal
Privacy Policy
Last updated: July 29, 2026
1. What we collect
Account data: when you sign in with Google, we receive your name, email address, and profile photo from Google OAuth. We don’t receive or store your Google password.
Product data: the applications, bookmarks, and reviews you create; the free-text query you submit to the AI niche matcher; and your plan status (Free or lifetime Pro).
Billing data: if you upgrade to Pro, Stripe collects and stores your payment details directly — refyr never sees or stores your full card number.
Usage data: basic technical logs (timestamps, request paths, error rates) used to run and debug the Service, and — if enabled — aggregate, privacy-respecting analytics about which pages are used.
2. How we use it
- To authenticate you and keep you signed in;
- To run the features you use — search, filters, the AI matcher, your application tracker, and bookmarks;
- To process one-time Pro purchases and unlock lifetime access;
- To keep the Service secure, debug issues, and improve it over time;
- To email you about your account or the Service when necessary (e.g. a billing receipt or a security notice).
We do not sell your personal data, and we don’t show ads on refyr.
3. Who we share it with
We share the minimum data necessary with a small number of processors that run parts of the Service on our behalf:
- Google — for Sign in with Google (OAuth authentication).
- OpenAI — receives the text of your niche-matching queries (and program descriptions) to generate embeddings and match explanations.
- Stripe — handles one-time Pro payments and stores your billing/payment details.
- Our hosting/infrastructure providers — run the servers and database the Service operates on.
Each of these processes data under its own privacy commitments, only for the purpose of providing that part of the Service. We don’t sell or rent your data to anyone else, and we only disclose it further if required by law.
4. Cookies
refyr uses httpOnly session cookies to keep you signed in — they hold an access/refresh token and a small cached copy of your profile, and are never readable by page scripts. We don’t use third-party advertising or cross-site tracking cookies.
5. Data retention & deletion
We keep your account data for as long as your account is active, plus a reasonable period afterward for legal, billing, and security purposes. You can request deletion of your account and associated data at any time by emailing support@refyr.app — we’ll confirm once it’s done, typically within 30 days. Some billing records may be retained longer where required by law (e.g. tax records).
6. Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, or to object to certain processing. To exercise any of these, email support@refyr.app — we’ll respond as required by applicable law.
7. Data security
We use industry-standard practices to protect your data — passwords are never handled by us at all (auth is delegated to Google), session tokens live in httpOnly cookies rather than anywhere client scripts can read them, and access to production data is restricted. No system is perfectly secure, and we can’t guarantee absolute security.
8. Children’s privacy
refyr is not directed at children under 16, and we don’t knowingly collect data from them.
9. International users
Your data may be processed in a country other than the one you live in, wherever our infrastructure and processors (Section 3) operate. By using the Service, you consent to that transfer.
10. Changes to this policy
We may update this policy as the Service evolves. We’ll update the “Last updated” date above, and make a reasonable effort to notify signed-in users of material changes.
11. Contact
Questions about this policy, or a request under Sections 5–6: support@refyr.app, or see Contact. See also our Terms of Service.