Privacy
What we hold, and what we cannot hold.
Last updated 1 August 2026
Reep Tech Ltd, Hilltop, Nsukka, Nigeria
Reep is a custodian of encrypted data. This policy explains the small amount of information we can actually read, why we hold it, and how to remove it.
Data we can read
Account email, billing records handled by our payment processor, contact details for guardians and beneficiaries you enter, and technical logs such as IP address and device type used for security and abuse prevention.
Data we cannot read
Everything inside your vault. Content is encrypted in your browser with a key derived from your passphrase, which is never transmitted to us. We store ciphertext, so we cannot produce your vault contents to anyone, including a court.
Why we process it
To operate your account, send heartbeat reminders, contact guardians when a verification request opens, take payment, and meet legal obligations. We do not profile you and we do not sell data.
Guardians and beneficiaries
When you add someone, you provide their name, relationship and contact details. We use these only to contact them about your vault. They can ask us to correct or erase their details, which removes them from your guardian network.
Retention
Account data is kept while your account is open. After deletion, ciphertext is removed and identifiers are erased within thirty days, except records we must keep for tax and accounting.
Your rights
Access, correction, erasure, portability, restriction and objection under GDPR, and equivalent rights under Nigerian data protection law. Write to hello@reep.cc and we respond within thirty days.
International transfers
Vaults are stored in the region matching your jurisdiction. Where data moves between regions, it does so under standard contractual clauses.
Changes
Material changes are emailed to account holders at least fourteen days before they take effect.