Privacy and your data
Where Remi stores your data, who handles it, how long it's kept, and how to use your rights. A summary of Remi's privacy policy.
Your workspace lives in the EU, is encrypted, and is never used to train a model.
This page sums up Remi's privacy policy. The policy itself is what counts: read it in full at remiapp.ai/privacy. Remi AI Ltd, registered in England and Wales, is the data controller.
What Remi doesn't do with your data
- It doesn't use your data to train AI models.
- It doesn't sell your data.
- It doesn't profile you for advertising.
- It doesn't share your data with advertisers, data brokers or any other third parties beyond the service providers listed below.
Where your data is stored
All Remi-managed infrastructure is hosted in the EU.
| What | Where it's kept | Region |
|---|---|---|
| Account data, messages, events and usage | Neon PostgreSQL | EU only |
| Document files | Hetzner S3-compatible storage | EU only |
| Document vector embeddings | ChromaDB, self-hosted on Hetzner | EU only |
| Real-time session tokens | Ably | EU/UK |
When your data leaves the EU
When you send a message, your prompt and the relevant parts of your documents go to an AI provider, which writes the response. Remi's automatic routing puts EU providers first.
The only time your data leaves the EU is when a prompt goes to a US-based AI provider, and that happens only if your workspace is set up to use one. If you choose a US-based model yourself, your prompt is processed in the US. These transfers are covered by Standard Contractual Clauses (SCCs). Under their API terms, US-based providers don't keep your data to train models.
| AI provider | Data location | Used for |
|---|---|---|
| Mistral | EU | Responses |
| Remi-hosted models | EU | Responses |
| OpenRouter | US/EU (varies) | Routing to other providers |
| Anthropic (Claude) | US | Responses |
| OpenAI (GPT) | US | Responses |
| Google (Gemini) | US | Responses and embeddings |
What Remi collects
- Account data: your email address, which you sign in with; your name, if you give it; and which accounts and workspaces you belong to.
- Usage data: chat messages and AI responses, the documents you upload and the text taken from them, facts and knowledge items, which integrations are connected, usage and cost records, sign-in times, session data, IP addresses, and browser and device information.
- Technical data: vector embeddings of your documents, which are mathematical representations rather than readable text, and event logs that record every action as an audit trail.
Who handles your data
Remi shares data only with the service providers it needs to run:
- AI providers: Mistral and Remi-hosted models, and, only if your workspace uses them, OpenRouter, Anthropic, OpenAI and Google. They write responses.
- Neon: database hosting.
- Hetzner: servers and file storage.
- Ably: real-time messaging.
- Brave Search: web results. It gets only the search query, not who you are.
- Resend: sends emails, such as your sign-in codes.
- PostHog, hosted in the EU: product analytics and session replay. Chat and document content is masked before anything is captured.
Cookies and analytics
Remi uses essential cookies for signing in and keeping your session. It uses no advertising cookies.
PostHog, hosted in the EU, handles product analytics, and keeps its state in your browser's local storage rather than in cookies. Session replays record only layout and clicks: chat and document content is masked, and no text or input contents are recorded. To delete the analytics data linked to your account, write to privacy@remiapp.ai.
How long Remi keeps your data
| Data | How long |
|---|---|
| Account data | While your account is active. Deleted within 30 days of closing it. |
| Chat messages and AI responses | While your account is active. Deleted within 30 days of closing it. |
| Documents and their embeddings | While your account is active. Deleted within 30 days of closing it, or when you delete the document. |
| Event logs | 12 months after you close your account, for the audit trail. Then deleted. |
| Billing records | 6 years, as UK tax law requires. |
Your rights
Under UK GDPR, you have the right to:
- see the personal data Remi holds about you;
- correct data that's wrong;
- have your data deleted, apart from what the law says Remi must keep;
- get your data in a machine-readable format to take elsewhere;
- restrict how Remi processes your data;
- object to processing that's based on Remi's legitimate interest;
- withdraw your consent, where processing is based on it.
To use any of them, email privacy@remiapp.ai. Remi replies within 30 days.
If you're not happy with the answer, you can complain to the Information Commissioner's Office (ICO) at ico.org.uk or on 0303 123 1113.
Close your account
The account's owner can ask the Remi team to delete the account and everything in it, from Settings · Account. Delete your account has the steps. Nothing is deleted until the team replies, and then the retention times above apply.
When the policy changes
Remi emails you about material changes to the policy at least 30 days before they take effect.
Team roles
The four roles on a Remi account, what each one can do, what stays private whatever your role, and how to invite people, change a role or remove someone.
Shortcuts, links and troubleshooting
Keyboard shortcuts for the web, Remi Desktop and the browser extension, links that open Remi, fixes for the errors you might see, and how to reach the Remi team.