Privacy Policy
Last updated: May 2026
This Privacy Policy explains how Renewly Alerts ("we", "us") collects, uses, stores and shares personal data when you use our document renewal tracking service (the "Service"). It is written to align with the EU General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act (CCPA/CPRA) and similar privacy laws.
1. Who we are (Data Controller)
Renewly Alerts is the data controller for the personal data you provide when using the Service. You can contact us through the support channel listed in the app for any privacy-related question or request.
2. What data we collect
- Account data: email address, authentication identifiers, and (if you sign in with Google) your Google profile name and avatar.
- Document data: photos and PDFs you upload (which may contain ID numbers, license numbers, addresses, dates of birth, insurance policy numbers, vehicle details and similar information).
- Extracted metadata: document type, expiry dates, issuer and other fields extracted from your uploads by automated processing (AI).
- Usage data: basic logs (timestamps, error events) needed to operate and secure the Service.
We do not intentionally collect special category data (e.g. health, biometric or political data). If you upload a document that contains such information, you do so at your own discretion.
3. How we use your data (purposes & legal bases)
- To provide the Service — store your documents, extract expiry dates, show reminders. Legal basis: performance of a contract with you.
- To send renewal notifications by email or push. Legal basis: performance of a contract.
- To secure the Service and prevent abuse. Legal basis: legitimate interests.
- To comply with legal obligations (e.g. responding to lawful requests). Legal basis: legal obligation.
We do not sell your personal data. We do not use your documents to train AI models.
4. Automated processing (AI)
Documents you upload are processed by third-party AI providers to extract structured fields such as document type and expiry date. The provider receives the image or PDF content solely for the purpose of returning the extracted data and is contractually prevented from using it for training. AI extraction can be inaccurate — please verify all extracted information against the original document. You have the right not to be subject to a decision based solely on automated processing that has legal effects on you; the extracted data is informational and you remain in control of any renewal decisions.
5. Where your data is stored
Your account data and document metadata are stored in our managed cloud database. Uploaded files are stored in encrypted object storage. Access is restricted by row-level security so that only you (and authorised infrastructure) can read your data. Backups are encrypted.
6. Service providers (processors)
- Cloud database & storage provider — hosts your account, document metadata and files.
- Authentication provider — verifies your email/Google sign-in.
- AI provider — extracts expiry dates and metadata from uploaded documents.
- Email & notification providers — deliver reminder messages.
- Hosting / edge provider — serves the application.
Each processor is bound by a data processing agreement and may process data outside your country of residence (including the United States or the European Economic Area). Where transfers leave the EEA/UK, we rely on Standard Contractual Clauses or equivalent safeguards.
7. How long we keep your data
We retain your account data and documents for as long as your account is active. If you delete a document, it is removed from active storage promptly and from backups within the normal backup rotation (typically up to 30 days). If you delete your account, your personal data and uploaded files are deleted within 30 days, except where we are required to retain certain records to comply with the law.
8. Your rights
Depending on where you live, you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate data.
- Delete your data ("right to be forgotten").
- Export your data in a portable format.
- Object to or restrict certain processing.
- Withdraw consent at any time (where processing is based on consent).
- Lodge a complaint with your local data protection authority.
- If you are in California: opt out of "sale" or "sharing" of personal data — we do not sell or share your data for cross-context behavioural advertising.
You can exercise most of these rights directly inside the app (deleting documents or your account). For other requests, contact us via the support channel.
9. Security
We use industry-standard measures including encryption in transit (HTTPS), encryption at rest, row-level access controls and least-privilege service credentials. No system is 100% secure, however, and we cannot guarantee absolute security of data transmitted over the internet.
10. Children
The Service is not directed to children under 16 and we do not knowingly collect data from them. If you believe a child has provided us with personal data, please contact us so we can delete it.
11. Cookies & tracking
We use only essential cookies and local storage required to keep you signed in and remember your preferences (such as theme). We do not use third-party advertising or cross-site tracking cookies.
12. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be communicated in the app or by email. The "Last updated" date at the top reflects the latest revision.
13. Contact
For any privacy question or to exercise your rights, contact us through the support channel listed in the app.