Last Updated: July 16, 2026
Rejourney ("we," "us," or "our") is committed to protecting your privacy. This Privacy Policy describes how we collect, use, and share information when you use our Service.
When you visit rejourney.co, we collect standard log data and use first-party cookies and local storage identifiers to understand how you interact with our site. This may include your IP address, browser type, and pages visited. We use this information to improve our website and marketing efforts.
We use the Rejourney web SDK on rejourney.co to capture optional first-party website analytics, performance signals, and session replay so we can improve our website and product experience. We load Rejourney website analytics and replay only after you provide explicit consent through our cookie consent banner. The SDK masks text inputs by default and does not load third-party session replay tooling.
We also use the Google tag for Google Ads conversion measurement. Consent Mode v2 keeps advertising storage, analytics storage, advertising user data, and ad personalization denied until you allow cookies. Before consent, Google Ads click or campaign identifiers are not persisted by Rejourney or submitted with signup requests. When a new account completes signup after consent, the conversion may include normalized email data that Google hashes before transmission, a unique transaction ID for deduplication, and consented Google Ads click or campaign identifiers used for attribution.
If you create a Rejourney account, we collect information necessary to provide the Service, including your name, email address, and billing information. We use this to manage your account, process payments, and send you Service-related notifications.
Rejourney processes data about your mobile application's end-users on your behalf. This data is collected via the Rejourney SDK and may include session replays, device metadata, approximate geolocation (country, region, city derived from IP address), and interaction events. You (our Customer) are the Data Controller for this data, and Rejourney is the Data Processor. You are responsible for ensuring your end-users are informed about session recording and that you have a valid legal basis for such processing.
Privacy is built into Rejourney by design. Our SDK automatically scrubs:
Console logs: When console log capture is enabled (on by default), the SDK captures up to 1,000 console log entries per session. Console logs may contain PII depending on your application's logging practices. We recommend disabling this feature or sanitizing logs if sensitive data may appear in console output.
Disclaimer:
While Rejourney provides these automatic privacy measures, they are provided as default tools to assist you. You (the developer/customer) are responsible for verifying that your specific implementation does not capture sensitive data and that you have configured masks or redactions as necessary for your unique UI and data flow.
We do not sell your data. We share information with the following sub-processors to provide the Service:
| Provider | Purpose | Location | Transfer Mechanism |
|---|---|---|---|
| Hetzner Online GmbH | Cloud Infrastructure & Hosting | Germany (EU) | EU — no transfer |
| Cloudflare R2 | Session Data Backups | EU (Guaranteed) | EU — no transfer |
| OVHcloud US | Object Storage | United States | DPA |
| Microsoft Azure OpenAI Service (GPT-5.5 deployment; effective July 30, 2026) | AI-assisted revenue-leak prediction using data-minimized, pseudonymized diagnostic and analytics signals | Customer-selected Azure region; EEA Customer Personal Data is processed in an EU/EFTA regional deployment | EU Data Boundary where configured; otherwise Microsoft DPA and EU SCCs, where applicable |
| ZeptoMail (Zoho) | Transactional Email Delivery | United States | SCCs (Art. 46(2)(c)) |
| Stripe | Payment Processing | United States | SCCs (Art. 46(2)(c)) |
Session Replays: Automatically deleted after 7 days on the free plan, otherwise retained for the duration detailed in your subscription.
Metadata & Analytics: Personally identifiable session metadata is retained for the duration of your active subscription. After a session recording is deleted, anonymized aggregate event data (containing no personal identifiers) may be retained indefinitely for product analytics, research, benchmarking, and public trend reporting.
Backups: Encrypted backups are retained for up to 90 days for disaster recovery.
We may analyze, process, and compile Customer Data and service telemetry to create fully anonymized, aggregated, or de-identified datasets. We may share these fully anonymous, non-personally identifiable (PII masked) datasets with trusted third-party research institutions or partners for academic and industrial research purposes.
Additionally, we may use such fully anonymous, aggregated, and de-identified data for the purposes of training, developing, and improving our artificial intelligence (AI), machine learning models, and automated features.
Prior to any sharing or training use, we apply rigorous privacy-preserving techniques to ensure all Personally Identifiable Information (PII) is permanently stripped or masked, and the data is rendered fully anonymous so that individual users, customer organizations, or apps cannot be re-identified under any circumstances. Once data is fully anonymized, it no longer constitutes "personal data" under the GDPR and other applicable global data privacy regulations.
Shared research datasets and model training will never include raw session recordings, screenshots, request payloads, unmasked personal data, customer confidential information, or information that could reasonably identify or single out a particular customer, application, or end-user.
Under GDPR, pseudonymized data remains personal data when it can be attributed to an individual using additional information. We treat pseudonymized data as personal data unless and until it has been rendered anonymous so that the individual is not or no longer identifiable by means reasonably likely to be used.
If you are located in the European Economic Area, you have the following rights regarding your personal data:
To exercise any of these rights, please contact [email protected]. We will respond within 30 days of receiving your request.
You also have the right to lodge a complaint with the data protection supervisory authority in your country of residence. A full list of EU supervisory authorities is available at edpb.europa.eu.
We use industry-standard security measures, including TLS 1.3 encryption for data in transit and AES-256 for data at rest. We conduct regular security audits to ensure your data remains protected.
We rely on the following legal bases under GDPR Article 6 for our processing activities:
We may update this policy periodically. Material changes will be notified via email or a prominent notice on our website.