Privacy Policy
REAP Integrity Membership
Last updated: August 26, 2026
1. Information We Collect
Personal Information
- Name, email address, and account credentials
- Profile information and preferences
- Goals, tasks, and progress data
- Journal entries and personal reflections
- Communication between partners (when shared)
Payment Information
- Payment information is processed securely by Stripe
- We do not store credit card numbers or payment details
- We retain transaction records for billing purposes
Usage Data
- App usage patterns and feature interactions
- Device information and browser type
- IP address and general location data
- Session duration and frequency of use
2. How We Use Your Information
- Provide and improve our services
- Process payments and manage subscriptions
- Send important account and service updates
- Provide customer support
- Generate insights and recommendations
- Ensure security and prevent fraud
3. Partner Data Sharing
Important: When you connect with a partner, certain information may be shared between you:
- Shared goals and projects are visible to both partners
- Progress on shared challenges and activities
- Calendar events marked as "shared"
- Collaboration partner interactions
- Individual journal entries remain private unless explicitly shared
4. Data Security
- All data is encrypted in transit and at rest
- Secure authentication and session management
- Regular security audits and monitoring
- Limited access to personal data by staff
- Secure cloud infrastructure and backups
5. Calendar Integration (Google Calendar & Microsoft Outlook)
Important: When you connect your calendar accounts, here's how we use your data:
What We Access
- Calendar Events: We read your calendar events to display them in your REAP Daily Hub for schedule management
- Event Creation: We create calendar events in your Google/Outlook calendar when you create events in REAP
- Event Details: Event titles, dates, times, locations, descriptions, and meeting links (Zoom, Teams, Google Meet)
- Meeting Information: We extract meeting links to make it easy for you to join meetings directly from REAP
What We Do NOT Do
- No Sharing: We do not share your calendar data with anyone, including other REAP users
- No Selling: We never sell your calendar data to third parties or advertisers
- No Unrelated Access: We only access calendars you explicitly connect to REAP
- No Marketing: We don't use your calendar data for marketing or advertising purposes
- Private Events Stay Private: Events marked as private in your calendar are not accessible by REAP
How We Protect Calendar Data
- All calendar data is encrypted in transit and at rest
- We use secure OAuth 2.0 authentication (no passwords stored)
- Access tokens are stored securely and refreshed automatically
- You can disconnect your calendar at any time from Account Settings
- When you disconnect, we immediately stop accessing your calendar and delete stored tokens
Why We Need Calendar Access
- Display all your commitments in one place (REAP Daily Hub)
- Help you manage time and avoid scheduling conflicts
- Track productivity and time allocation for your personal development goals
- Provide easy access to meeting links (Zoom, Teams, Google Meet)
- Sync events between REAP and your existing calendar workflow
6. Zoom Integration
Important: When you connect your Zoom account, here's how we use your data:
- Meeting Creation: We create Zoom meetings on your behalf when you schedule events that require video conferencing
- Meeting Links: We store meeting URLs to display in your calendar and share with participants
- Cloud Recordings & Transcripts (optional): With read-only recording access (
cloud_recording:read), we can retrieve the transcript of a meeting you recorded to Zoom's cloud — but only when you ask REAP to help you draft a follow-up email or suggest tasks from that specific meeting.
- User-Initiated Only: We retrieve a transcript only when you start a follow-up or task-suggestion action for a specific meeting — never automatically, in the background, or in bulk.
- How Transcripts Are Used: A transcript is used solely to generate a draft (a follow-up email or suggested tasks) for you to review and edit. Transcripts are not sold, shared with third parties, or used for advertising.
- No Participant Data Harvesting: We do not collect or store data about meeting participants beyond what you choose to save
- Secure Tokens: We use OAuth 2.0 to securely connect to your Zoom account (no passwords stored)
- Disconnect Anytime: You can disconnect Zoom from Account Settings at any time
7. Bank Account Connections (Plaid)
Important: Our budgeting features let you securely connect your bank and credit card accounts using Plaid Inc. Here's how your financial data is handled:
How the Connection Works
- Powered by Plaid: We use Plaid to securely connect to your financial institution. You enter your bank credentials directly into Plaid's secure interface — we never see or store your bank username or password.
- Explicit Consent: We only connect accounts you choose to link by clicking "Connect Bank" and completing Plaid's authorization flow.
- Access Tokens: Plaid provides us a secure access token (not your login) that lets us retrieve your account data on your behalf.
What We Access
- Transactions: Transaction history to build your spending feed, categorize purchases, and detect recurring bills and income
- Balances: Account balances to display your current cash position
- Liabilities: Credit card and loan details (APR, minimum payment, due dates, balances) to power our debt-tracking features
How We Use and Protect It
- Budgeting Only: Your financial data is used solely to provide budgeting, spending-tracking, and debt-management features to you within the app.
- Never Sold or Shared: We do not sell, rent, or share your financial data with third parties or advertisers.
- Encrypted: Financial data and access tokens are encrypted in transit and at rest.
- Disconnect Anytime: You can disconnect a bank at any time from the app. When you do, we revoke the connection with Plaid (via Plaid's item removal) and delete the associated financial data and access token.
- Plaid's Role: Plaid's handling of your data is governed by Plaid's End User Privacy Policy.
8. Third-Party Services
- Stripe: Payment processing (subject to Stripe's privacy policy)
- Plaid: Secure bank account connections for budgeting features (subject to Plaid's privacy policy)
- SendGrid: Email communications
- OpenAI: AI-powered coaching features (data processed securely)
- Google Calendar API: Calendar synchronization for productivity features
- Gmail API: Sending follow-up emails you compose (send-only; no inbox access)
- Google Drive API: Attaching Drive files you select as project resources (per-file access only)
- Microsoft Graph API: Outlook Calendar synchronization for productivity features
- Zoom API: Video meeting creation, scheduling, and (with your consent) meeting transcripts for drafting follow-ups
- These services have their own privacy policies and security measures
- REAP's use of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements
9. Data Retention
- Account data is retained while your subscription is active
- Data may be retained for up to 30 days after cancellation
- Financial records kept for 7 years as required by law
- You can request complete data deletion at any time
10. Your Rights
- Access: Request a copy of your personal data
- Correction: Update or correct inaccurate information
- Deletion: Request deletion of your personal data
- Portability: Export your data in a common format
- Opt-out: Unsubscribe from marketing communications
11. Cookies and Tracking
- We use essential cookies for authentication and security
- Session cookies to maintain your login state
- Preference cookies to remember your settings
- We do not use advertising or tracking cookies
12. International Users
Our services are hosted in the United States. If you are accessing from outside the US, please be aware that your information may be transferred to, stored, and processed in the US where our servers are located.
13. Children's Privacy
Our service is not intended for children under 13. We do not knowingly collect personal information from children under 13. If we become aware of such collection, we will delete the information immediately.
14. Changes to Privacy Policy
We may update this Privacy Policy periodically. Material changes will be communicated via email or through our service. Your continued use after changes constitutes acceptance.
15. Gmail & Google Drive Integration
Important: These optional Google integrations are used only to provide features you explicitly initiate. You can connect or disconnect them at any time in Account Settings.
Gmail — Sending Email
- What We Access: We request the send-only Gmail scope (
gmail.send). We do not request or use access to read, search, delete, or modify your inbox or any existing messages.
- How We Use It: When you compose and review a follow-up email inside REAP and tap Send, we send that single message from your Google account to the recipient you selected.
- User-Initiated Only: Email is sent only as a direct result of you pressing Send. REAP never sends email automatically, in the background, or in bulk.
- Content Handling: We do not retain the content of sent emails beyond what is needed to deliver the message and show you a record within the app. We never sell it or use it for advertising.
Google Drive — Attaching Files
- What We Access: We request the per-file Drive scope (
drive.file), which grants access only to the specific files you choose through Google's file picker. We cannot see or access any other files in your Drive.
- How We Use It: We store a link/reference to the files you select so you can attach them as resources to your projects and reopen them later.
- User-Initiated Only: We access a file only when you pick it. We do not scan, index, or read the rest of your Drive.
REAP's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. You may revoke REAP's access at any time from your Google Account permissions page.
16. Contact Us
If you have questions about this Privacy Policy or want to exercise your rights, please contact us: