Reflect
AboutPrivacyTermsDPA

Privacy Policy

Last updated: 2026-07-27

This policy describes how Reflect (“we”, “us”) processes data when operators (mobile app studios) integrate the Reflect SDK and use the Reflect dashboard. We act as a data processor — the operator is the controller of any end-user data passing through Reflect.

Release status (27 July 2026): the strict server-side 90-day click detach/delete, complete event-bag scrub, source-specific hourly jobs, and explicit email-webhook object sweep described below are locally verified release-candidate controls, not current production guarantees. Production is still at migration 138 of the 145-file release head. It currently guarantees 24-hour raw-click-IP truncation, but a referenced click may remain beyond 90 days until the ordered migration and backend rollout completes.

What we collect

From mobile end-users (via your SDK integration):

From operators: account email, company name, optional phone for billing, IP address of admin sessions for security.

What we do NOT collect

Retention target after the pending strict release

If an operator exports data to its own warehouse, that operator controls the exported copy and is responsible for its downstream retention and deletion. New attribution exports omit the unique click_id, and every warehouse export uploads directly to that destination without creating a new Reflect-side staging copy.

Cloud object lifecycle timing is measured from object creation rather than an original click timestamp, and expiration is asynchronous. The pending release therefore adds an explicit source-age sweep for encrypted email-webhook staging plus durable exact-key cleanup markers when a request rollback cannot finish immediately. Those markers are tenant-prefixed and are removed with the tenant. Exhausted email delivery keeps the single tenant-prefixed encrypted stage instead of creating a second global archive, plus a tenant-scoped operator index only until the same source deadline; replay is refused after expiry. These controls remain a deployment gate, and lifecycle configuration alone is not proof of timely deletion. Those objects are not used to authorize an expired click callback or identifier. Restricted whole-database disaster-recovery backups and provider-managed restore history can remain available for up to 30 days and are used only for recovery. A restore stays isolated until retention rules and completed deletion requests have been reapplied; it cannot serve traffic or operator reads first. A longer legal hold requires a documented legal obligation and isolation from ordinary analytics or delivery.

End-user rights (GDPR / CCPA)

End-users contact the app operator directly. Operators have these endpoints in Reflect to satisfy user requests:

Sub-processors

Where data lives

Reflect Edge Processing Nodes run at the closest geographic Point of Presence to the incoming request. Persistent storage clusters are configured with primary regions reflective of the operator's tenancy. Specific region commitments are in the DPA.

Security

Contact

[email protected] for privacy questions or to file a complaint with our DPO.

Questions? Email [email protected]. A Retroage Engineering product.