Privacy Policy
This policy describes how Reflect (“we”, “us”) processes data when operators (mobile app studios) integrate the Reflect SDK and use the Reflect dashboard. We act as a data processor — the operator is the controller of any end-user data passing through Reflect.
Release status (27 July 2026): the strict server-side 90-day click detach/delete, complete event-bag scrub, source-specific hourly jobs, and explicit email-webhook object sweep described below are locally verified release-candidate controls, not current production guarantees. Production is still at migration 138 of the 145-file release head. It currently guarantees 24-hour raw-click-IP truncation, but a referenced click may remain beyond 90 days until the ordered migration and backend rollout completes.
What we collect
From mobile end-users (via your SDK integration):
- Install identifiers (UUID generated client-side, GAID on Android, IDFA on iOS only when ATT consent is granted).
- Device metadata: OS version, country (from IP geolocation), language, model.
- Network and click context used for attribution and fraud prevention. Production keeps a click’s raw IP for at most 24 hours and then nulls it. After the pending strict-retention release, its coarsened subnet and other per-click context will reach their policy boundary at 90 days and be physically removed by the next successful hourly purge.
- App-defined events your SDK reports — event name, timestamps, optional revenue values, and bounded custom properties. The pending release recursively strips click-token and query-bearing link context from custom bags and omits those bags from long-lived archive copies.
- Deep-link and install-referral context. The pending mobile-core release keeps only a query-free route, a fixed direct/deferred source, and a reattribution flag in durable deep-link events. Raw install-referrer and Apple AdServices input is process-only for up to 30 seconds for an immediate online send; durable referral timestamps are reduced to a UTC-day bucket and custom/raw referral identifiers are discarded.
- The unpublished Web SDK candidate stores browser page/referrer context without query strings or fragments. Automatic campaign capture keeps only sanitized source, medium, and campaign values; click IDs, token-shaped values, and raw query parameters do not enter its durable outbox.
- One-way hashes (SHA-256) of email/phone for configured partner matching. After strict-retention activation, any raw values an operator deliberately places in app-defined event properties are stripped with the event’s free-form bags at the 90-day source boundary.
From operators: account email, company name, optional phone for billing, IP address of admin sessions for security.
What we do NOT collect
- Email or phone by default. If an operator deliberately includes those values in app-defined event properties, they are protected as event data and stripped no later than the 90-day raw-data boundary; matching integrations use hashes where supported.
- Precise location coordinates. We derive a coarse country from the request IP; IP handling follows the retention limits above.
- Cross-app tracking identifiers — every Reflect tenant is isolated.
Retention target after the pending strict release
- Events: every free-form referral, properties, device, partner-parameter, and callback-parameter bag will be removed after 90 days, even when its arbitrary contents cannot be classified. A fixed pseudonymous analytical shell may be retained for historical measurement until deletion or account closure.
- Attributions: the unique click identifier and click-to-install time will be removed when the source click expires. Historical reporting retains the partner, attribution type, attribution time, non-unique source-link configuration, and coarse acquisition country.
- SDK attribution cache: in the pending mobile-core release, a valid click ID may appear only in the current attribution callback. The cores do not persist that ID or its exact expiry; cache, getter, and restart replay retain only coarse partner/type/campaign.
- Browser outbox: in the unpublished Web SDK candidate, unacknowledged events expire at the strict 90-day boundary measured from the earlier of event time and local enqueue time. Exact-boundary, malformed, and older rows cannot be sent.
- Postback, CAPI & webhook delivery logs: 30 days. After activation, click-marked postback attempts will not persist the rendered partner URL, request body, or captured response.
- Clicks: raw IP is already limited to 24 hours. After activation, the full per-click record and context will reach its policy boundary at 90 days and be removed by the next successful hourly purge. Click-specific callback URLs and click-ID/external-ID/sub-parameter macros will stop at the strict boundary; Reflect will not start such a partner request without at least 30 seconds of remaining retention headroom. Campaign-only reporting can continue from the retained source link.
- AdServices, email-attribution, and self-attributing-network source records: after activation, exact source context and recipient-linked click/send records will be removed or detached at 90 days. Retained reporting keeps only reviewed coarse campaign/count dimensions and derived credit without the original recipient or source link.
- Billing records: 7 years (US/EU tax requirements).
If an operator exports data to its own warehouse, that operator controls the exported copy and is responsible for its downstream retention and deletion. New attribution exports omit the unique click_id, and every warehouse export uploads directly to that destination without creating a new Reflect-side staging copy.
Cloud object lifecycle timing is measured from object creation rather than an original click timestamp, and expiration is asynchronous. The pending release therefore adds an explicit source-age sweep for encrypted email-webhook staging plus durable exact-key cleanup markers when a request rollback cannot finish immediately. Those markers are tenant-prefixed and are removed with the tenant. Exhausted email delivery keeps the single tenant-prefixed encrypted stage instead of creating a second global archive, plus a tenant-scoped operator index only until the same source deadline; replay is refused after expiry. These controls remain a deployment gate, and lifecycle configuration alone is not proof of timely deletion. Those objects are not used to authorize an expired click callback or identifier. Restricted whole-database disaster-recovery backups and provider-managed restore history can remain available for up to 30 days and are used only for recovery. A restore stays isolated until retention rules and completed deletion requests have been reapplied; it cannot serve traffic or operator reads first. A longer legal hold requires a documented legal obligation and isolation from ordinary analytics or delivery.
End-user rights (GDPR / CCPA)
End-users contact the app operator directly. Operators have these endpoints in Reflect to satisfy user requests:
POST /privacy/delete— the SDK’s signed per-install deletion request.POST /admin/gdpr/delete— an authenticated operator deletion request.POST /admin/gdpr/export— an authenticated JSON export of the subject data Reflect still holds.
Sub-processors
- Reflect Infrastructure & Cloud Compute Subprocessors — Tier-1 global infrastructure providers adhering to ISO 27001, SOC 2 Type II, and strict international data protection standards.
- Resend — transactional email (login magic links, usage alerts).
- PayPal — subscription billing. Reflect never sees card details.
Where data lives
Reflect Edge Processing Nodes run at the closest geographic Point of Presence to the incoming request. Persistent storage clusters are configured with primary regions reflective of the operator's tenancy. Specific region commitments are in the DPA.
Security
- HMAC-SHA256 signing for signed SDK applications; explicitly configured legacy browser compatibility is isolated by app policy.
- AES-GCM at-rest encryption for partner credentials (CAPI tokens, OAuth refresh tokens).
- SHA-256 hashing of email/phone before postback transmission.
- TLS 1.2+ for every endpoint. HSTS preload on the marketing site.
Contact
[email protected] for privacy questions or to file a complaint with our DPO.