Legal
Terms, Privacy & Security
reph is currently in pilot: a small, honest program for teams evaluating the product, not a mature commercial service. This page says plainly what that means, with no filler legalese.
§Terms of service (pilot)
- The service is provided as-is during the pilot program: no uptime guarantee, no SLA. We run it in good faith and fix things fast, but it's early.
- Your content remains yours. We claim no ownership over documents you create or upload; you can export or delete them at any time.
- We may contact you about the service: onboarding help, incident notices, or asking how the pilot is going.
- Either party can end the pilot at any time. If we do, you'll get advance notice and a chance to export your documents first.
§Privacy
What we store: your account email and display name, the documents and comments you create, and basic usage events (sign-ins, edits, API calls) needed to run and debug the service.
Where: on the operator's own server, the same one hosting this instance. There is no third-party data warehouse.
What we don't do: we don't sell or share your data, and we don't run third-party analytics or ad trackers on the app.
Performance measurements: so we can tell the difference between "reph is slow" and "this document has forty people in it", the app may send a small set of first-party performance numbers from your browser: how many people are editing a document at once, how many documents or comment threads a list is rendering, how long a document took to open, and how long the longest blocking task was. That is the complete list.
- It never includes document content, document titles, comment text, or file names. Document identifiers are one-way hashed before they leave the browser.
- It goes to the same server that hosts this instance. No third-party analytics provider is involved.
- It is sampled (a fraction of sessions), stored as daily totals rather than a per-event trail, and deleted after 120 days.
- An operator can switch it off entirely for a deployment.
Export and deletion: you can export everything we hold about you, and delete your account, yourself. Both are in the account menu, no request required. Export gives you a JSON file; deleting your account removes your profile, your personal documents, and your sessions, and anonymises your entries in the audit log. Documents owned by a workspace stay with that workspace, since they belong to the team rather than to you personally. Prefer that we do it? Contact us and we'll confirm once it's done.
§Payments
- Payment processor: paid plans, when available, are billed through Stripe. Card and payment details are entered on Stripe's own hosted Checkout and Customer Portal pages, and are handled by Stripe only. reph never receives, stores, or logs your card number, expiry, or CVC.
- Billing cadence: Pro is billed monthly, per purchased seat, at $5/seat/month. Invites are blocked once a workspace's seats are used; changing the number of purchased seats prorates the charge for the current billing period.
- Cancellation: cancel anytime from the billing portal. Your workspace keeps Pro access through the end of the current billing period; it does not stop immediately.
- Refunds: contact us via the support link; we handle refund requests case by case.
- Downgrades never delete data. If a workspace's Pro subscription ends or it downgrades to Free, seats fall back to the free tier's seat count and the workspace stops being covered by Pro's higher doc limits. Documents, members, comments, and version history are never deleted as a result of a billing change.
§Security
- Authentication: magic-link email or OAuth (Google/GitHub); sessions use short-lived JWTs with rotating refresh tokens, not long-lived passwords.
- AI keys: if your workspace stores a shared AI provider key, it's encrypted at rest (envelope encryption), never logged or shown back in full.
- Backups: the database is snapshotted on a rotating schedule so a hardware failure doesn't mean data loss.
- Responsible disclosure: found a security issue? Contact us with details; we'll respond and fix promptly rather than pursue anyone reporting in good faith.
§Contact & support
Questions, support requests, deletion requests, or security reports? contact us here.
reph: collaborative markdown for teams and agents. This page will grow into fuller terms as the product matures past pilot.