Privacy
This product reads your meeting transcripts. You should know exactly where they go, what law governs that, and what say you have over it.
Last updated 5 August 2026
Who runs this, and who this policy covers
Reqorra is run by an individual developer, not a company, and is in early access. For the purposes of the laws referenced below, that developer is the data controller (GDPR/UK GDPR), business (CCPA/CPRA), organisation (PIPEDA), APP entity (Australia), or data fiduciary (India’s DPDP Act) responsible for your data. Questions about anything on this page, or a request to exercise any right described here, go to info@reqorra.com. This is also the single point of contact for data protection authorities, and we will not ask you to prove your identity beyond what is reasonably needed to confirm the request is yours.
This policy applies wherever you access Reqorra from. It is written to meet the disclosure requirements of the EU/UK GDPR, the California Consumer Privacy Act as amended by the CPRA and the comparable laws of other US states, Canada’s PIPEDA, Australia’s Privacy Act, Brazil’s LGPD, Japan’s APPI, Singapore’s PDPA, South Korea’s PIPA, and India’s DPDP Act, among others. Where a right below is granted by one of these laws rather than universally, it says so.
What we collect
What you paste or upload. Meeting transcripts, project names, and anything you type into a requirement, risk, stakeholder or document. This is the substance of the product; there is no version of it that works without holding this text. If a transcript you paste contains other people’s personal data — names, roles, opinions attributed to them — we process that data too, on your instructions, exactly as described in this policy.
What we generate from it. Requirements, user stories, acceptance criteria, test cases, documents, review findings and the change history that connects them.
Your account. Your email address and a password hash, both held by our authentication provider. We never see your password.
Technical data. Server logs generated by the hosting and database providers as an ordinary part of running the service — IP address, timestamp, and request path — kept only as long as those providers retain operational logs, and used solely to run and secure the service, never to profile you.
What we do not collect. No analytics or tracking scripts, no advertising identifiers, no third-party cookies, and no cross-site or cross-device tracking. The only cookies set are strictly necessary ones that keep you signed in — there is nothing to consent to under the EU’s ePrivacy rules or similar cookie-consent laws, because nothing non-essential is set.
Children. Reqorra is not directed at children and is not knowingly used by anyone under 16. We do not knowingly collect personal data from children. If you believe a child has created an account, contact us and it will be deleted.
Why we process it, and on what legal basis
Under GDPR/UK GDPR, each use of your data rests on one of these bases:
- Contract (Art. 6(1)(b)). Storing and processing what you paste or upload, generating requirements/stories/documents from it, and running your account — this is the service you asked for.
- Legitimate interests (Art. 6(1)(f)). Keeping the technical logs needed to run, secure and debug the service, weighed against your privacy and kept to the minimum needed.
- Consent (Art. 6(1)(a)). Anonymous/free-tool use before you have an account, where holding your output for seven days so you can claim it is something you actively start by using the tool, and can end at any time by not claiming it.
- Legal obligation (Art. 6(1)(c)). Where a law requires us to keep or disclose specific records.
We do not use profiling or automated decision-making that produces legal or similarly significant effects about you (GDPR Art. 22), and we do not use your data for any purpose beyond running the product you asked for — no marketing profiling, no data broker sale, no ad targeting.
Where it goes — our subprocessors
Your text is stored in a Postgres database hosted by Supabase, and the application runs on Vercel.
To generate anything, the relevant text is sent to Anthropic (Claude), which processes it and returns a result. Where a fallback provider is configured, that traffic may instead route through OpenRouter to the same class of model. Only the text needed for the request is sent — a transcript for extraction, or the requirements involved for a review pass.
Account emails — password resets and email-change confirmations — are delivered by Resend.
Those four are the complete list of subprocessors: Supabase, Vercel, Anthropic (and OpenRouter as fallback), and Resend. Each acts as a data processor on our instructions, is bound by its own data processing agreement, and is contractually prohibited from using your content for its own purposes. None of them is paid for or given access to your data in exchange for anything beyond the fee for running the service. We do not sell personal data and have not sold personal data in the preceding twelve months, and we do not share personal data for cross-context behavioural advertising — so there is nothing for a “Do Not Sell or Share My Personal Information” link to switch off, and no financial incentive program under the CCPA/CPRA to disclose.
International transfers
Our subprocessors operate infrastructure in the United States and, for some Supabase projects, the EU. If you are in the EEA, UK, Switzerland, or another jurisdiction with its own data-transfer restrictions (Brazil’s LGPD, South Korea’s PIPA, China’s PIPL among them) and your data is processed in the US, that transfer relies on the safeguards each subprocessor has in place — Standard Contractual Clauses and, where applicable, the EU-U.S. and Swiss-U.S. Data Privacy Frameworks that Vercel, Supabase, Anthropic and Resend each participate in or contractually equal. We do not operate our own infrastructure in China and do not store data there; if that changes, this section will be updated before it does.
Training
Your content is not used to train any model, by us or, under the commercial API terms these services are used through, by the model providers. It is sent to generate your output and for no other purpose.
How long we keep it
Project data is kept until you delete it. Deleting a project removes everything inside it — meetings, transcripts, requirements, documents, history — immediately and permanently. Deleting your account removes every project you own the same way.
Output generated before you signed up, from the free tools, is held for seven days so you can claim it into a project, then deleted automatically.
There is no backup from which deleted content can be restored. Deletion means deletion. This is also how we meet storage-limitation obligations under GDPR Art. 5(1)(e) and equivalents elsewhere: we hold nothing longer than the purpose it was collected for requires, and the purpose ends the moment you delete it.
Your rights
From your account page you can, without needing to ask us: download everything you have put in as a single JSON file, change your email or password, and delete your account outright. That covers access, portability, correction and erasure end to end, self-serve, for every user regardless of location.
If you would rather ask us directly, or your jurisdiction gives you a right this page hasn’t named, write to info@reqorra.com. We respond to every request personally — there is no ticket queue — and aim to act within 30 days (the GDPR/UK GDPR and CCPA/CPRA statutory windows), or 45 days under India’s DPDP Act grievance timeline, whichever applies to you. Depending on where you are, this can include:
- Access, correction, deletion and portability — EU/UK GDPR, CCPA/CPRA and the other US state laws, Canada’s PIPEDA, Australia’s Privacy Act, Brazil’s LGPD, Japan’s APPI, Singapore’s PDPA, South Korea’s PIPA, and India’s DPDP Act all grant some version of these — self-serve on the account page, or by request.
- Restriction and objection to processing (GDPR Arts. 18 & 21) — tell us and we will stop, subject to explaining if a legal reason means we can’t.
- Withdraw consent at any time, where consent is the basis (GDPR Art. 7(3)), without affecting anything already done.
- Non-discrimination (CCPA/CPRA) — exercising any right never changes your price or your access to the service. Paid plans differ from the free one only in the usage limits published on the pricing page, never in how anyone’s data is treated or in what rights they have over it.
- Right to grievance redressal and to nominate (India’s DPDP Act) — the contact above is also our grievance officer contact, and you may nominate another individual to exercise your rights on your death or incapacity by writing to us.
- Lodge a complaint with your local supervisory authority — your EU/UK/EEA data protection authority, your US state attorney general, the OAIC in Australia, the ANPD in Brazil, or the equivalent body where you live — at any time, independent of contacting us first.
Security, stated plainly
Traffic is encrypted in transit, data is encrypted at rest by the hosting providers, and every database table enforces row-level access so one account cannot read another’s project.
What this is not: Reqorra has no SOC 2 report, no penetration test on file, and no formal incident-response commitment. It is an early-access product run by one person. If your transcripts contain material your organisation would treat as regulated or highly confidential, that is a real consideration — decide accordingly.
If a breach occurs that creates a real risk to your rights and freedoms, we will notify the relevant supervisory authority and affected users without undue delay, in line with GDPR Art. 33/34 and equivalent breach-notification duties elsewhere — including, where applicable, India’s DPDP Act and US state breach-notification statutes.
Changes
If this policy changes in a way that affects what happens to your data, the date at the top changes and material changes will be noted here. Where a change requires your consent under an applicable law, we will ask for it before it takes effect.