Privacy Policy
Last updated: April 17, 2026
Introduction
Reproot ("we," "our," or "us") is a Beta platform for freelancer reviews and client feedback, operated by an independent developer based in the United States. This Privacy Policy explains how we collect, use, disclose, and protect your information when you use our platform.
By using Reproot, you agree to the data practices described in this policy. If you do not agree with our policies, please do not use the platform.
Beta Notice: Reproot is currently in Beta. Some features mentioned in this policy may be limited or planned for future updates. We're committed to transparency about our current capabilities.
TL;DR: We only collect the minimum info needed to run Reproot. No ads, no trackers, no selling your data. You can delete your account anytime.
Who We Are (Data Controller)
Reproot is operated by an individual developer. For privacy-related inquiries, please use our support chat in the bottom right corner.
Location: No physical office — Reproot is independently developed and operated remotely from the United States.
Information We Collect
Personal Information
We collect information you provide directly to us, including:
- Email address and password (for account creation)
- Basic profile information (name, username)
- Reviews and ratings you submit
- Communications with us (e.g., support requests, feedback)
- Account settings and preferences
- Email/password reset tokens
Automatically Collected Information
We automatically collect the following data when you use the platform:
- IP Address: For security/rate limiting
- Browser & Device Info: User Agent
- Session Data: JWTs, login/logout events
- Activity Logs: Review views, basic profile activity
- Performance Data: Load times, errors
- Security Events: Failed logins, suspicious behavior
How We Use Your Information
- Operate and maintain the platform
- Process and display public reviews and ratings
- Send verification and password reset emails
- Notify users of important service changes
- Apply basic content moderation
- Analyze basic engagement metrics
- Detect and prevent fraud, abuse, and attacks
- Respond to inquiries and support requests
- Comply with legal obligations
Legal Basis for Processing (GDPR)
We process your personal data based on your consent (when you sign up), contractual necessity (to provide the service), and legitimate interests (to secure and improve the platform).
Third-Party Services (Data Processors)
We use trusted service providers to operate the platform. These may process your data on our behalf:
- Vercel: Hosting and deployment
- Resend: Transactional emails (verification, reset)
- Zoho Mail: Customer support and email routing
- PostgreSQL: Database storage
- Cloudflare: DNS, security, performance optimization
We ensure these providers adhere to strong security and data protection standards.
Information Sharing
We do not sell, rent, or share your personal information with advertisers or unrelated third parties.
We may disclose data only in these situations:
- Public Content: Reviews you post (unless anonymous) are publicly viewable
- Email Delivery: With providers like Resend and Zoho
- Security Services: To detect fraud or platform abuse
- Legal Compliance: When required by law or court order
- Business Transfer: If Reproot is sold or merged
- With Consent: When you explicitly authorize it
Content Moderation and Security
We use basic automated methods to keep Reproot safe during the Beta phase:
- Basic Content Filtering: Detects spam and inappropriate content
- Rate Limiting: Prevents abuse and brute force attacks
- Monitoring: Suspicious behavior and failed logins
- Manual Review: Basic moderation of reported content
- Account Protection: Secure authentication and access control
Note: Advanced reporting tools and community moderation features are planned for future updates as the platform grows.
Data Security
We protect your data using industry-standard practices:
- End-to-end encryption (HTTPS)
- Secure password hashing (bcrypt)
- JWT authentication with expiration
- Role-based access and session validation
- Frequent updates and infrastructure hardening
- Input sanitization to prevent injection attacks
Your Rights
Depending on your location, you may have these rights:
- Access your data
- Correct inaccurate information
- Request deletion
- Export data (portability)
- Object to processing
- Withdraw consent at any time
- Post reviews anonymously
- Delete your account
- Use our support chat for any privacy concerns
To exercise your rights, please use our support chat in the bottom right corner.
Email Communications
We send emails only for service-related purposes:
- Email verification (signup)
- Password reset
- Account alerts or critical platform updates
- Security alerts (e.g., suspicious logins)
You will not receive marketing emails unless you opt-in.
Data Retention
We keep your data only as long as needed:
| Data Type | Retention |
|---|---|
| Account info | Until account deletion |
| Reviews/comments | Until you delete them or your account |
| Session data | 30 days for active sessions and refresh tokens |
| Email tokens | 24h (verification), 30m (password reset) |
| Access tokens | 30m |
| Security logs | 1 year for analysis |
We delete or anonymize your data when no longer needed.
International Transfers
Data may be processed outside your country (e.g., US servers).
We ensure adequate protections via:
- Standard contractual clauses
- Privacy-compliant service providers
- Legal safeguards required by law
Children's Privacy
Users must be at least 18 years old to create an account on Reproot.
We do not knowingly collect data from minors.
If you believe a child has used the platform, contact us immediately.
Changes to This Policy
We may update this policy when necessary.
You'll be notified via:
- Updates on the website
- Email (if material changes occur)
Continued use of the site means you accept the changes.
Contact Us
If you have any questions about this Privacy Policy or our data practices, we're here to help:
💬 Support Chat
For privacy concerns, use our support chat in the bottom right corner. We'll get back to you as soon as possible.
We'll respond to your privacy inquiry as quickly as we can, typically within 24 hours.
Related Documents
Please also review our Terms of Service which governs your use of Reproot.