What we do with your data
Short version: we hold what the product needs to work and what an audit trail needs to be trustworthy, and nothing for advertising.
This policy is a working draft. It describes accurately what ReliFrame does with data today, but it has not been reviewed by a lawyer and is not a substitute for one. If you need a signed DPA or a policy your own counsel has approved, write to hello@reliframe.com.
Last updated 3 September 2026.
Who we are
ReliFrame is a reliability and safety engineering platform. This policy covers the website at reliframe.com. The application is not yet open to the public; when it launches this policy will name its address too.
What we collect
What you give us
- Your name and email address, when you create an account.
- Your password, stored only as an Argon2id hash. We never store or log the password itself.
- An avatar image, if you upload one.
- The engineering content you create: projects, analyses, components, hazards, failure modes and any files you attach.
What we record automatically
- Your IP address and browser user-agent, against sign-in attempts and against changes you make. This is what makes an audit trail an audit trail, and it is what lets us lock an account that is being attacked.
- The email address used in a sign-in attempt, successful or not, so that repeated failures can be rate-limited.
- Which actions you took, when, and under what role.
We do not use advertising trackers, and there is no analytics script on this site.
Why we hold it
To run the service you asked for, to keep your account secure, and — in the case of the audit trail — because engineering work that has to satisfy an assessor has to be attributable. If you are in the UK or EU, our basis is performance of a contract for the first, and legitimate interest in security and integrity for the second.
Who else sees it
We do not sell your data and we do not share it for advertising. We use these processors to run the service:
- Neon
- PostgreSQL database hosting. Your account and engineering content live here.
- Render
- Application server hosting.
- Cloudflare
- Website and application delivery.
- S3-compatible object storage
- Uploaded files and generated reports.
- Stripe
- Payments, for paid plans. Card details go to Stripe directly and never reach our servers.
- Resend
- Transactional email — verification, password resets and notifications. Marketing email is not sent from here.
Cookies
The application sets one cookie, reliframe_refresh. It holds your
session, is httpOnly so no script can read it, and is scoped to the
API path so it is not sent with ordinary page requests. It exists to keep you
signed in; there is no consent banner because there is nothing else to consent to.
How long we keep it
- Your account and content: for as long as your account exists.
- Audit records: retained as the record of what happened, and not edited after the fact.
- Sign-in attempt records: kept only as long as they are useful for rate limiting and lockout.
Ask us to delete your account and we will remove your personal data. Some audit entries reference the fact that an action occurred; where they must be kept, they are kept without identifying you.
Your rights
You can ask for a copy of your data, ask us to correct it, or ask us to delete it. Write to hello@reliframe.com and we will respond within 30 days. If you are in the UK or EU and are not satisfied, you can complain to your data protection authority.