PRIVACY POLICY Last updated on 18 September 2026 1. WHO IS RESPONSIBLE FOR YOUR DATA Tim Zierer, trading as Reelwire, Calle 47A x 47Y 100-1 #818, Fraccionamiento Las Americas 2, 97302 Merida, Yucatan, Mexico. Sole trader. Email: contact@reelwire.io Phone: +52 999 567 5838 This policy covers the Reelwire website, the Reelwire application, its API and its MCP server. Where this policy says "we" it means the sole trader named above. 2. WHAT WE COLLECT, AND WHY We collect the following and nothing else. Each entry says what it is for and how long it is kept. 2.1 Your account Your name, your email address and a one-way hash of your password. We never store the password itself and cannot recover it, which is why a reset replaces it rather than sending it to you. Kept while your workspace exists, and deleted with it. 2.2 Your workspace and its billing details The workspace name, the plan it is on, and the billing details you enter: company name, billing address, and a tax identifier where you give one. Billing details are frozen onto each invoice at the moment it is raised, because an invoice has to say what was true when it was issued rather than what is true today. Kept for as long as the law requires invoices to be kept, which is longer than the workspace itself. 2.3 Payment details Payments are processed by Stripe. Card numbers are entered on Stripe's own form and never reach our servers. We store what Stripe reports back about the card: its brand, its last four digits and its expiry, so you can tell which card is on file. Kept while a payment method is on file. 2.4 What you put into the product Media you upload, posts you write, brands you configure, the data you send over the API, and the clips Reelwire renders from all of it. This is your content. We process it to run the service you asked for and for nothing else. We do not read it, mine it, sell it, or use it to train anything. Kept while your workspace exists, subject to the storage your plan includes. Rendered clips are removed as the retention on your plan expires. 2.5 Credentials for the platforms you publish to The tokens that let Reelwire post to your own accounts. They are encrypted at rest and are used for one purpose: publishing what you told us to publish. Kept until you disconnect that channel, and destroyed immediately when you do. 2.6 Records of what the system did Request logs, delivery records, render records and sign-in events, each with a timestamp and the IP address the request came from. These exist so that a failed post can be explained, a bill can be justified, and abuse can be investigated. They are not used to build a profile of you. Kept for as long as they are useful for those purposes, and routinely pruned. 2.7 Email we send you Verification letters, password resets, invoices and, where a plan includes it, notices about posts awaiting approval. We record that a message was sent and whether it was accepted for delivery. 3. WHAT WE DO NOT DO We do not run advertising, and we carry no advertising trackers anywhere. We do not sell personal data, and we do not share it for anyone else's marketing. We do not use your content to train machine-learning models, ours or anybody else's. 4. COOKIES AND LOCAL STORAGE 4.1 On the marketing website When you first arrive we ask you what we may set. Until you answer, we set nothing. Necessary. One cookie recording the answer you gave, kept for a year. Without it we would have to ask again on every page, which is not a question, it is pressure. Analytics. If you agree, we load Google Analytics, which sets cookies that let us see which pages are read and for how long. If you decline, no Google Analytics script is loaded at all: it is not loaded first and disabled afterwards. You can change your mind by clearing this site's cookies, which brings the question back. Separately from cookies, your browser remembers whether you chose the light or the dark theme. That never leaves your browser. 4.2 In the application One session cookie when you sign in. It is what keeps you signed in, it is not used for tracking, and it ends when the session does. 4.3 reCAPTCHA The sign-in screen and the forms on this website are protected by Google reCAPTCHA v3, which tells us whether a submission came from a person or from a script. To do that, Google's script collects information about the device and the browser and how it is being used, and may set cookies of its own, under Google's privacy policy and terms: https://policies.google.com/privacy https://policies.google.com/terms This is not optional and is not covered by the choice above, because it is not measurement: it is what stops an automated attack on your account and on our mailbox. The legal basis is our legitimate interest in keeping the service secure and usable. We receive a score, not a profile, and we use it for nothing else. 5. WHO ELSE PROCESSES IT We use a small number of processors, each for one job: - Stripe, for payments, subscriptions and invoices. - Our email provider, for sending the letters listed in 2.7. - Our hosting provider, on whose infrastructure the service runs. - Google, for reCAPTCHA on the sign-in screen and the website's forms, and, only if you agreed to it, for Google Analytics on the website. See 4.1 and 4.3. - The social platforms you connect, which receive exactly what you publish to them and are then governed by their own terms and their own privacy policies. Some of these operate outside your country. Where personal data is transferred, it is transferred under the safeguards that provider offers for international transfers. 6. LEGAL BASES Where the GDPR applies to you: - Running the service, billing you for it and supporting you: performance of a contract. - Keeping invoices and tax records: a legal obligation. - Security, fraud prevention and abuse investigation: our legitimate interests. - Anything you opt into separately: your consent, which you can withdraw at any time. 7. YOUR RIGHTS You may ask us to give you a copy of your personal data, correct it, delete it, restrict what we do with it, or hand it to somebody else in a portable form. You may object to processing we base on legitimate interests. Where processing rests on consent, you may withdraw it. Write to contact@reelwire.io. We answer within 30 days. If you are in the EU or the UK and you are not satisfied with the answer, you may complain to your national supervisory authority. 8. SECURITY Traffic is encrypted in transit. Platform credentials are encrypted at rest. API keys are stored as hashes and shown once, at the moment they are created, which is why we cannot tell you an existing key's value. Access to production data is limited to the people who need it to operate the service. No system is perfect. If a breach affects your personal data, we will tell you and the relevant authority as the law requires. 9. CHILDREN Reelwire is a business product and is not directed at children. We do not knowingly collect data from anyone under 16. 10. CHANGES We will post any change here and move the date at the top. Where a change is material, we will tell account holders by email rather than relying on you to notice. 11. CONTACT contact@reelwire.io, or the postal address in section 1.