Legal

Privacy Policy for ReFrame (US / California Edition)

1. Introduction

Welcome to ReFrame. This Privacy Policy explains how we collect, use, disclose, retain, and protect information when you use our website or mobile application. ReFrame helps users practice and reflect on workplace conversations using personalized scenarios, coaching feedback, and AI-supported debriefs.

We aim to be clear about what the app actually does: ReFrame does not record live meetings, does not sell personal information, and does not use advertising trackers. The app does store profile information, practice and reflection content, usage telemetry, and certain AI-generated outputs so that the product can function, improve, and support users.

2. Information We Collect

Under the CCPA/CPRA, we may collect the following categories of personal information.

Identifiers and Account Data

We collect information such as your name, preferred name, email address, account ID, authentication status, and legal consent timestamps/version records. If you create or update a password, that password is handled through Supabase authentication. ReFrame does not store your raw password in our application database.

Account login credentials, when combined with a password or equivalent authentication token, may be considered Sensitive Personal Information under CPRA.

Profile and Professional Context

We collect profile information used to personalize your experience, including industry, business or academic domain where applicable, job function, experience level, student internship status, and people-manager status.

Demographic and Cultural Tuning Preferences

You may choose to provide gender and cultural-context preferences, including whether you identify as underrepresented by gender or ethnicity in your field. These fields are used to tune coaching and scenario generation. They may be considered sensitive or demographic information depending on context.

User-Generated Practice and Reflection Content

We collect content you provide while using ReFrame, including:

Because these fields are free text, you may choose to include sensitive personal information, such as health information, workplace conflict details, race or ethnicity, disability, family status, or other personal experiences. Please avoid entering information you do not want processed by ReFrame or its service providers.

AI-Generated and Derived Content

ReFrame stores certain AI-generated or derived content, including coaching feedback, evaluation results, scenario metadata, reflection summaries, recommended practice skills, and internal progress or skill metrics. These outputs are used to provide the service, support product quality, and improve ReFrame.

Internet, Device, and Usage Activity

We collect usage and diagnostic information such as event type, page path, session ID, event metadata, timestamps, heartbeat activity, session duration, client platform, timezone header, browser user agent for web session starts, and certain operational request metadata such as IP address for rate limiting and security.

3. How We Use Your Information

We use your information to:

4. AI Processing and OpenAI Usage

ReFrame uses OpenAI to power AI-supported coaching, scenario generation, response evaluation, session summaries, and reflection/debrief conversations.

Depending on the feature, ReFrame may send OpenAI your profile context, practice responses, reflection conversation history, scenario context, prompts, and related metadata needed to generate the requested feature.

OpenAI acts as a service provider/subprocessor for these AI features. OpenAI does not use ReFrame API data to train its models by default. Some ReFrame AI calls use one-time Responses API requests with storage disabled where supported. Other flows use OpenAI Conversation objects so that multi-turn context can persist during a session. When you delete your account, ReFrame attempts to delete associated OpenAI Conversation objects and legacy thread objects. If an OpenAI deletion attempt fails, ReFrame logs the failure and retains an internal marker so the deletion can be retried.

5. Sharing with Third-Party Service Providers

We do not sell your personal information. We share information with service providers only as needed to operate ReFrame.

Current service providers include:

These providers process information according to their own security, retention, and service-provider terms.

6. Local Storage, Cookies, and On-Device Storage

ReFrame uses browser and mobile storage to keep the app functional.

On web, we use localStorage and sessionStorage for authentication tokens, session tracking, app session data, temporary feedback drafts, local feedback records, UI preferences, and admin interface preferences where applicable. We also use a small UI preference cookie for sidebar state.

On mobile, we store authentication tokens using Expo SecureStore where available, with AsyncStorage used for fallback or legacy migration. Mobile may also store app preferences such as theme mode and runtime binding information.

7. Internal Admin Access

Authorized ReFrame administrative personnel may access backend admin tools to maintain the service, provide support, monitor product health, review feedback, and improve the product.

Admin-accessible data may include user profiles, account metadata, telemetry events, session heartbeats, practice sessions, practice attempts, feedback records, skill/progress metrics, OpenAI operational logs, and user detail views. Admin access is server-enforced and limited to configured authorized users.

8. Your Privacy Rights, Including California CCPA/CPRA Rights

If you are a California resident, you may have the following rights.

Right to Know and Access

You may request information about the categories and specific pieces of personal information we collect, use, disclose, and retain.

ReFrame also provides an in-app data export. The current automated export includes your profile information and the personal text you provided during completed Challenge and Deconstruct sessions. It does not include every operational record, telemetry event, OpenAI call log, internal analytics record, AI-generated evaluation, AI-generated coaching output, or admin-only metric.

You may contact us to request additional information.

Right to Delete

You may delete your account through the app.

When you delete your account, ReFrame deletes your authentication user and profile record, redacts or removes user-typed personal content from certain session records, anonymizes feedback records, and attempts to delete associated OpenAI Conversation or legacy thread data.

Some records are retained in anonymized or de-identified form for analytics, product integrity, service improvement, security, and operational purposes. Retained records may include session metadata, AI-generated content, internal metrics, OpenAI operational logs, event telemetry, and aggregate reporting data after the direct identity link has been removed.

Right to Correct

You may update profile information in the app settings where the app allows editing. You may contact us for help correcting information that cannot be edited directly in the app.

Right to Limit Use of Sensitive Personal Information

You may request that we limit the use of Sensitive Personal Information to what is necessary to provide ReFrame, maintain security, and operate the service.

Right to Non-Discrimination

We will not discriminate against you for exercising your privacy rights.

9. Data Retention

We retain personal information only as long as reasonably necessary for the purposes described in this policy, unless a longer period is required or permitted by law, security needs, dispute resolution, backup retention, or legitimate operational requirements.

Account deletion removes or anonymizes personal information as described above. ReFrame may retain de-identified, anonymized, aggregate, operational, or AI-generated records for product improvement, analytics, security, auditability, and service operations.

We do not currently represent that inactive accounts are automatically purged after a fixed number of days unless and until such a purge process is implemented.

10. Contact Us

If you have questions or wish to exercise your privacy rights, contact us at:

info@humanize-consultancy.com