Security

    How we look after your customers' data

    Remindlo holds the names and phone numbers of the people you serve. This page sets out what we do to protect them, in plain terms. Every point describes how the system works today.

    Last reviewed: 1 October 2026

    Where your data lives

    Hosted in the EU

    Our database is hosted in Paris, inside the EU, and is encrypted at rest.

    Encrypted in transit

    The website, the dashboard, the API and the MCP server are only reachable over HTTPS (TLS).

    Who else handles it

    Phone numbers go to our SMS providers to deliver your messages, and some providers operate outside the UK and EEA under Standard Contractual Clauses. The full list is in our privacy policy.

    Your data stays in your workspace

    Enforced by the database

    Every table holding customer data has row-level security, so the database itself only returns rows belonging to the workspace of the person signed in. It does not rely on the application remembering to filter.

    Passwords

    Passwords are stored only as a hash. We cannot read your password, and we never ask for it outside the sign-in page.

    Card details

    Payments are taken by Stripe. Your card number never reaches our servers.

    Keys and connected accounts

    API keys

    A key is shown once, when you create it. We store only a SHA-256 hash of it, so a copy of our database would not reveal a working key. Revoking a key in the dashboard stops it immediately.

    Calendar tokens

    The tokens that let us read your Google or Outlook calendar are encrypted with AES-256-GCM before they are stored, with a key that is kept outside the database.

    What we do with your calendar

    Outlook access is read-only. With Google Calendar we read your events, and the only thing we ever write is a private, hidden note on an event, such as a phone number you typed in the add-on, so you are not asked for it twice. We never create, move or delete your appointments.

    Connecting a calendar safely

    Each connection request carries a single-use token tied to your signed-in account, so a link prepared by someone else cannot attach your calendar to their workspace.

    Backups and recovery

    Every night

    The whole database is backed up nightly. A copy that is empty, incomplete or fails any of the checks below is never stored: the run stops and raises an alert, and the previous good copies stay in place.

    Encrypted before it leaves

    Backups are encrypted with a key our servers do not hold, so neither the backup storage nor our own build system can read them.

    Stored with a different provider

    Backups are kept in Western Europe with a different provider from the one that runs the database, and locked against deletion for 30 days, including by us.

    Kept for a limited time

    Daily copies are kept for 30 days and weekly copies for 90. Data you delete from Remindlo is gone from every backup within 90 days.

    Every backup is restored before it is kept

    A backup is only worth something if it restores. Each night, before the copy is stored, it is loaded into a separate, empty database and checked table by table against the original, and the encrypted file is opened again to prove it is intact.

    Getting your messages delivered

    Two SMS providers

    We send through two independent SMS providers. If one cannot accept a message, it is handed to the other automatically, so one provider's outage does not stop your reminders.

    Sent once

    Each message is claimed before it is sent, so a retry or a duplicate request cannot text your customer twice.

    Opt-outs respected

    A customer who replies STOP is not messaged again unless they reply START. Messages from a sender name cannot be replied to, so those customers can ask you, or us, to remove them.

    AI and your data

    Not used for training

    Where Remindlo uses AI, to read a photo of a paper diary, tidy up contact names from a calendar or suggest message wording, it runs on a paid AI service whose terms rule out using your data to train models. We send only what the task needs, never your contact list or message content.

    Assistants you connect

    If you connect ChatGPT, Claude or another assistant through our MCP server, you approve it on a consent screen, it gets its own key, and you can revoke it from the dashboard at any time.

    Webhooks and monitoring

    Signed webhooks

    Webhooks we send carry an HMAC-SHA256 signature so your system can check they came from us, and we refuse to deliver them to private or internal network addresses.

    Verified callbacks

    Delivery receipts, replies and payment events from our SMS and payment providers are accepted only with a valid signature from the provider.

    Error monitoring

    We record browser errors with an error-monitoring service hosted in the EU. We do not record sessions or screens, and we strip query strings from every address before it is sent.

    Reporting a security issue

    If you think you have found a vulnerability, email security@remindlo.co.uk with enough detail for us to reproduce it. Please give us a reasonable chance to fix it before telling anyone else, and do not access, change or keep data that is not yours while testing.

    For anything else about how we handle personal data, see our privacy policy and messaging policy.