How we look after your customers' data
Remindlo holds the names and phone numbers of the people you serve. This page sets out what we do to protect them, in plain terms. Every point describes how the system works today.
Last reviewed: 1 October 2026
Where your data lives
Hosted in the EU
Our database is hosted in Paris, inside the EU, and is encrypted at rest.
Encrypted in transit
The website, the dashboard, the API and the MCP server are only reachable over HTTPS (TLS).
Who else handles it
Phone numbers go to our SMS providers to deliver your messages, and some providers operate outside the UK and EEA under Standard Contractual Clauses. The full list is in our privacy policy.
Your data stays in your workspace
Enforced by the database
Every table holding customer data has row-level security, so the database itself only returns rows belonging to the workspace of the person signed in. It does not rely on the application remembering to filter.
Passwords
Passwords are stored only as a hash. We cannot read your password, and we never ask for it outside the sign-in page.
Card details
Payments are taken by Stripe. Your card number never reaches our servers.
Keys and connected accounts
API keys
A key is shown once, when you create it. We store only a SHA-256 hash of it, so a copy of our database would not reveal a working key. Revoking a key in the dashboard stops it immediately.
Calendar tokens
The tokens that let us read your Google or Outlook calendar are encrypted with AES-256-GCM before they are stored, with a key that is kept outside the database.
What we do with your calendar
Outlook access is read-only. With Google Calendar we read your events, and the only thing we ever write is a private, hidden note on an event, such as a phone number you typed in the add-on, so you are not asked for it twice. We never create, move or delete your appointments.
Connecting a calendar safely
Each connection request carries a single-use token tied to your signed-in account, so a link prepared by someone else cannot attach your calendar to their workspace.
Backups and recovery
Every night
The whole database is backed up nightly. A copy that is empty, incomplete or fails any of the checks below is never stored: the run stops and raises an alert, and the previous good copies stay in place.
Encrypted before it leaves
Backups are encrypted with a key our servers do not hold, so neither the backup storage nor our own build system can read them.
Stored with a different provider
Backups are kept in Western Europe with a different provider from the one that runs the database, and locked against deletion for 30 days, including by us.
Kept for a limited time
Daily copies are kept for 30 days and weekly copies for 90. Data you delete from Remindlo is gone from every backup within 90 days.
Every backup is restored before it is kept
A backup is only worth something if it restores. Each night, before the copy is stored, it is loaded into a separate, empty database and checked table by table against the original, and the encrypted file is opened again to prove it is intact.
Getting your messages delivered
Two SMS providers
We send through two independent SMS providers. If one cannot accept a message, it is handed to the other automatically, so one provider's outage does not stop your reminders.
Sent once
Each message is claimed before it is sent, so a retry or a duplicate request cannot text your customer twice.
Opt-outs respected
A customer who replies STOP is not messaged again unless they reply START. Messages from a sender name cannot be replied to, so those customers can ask you, or us, to remove them.
AI and your data
Not used for training
Where Remindlo uses AI, to read a photo of a paper diary, tidy up contact names from a calendar or suggest message wording, it runs on a paid AI service whose terms rule out using your data to train models. We send only what the task needs, never your contact list or message content.
Assistants you connect
If you connect ChatGPT, Claude or another assistant through our MCP server, you approve it on a consent screen, it gets its own key, and you can revoke it from the dashboard at any time.
Webhooks and monitoring
Signed webhooks
Webhooks we send carry an HMAC-SHA256 signature so your system can check they came from us, and we refuse to deliver them to private or internal network addresses.
Verified callbacks
Delivery receipts, replies and payment events from our SMS and payment providers are accepted only with a valid signature from the provider.
Error monitoring
We record browser errors with an error-monitoring service hosted in the EU. We do not record sessions or screens, and we strip query strings from every address before it is sent.
Reporting a security issue
If you think you have found a vulnerability, email security@remindlo.co.uk with enough detail for us to reproduce it. Please give us a reasonable chance to fix it before telling anyone else, and do not access, change or keep data that is not yours while testing.
For anything else about how we handle personal data, see our privacy policy and messaging policy.