Remi — Privacy Policy
Version 1.0 · Last updated 15 July 2026
1. The short version
We know nobody reads privacy policies. Here is the honest summary. The detail follows, and the detail governs.
| Question | Answer |
|---|---|
| Who are we? | Remi is a service operated by EZ Lab Private Limited, a company incorporated in India ("Remi", "we", "us"). |
| What is Remi? | A private, AI-led reflection conversation about your professional life, which produces a Professional Passport — a reflection of how you work. It is not therapy, not medical care, not an assessment, and not a performance evaluation. |
| Does my employer see my conversation? | No. Not your transcript, not your Passport, not your individual answers — not with your name on them, not without. There is no path in the product for them to get it, and our contract with them forbids it. This is the central commitment of this policy. |
| Can anyone at Remi see my conversation? | Yes, technically — a small number of authorised staff can, under strict controls, for the limited purposes listed in section 8. We'd rather tell you that than claim an impossibility we haven't built. See section 8. |
| Is my conversation used to train AI models? | No. Our AI provider is contractually prohibited from training on it, and does not retain it by default. See section 11. |
| Where does my data go? | Remi runs in India — stored in Mumbai, servers in Mumbai. The one exception: your conversation goes to our AI provider in the US to generate replies. See sections 9 and 15. |
| Can I delete it? | Yes, all of it, at any time. See section 13. |
| Who do I complain to? | Our Grievance Officer (section 17), and then the Data Protection Board of India. |
| Is Remi available outside India? | No. Remi is offered in India only. See section 2. |
2. Scope of this policy
This policy applies to:
- The Remi web application at myremi.co and any subdomains
- Remi conversations and the Professional Passport
- Remi sessions delivered at or for an organisation ("Organisation Sessions")
- Remi free and paid individual accounts, including remi+ (our paid subscription) and LinkedIn enhancer (a separate optional add-on)
- Our marketing site, emails, and support channels
This policy does not apply to third-party services you reach from Remi (for example LinkedIn), which have their own policies.
Where Remi is offered. Remi is offered in India only, to people in India. We do not target, market, or offer the Service to individuals in the European Economic Area, the United Kingdom, or elsewhere, and this policy is written to India's legal framework. If you are outside India, please do not use Remi.
3. Who we are, and — importantly — in what capacity
Remi is an independent Data Fiduciary. Under India's Digital Personal Data Protection Act, 2023 ("DPDP Act"), the entity that determines the purpose and means of processing your personal data is the "Data Fiduciary", and that entity is us — EZ Lab Private Limited.
This matters more than it sounds, so we will be explicit:
When your employer pays for a Remi session, they are not our client in respect of your personal data. You are. We do not process your conversation on your employer's instructions. Your employer cannot instruct us to disclose it, cannot request access to it, and has no contractual right to it. We are not your employer's data processor, vendor-of-record, or agent for your personal data. Our duties in respect of your conversation run to you.
What your employer is our client for: the facilitation of the session and the delivery of an aggregate, non-attributable organisational report (section 7).
If you are reading this from an organisation considering purchasing Remi: this structure is not negotiable. It is the reason the product works.
Our details:
| Legal entity | EZ Lab Private Limited |
| Entity type | a private limited company incorporated in India |
| CIN / LLPIN | U74999HR2019PTC082899 |
| Registered address | 5122, 12th Floor, Tower No. 05, ATS Kocoon, Sector 109, Gurgaon, Haryana 122006, India |
| hello@myremi.co | |
| Grievance Officer | See section 17 |
4. Who this policy is for
Remi is built for working professionals aged 18 and over.
Remi is not for children. Under the DPDP Act, a "child" in India is anyone under 18 years of age — a higher threshold than in many other countries. We do not knowingly collect personal data from anyone under 18, we do not offer Remi to under-18s, and we do not undertake tracking or behavioural monitoring of, or targeted advertising directed at, children. If we learn that a user is under 18, we will delete the account and associated data. If you believe a person under 18 has used Remi, contact the Grievance Officer immediately.
We also do not knowingly process the data of persons with a lawful guardian in a manner requiring guardian consent under the DPDP Act. If this applies to you, contact us before using Remi.
5. What we collect
5.1 Information you give us directly
| Category | Examples | Where it comes from |
|---|---|---|
| Identity & account | Name, email address, password or SSO identifier | You, at sign-up |
| LinkedIn SSO data (if you sign in with LinkedIn) | Your LinkedIn ID, name, email, profile photo, headline, and any other fields covered by the permissions you approve at the consent screen | LinkedIn, with your authorisation |
| Professional context | Your role/job title, your employer or organisation, tenure, function | You, or the Organisation roster (see 5.4) |
| Conversation content | Everything you type or say to Remi during a session, in free text | You |
| Feedback | Ratings of how the session felt, how the conversation went, how useful the insight was, whether you'd return, and free-text comments on what was best and what could be better | You, at the end of a session |
| Support & correspondence | Emails, support tickets, bug reports | You |
| Payment information | For paid plans: billing name, address, GSTIN (if applicable), and transaction records. We do not collect or store your full card number, CVV, or UPI credentials — these go directly to our payment gateway. | You, via our payment gateway |
5.2 The conversation, specifically — please read this
Remi is an open-ended conversation. You control what you put into it. Because it is free text, it may end up containing categories of information we did not ask for and do not need, including:
- Information about how you feel — including stress, burnout, anxiety, or distress
- Information about your health or mental health
- Information about your colleagues, your manager, or other identifiable people
- Information about your employer's confidential business matters
- Information about your personal life, family, finances, or beliefs
Some of this may qualify as "sensitive personal data or information" (SPDI) under the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 — which expressly include mental health condition.
Two things follow from this:
- Please do not share more than you need to. Remi does not need your medical history, your colleagues' names, or your employer's trade secrets to be useful to you. It works on how you work.
- Where you do share it, you are consenting to us processing it for the purposes in section 6. You can withdraw that consent and delete the conversation at any time (section 13).
5.3 Information Remi infers or derives
This is a profiling activity and we want to name it plainly. From your conversation, Remi derives:
| Derived output | What it is |
|---|---|
| Professional Passport | A reflective summary of how you work — your communication tendencies, decision-making style, collaboration patterns, what energises and drains you, and blind spots to consider |
| Work Twin | A characterisation of your working style expressed through Remi's reflection library |
| Progressive insight layers | Additional reflections that build as you have more conversations over time (for example, role fit reflections, strengths for a next role, longer-term patterns) |
| Fit Score (remi+) | A live reflection on how your working style relates to your current role and your trajectory — updated as you have more conversations, framed as how to thrive where you are |
| LinkedIn Activator (remi+) | Helps you write LinkedIn posts grounded in how you actually talk |
| LinkedIn summary card | A shareable graphic summarising your Passport, generated for you |
These are reflections, not measurements. They are not clinical assessments, not psychometric tests, not validated instruments, and not predictions of your performance or potential. They are Remi's structured read of what you told it. They can be wrong. They are not a verdict on you, and nobody should treat them as one — including you. See section 11 for more on the limits of AI output.
5.4 Information your Organisation gives us
If you take part in an Organisation Session, your employer may provide us with a participant roster containing: your name, work email address, job title/role, team or function, and session logistics.
We use this only to invite you, authenticate you, and run the session. We do not send it back to your employer enriched, annotated, or joined to anything you said.
5.5 Information we collect automatically
| Category | Examples | Purpose |
|---|---|---|
| Technical/device | IP address, browser type and version, device type, operating system, language, screen size | Security, fraud prevention, debugging, compatibility |
| Usage | Pages viewed, features used, session start/end times, message counts, timestamps | Product improvement, reliability |
| Logs | Server logs, error traces, API request metadata | Security, incident response, and to meet the log-retention obligation described in section 12 |
| Cookies & similar | See section 16 |
6. Why we process your data, and on what legal basis
Under the DPDP Act, we process personal data on the basis of your consent, except in the narrow circumstances the Act designates as "certain legitimate uses" (for example, where you have voluntarily provided data for a specified purpose, or where processing is required to comply with a legal obligation or a court order).
| Purpose | What we do | Basis |
|---|---|---|
| Deliver the conversation | Send your messages to our AI provider and return Remi's replies | Consent |
| Generate your Passport and insights | Derive reflections from your conversation | Consent |
| Remember you between sessions | Store your conversations so Remi's reflections deepen over time | Consent |
| Produce aggregate Organisation reports | Aggregate patterns across a cohort, subject to the safeguards in section 7 | Consent |
| Account, authentication, support | Run your account, answer your questions | Consent / legitimate use |
| Safety response | Recognise signals of serious distress and surface support resources (section 10) | Consent |
| Security, fraud, abuse prevention | Detect and stop misuse | Legitimate use |
| Improve the product | Understand what works, fix what doesn't — using aggregate and de-identified data wherever possible | Consent |
| Billing and tax | Take payment, issue invoices, meet GST and accounting obligations | Legal obligation / legitimate use |
| Marketing communications | Send you product news, if you opted in | Consent |
| Legal compliance | Respond to lawful demands, defend claims | Legal obligation |
We do not:
- Sell your personal data. Ever. To anyone.
- Share your personal data with data brokers.
- Use your conversation for advertising or ad targeting.
- Use your conversation to train AI models (section 11).
- Give your employer your individual data (section 7).
- Feed your data into any performance management, appraisal, promotion, compensation, or termination process (section 7.3).
7. What your employer receives — the boundary
This is the section that matters most. If you read nothing else, read this.
7.1 The rule
| We give your Organisation | We never give your Organisation |
|---|---|
| An aggregate organisational report: themes and patterns across the whole participating cohort | Your conversation transcript |
| Team-level patterns to a team's manager, subject to the minimum-cohort floor below | Your Professional Passport |
| Completion and participation statistics at cohort level | Your individual answers, quotes, ratings, or feedback text |
| An indication that the session ran and how many people took part | Anything attributed or attributable to you by name, email, or inference |
7.2 The anonymisation floor
Aggregate and team-level reporting is only produced where the reporting group contains at least 5 participants who completed a session.
If a team or cohort is smaller than that floor, we do not produce a report for it. We do not produce a thinner report, a caveated report, or a verbal summary. We produce nothing, and we tell the Organisation why.
We also apply suppression to prevent re-identification by combination — for example, where a cohort is large enough but a particular characteristic within it is rare enough to point at one person. Reports contain no verbatim quotes.
We want to be candid about a limit here: statistical aggregation reduces re-identification risk; it does not mathematically eliminate it. A manager who knows their team well may believe they recognise someone in a pattern — and the smaller the group, the more that risk rises. This is why the floor exists, why rare-attribute suppression is applied on top of it, why quotes are excluded entirely, and why section 7.3 is drafted as it is.
7.3 The performance red line
Remi output must never be used in any employment decision. This is stated in our Privacy Policy because it is a privacy commitment, and it is replicated as a binding obligation in our contract with every Organisation.
Specifically, no Remi output — individual, team, or organisational — may be used as an input to:
- Performance reviews, ratings, or appraisals
- Promotion, succession, or "high potential" identification
- Compensation, bonus, or increment decisions
- Performance improvement plans, disciplinary action, redundancy selection, or termination
- Hiring, internal mobility screening, or role allocation decisions about identified individuals
- Any form of individual employee monitoring or surveillance
If an Organisation asks us to enable this, the answer is no, and we will terminate the relationship rather than comply. If you believe your employer has used Remi output this way, tell our Grievance Officer (section 17) — we will investigate, and we will act.
7.4 What we tell your employer about your participation
We tell your Organisation how many people took part. We do not tell them who.
They are paying for delivery, so they get a count — "38 of 50 invited employees completed a session." That's it. We do not confirm, deny, or hint at whether you personally took part, started and stopped, or declined outright.
This is deliberate. If declining were visible to HR, "voluntary" would stop meaning anything. So:
- Reminders come from us, not from your HR team. If you haven't taken part and the window is closing, Remi emails you. Your employer isn't cc'd and isn't told who got a reminder.
- Your employer cannot ask us for the list. The answer is no, and it's written into our contract with them.
- Declining has no consequence we participate in. If you're pressured to take part, tell us (section 17) — we take it up with them.
8. Who at Remi can see your conversation — stated honestly
We would rather tell you the truth than make a claim we cannot stand behind.
Your conversation is stored on our infrastructure in a form that a small number of authorised Remi personnel can technically access. Remi is not end-to-end encrypted, and we do not currently operate a zero-knowledge architecture in which access would be technically impossible for us. Claiming otherwise would be false.
What we do instead:
| Control | What it means |
|---|---|
| Purpose limitation | Authorised access occurs only to: (a) investigate a technical fault or security incident; (b) respond to a support request you raised; (c) comply with a binding legal obligation; or (d) act on a serious safety concern under section 10. |
| Least privilege | Access is restricted to named personnel whose role requires it. It is not available to our sales, marketing, or commercial staff, and it is never available to anyone at your employer. |
| Logging | Access to conversation data is logged and auditable. |
| Contractual duty | Every person with access is bound by confidentiality obligations. |
| Encryption | Data is encrypted in transit (TLS) and at rest by our database provider. |
What we do not do with that access: we do not read conversations out of curiosity, we do not review them for quality unless you have specifically asked us to look at your session, and we do not disclose them to your employer under any circumstances.
If a genuinely zero-access architecture matters to you, we are not there yet, and you should factor that into what you choose to share.
9. Who we share data with
We share personal data only with the following categories of recipient.
9.1 Processors and subprocessors
| Provider | What they do | What they receive | Location |
|---|---|---|---|
| Anthropic PBC | Provides the AI model (Claude) that powers the conversation | Your conversation content, and the context we supply with it (your name, role, and employer where we know them) | United States |
| Supabase | Database and storage — stores your account, conversation transcripts, and feedback | All stored personal data | Mumbai, India (ap-south-1) |
| Vercel Inc. | Application hosting. Our server code — including the code that passes your conversation to the AI provider — executes on Vercel's infrastructure. | Your conversation content in transit; technical and log data | Mumbai, India (bom1) |
| Our payment provider (applies only once paid plans launch) | Processes payments | Billing and transaction data. They receive card/UPI credentials directly; we never do. | India |
We use no analytics provider. No Google Analytics, no product analytics, no tracking pixels, no third-party trackers. See section 16.
GoDaddy is our domain registrar for myremi.co. A registrar points a web address at a server; it does not receive, process, or store your personal data. It is not a subprocessor and is listed here only so the picture is complete.
Each is engaged under a written contract that limits them to processing on our instructions, for our purposes only, with confidentiality and security obligations. We remain responsible to you for what they do.
On our AI provider specifically — the detail
Your conversation is transmitted to Anthropic to generate Remi's replies. This is the one place your words leave our systems, so here is the full picture.
| Do they train their AI on your conversation? | No. Our commercial agreement with Anthropic prohibits training on customer content, and their published policy is that retained data is never used for model training without express permission. |
| Do they keep your conversation? | Not by default. Anthropic does not retain conversation content sent through the API service we use. Your words are processed to generate a reply and are not stored at rest by them afterwards. |
| Is there an exception? | Yes, one, and we want you to know about it. Anthropic runs automated trust-and-safety systems. If a conversation is flagged by those systems, or if they are legally required to retain it, Anthropic may retain that conversation for up to 2 years. This is outside our control and applies regardless of the default. |
| Where does this happen? | United States. See section 15. |
On that exception: we're disclosing it because Remi conversations can touch on distress (section 10), and a flag is exactly the sort of thing that shouldn't be a surprise afterwards. It is a narrow, automated case — but it is real, and "your conversation is never stored anywhere" would be a false statement, so we're not making it.
9.2 Your Organisation
Only as described in section 7. Which is to say: never your individual data.
9.3 Legal and safety disclosures
We may disclose personal data where we are legally required to, or where it is genuinely necessary:
- To comply with a binding order of a court, or a lawful demand from a government or law enforcement authority with jurisdiction
- To comply with the DPDP Act, the Information Technology Act, 2000, CERT-In directions, or tax and accounting law
- To establish, exercise, or defend a legal claim
- To protect the life or safety of any person (section 10)
Our posture on government requests: we will require lawful process, we will assess whether the demand is valid and proportionate, we will resist demands that are not, we will disclose the narrowest data that satisfies a valid demand, and we will notify you unless legally prohibited from doing so.
9.4 If the company behind Remi ever changes
Remi is a project inside EZ Lab Private Limited. It's possible that changes — Remi could move into a company of its own, or EZ Lab could be involved in a merger, acquisition, financing, or sale of assets. There's nothing planned, but we'd rather tell you the possibility exists than have it arrive as a surprise.
If it happens, personal data may transfer to the new entity. Here is what we commit to:
- The section 7 boundary travels with the data, or the data doesn't travel. The commitments that your employer never receives your individual data, and that nothing you say feeds an employment decision, will be imposed as binding conditions on any successor or acquirer. If they won't accept them, we delete the data rather than transfer it.
- You will be told before it happens — not after — and given a real opportunity to export and delete your data first.
- Where the law requires fresh consent for the transfer, we will ask you. We will not treat your continued use as agreement to a change of the company that holds your conversations.
We're naming this in plain words rather than burying it in boilerplate, because a change in who holds your conversations is exactly the sort of thing you'd want to have been told about in advance.
9.5 Not shared
We do not share personal data with advertisers, data brokers, background-check providers, recruiters, insurers, or credit agencies.
10. Safety, distress, and crisis
Remi is not a mental health service, a therapist, a counsellor, a crisis line, or an emergency service. It is a professional reflection tool. Nothing it says is medical or psychological advice.
Careers are personal, though, and sometimes what surfaces in a conversation about work is bigger than work. Remi is designed to recognise signals that someone may be in serious distress — including references to self-harm or suicide — and, when it does, to stop the career conversation, say so plainly, and point to real human support:
- iCall — 9152987821 — free, confidential, trained counsellors (Mon–Sat, 8am–10pm); chat support at icallhelpline.org
- Vandrevala Foundation — 1860-2662-345 — 24/7 mental health helpline
What this means for your data: processing conversation content for this purpose is part of how Remi works. Where we act on a serious safety signal, we rely on your consent and, where applicable, on the protection of vital interests.
What this does not mean — please be clear on this:
- No human is watching. We do not monitor conversations in real time.
- There is no escalation. Remi does not alert a human being, a counsellor, your employer, your family, or emergency services when it recognises distress. Nobody is notified. Nobody calls you. The recognition happens inside the conversation, and what it produces is Remi saying so and pointing you to the helplines above.
- Detection is not guaranteed. Remi may miss it entirely.
If you are in immediate danger, contact emergency services, or call iCall on 9152987821 or the Vandrevala Foundation on 1860-2662-345 right now. Remi is not a substitute for a person.
We say this bluntly because a tool that hints at a safety net it doesn't have is worse than one that's honest about not having it.
11. AI, automated processing, and the limits of what Remi produces
11.1 How Remi works
Remi is powered by a large language model provided by Anthropic. Your conversation is sent to that model, which generates Remi's responses. Remi's reflections are produced by that model working within our own structured framework.
11.2 Training
Your conversations are not used to train AI models — not ours, not Anthropic's, not anyone's.
Concretely: our commercial agreement with Anthropic prohibits training on customer content, and their published policy is that retained data is never used for model training without express permission. Anthropic also does not retain conversation content by default on the API service Remi uses. The single exception — content flagged by their automated trust-and-safety systems, retained up to 2 years — is described in section 9.1; that retention is for safety and legal purposes, not training.
We do not train models on your data either. We have no model of our own, and we do not fine-tune anyone else's on what you tell Remi.
Where we improve Remi using what we learn, we do so using aggregate and de-identified information, or with your separate, specific, opt-in consent.
11.3 Automated decision-making
Remi profiles you in the sense that it derives reflections about your working style from what you say (section 5.3). Remi does not make automated decisions that produce legal effects concerning you or similarly significantly affect you. It does not decide anything about your employment, your pay, your role, or your access to anything. It reflects; you decide.
If that ever changes — if any Remi output ever becomes an input to a decision about you — we will change this policy first, loudly, and obtain a proper basis for it. Section 7.3 explains why we consider that a line we will not cross.
11.4 Accuracy — an honest limitation
AI-generated reflections can be wrong, incomplete, or generic. Remi may misread you. It works only from what you chose to tell it in a short conversation, which is not the whole of you. It has no access to your actual performance, your relationships, or your context beyond your own account of them.
Do not treat Remi's output as fact about yourself. Treat it as a prompt for your own thinking — which is the only thing a mirror has ever been good for.
You have the right to correct data we hold about you, including derived data you believe is wrong (section 13).
12. Security
We implement reasonable security safeguards designed to protect personal data, including:
- Encryption in transit (TLS) and encryption at rest
- Access control on the principle of least privilege, with authentication for all administrative access
- Segregation of individual data from any Organisation-facing reporting pipeline
- Logging and monitoring of system activity
- A defined incident response process
- Vendor due diligence and written processing contracts
- Confidentiality obligations and security training for everyone with access to personal data
Remi runs in India. Your data is stored in Mumbai and our servers run in Mumbai. The only thing that leaves the country is your conversation going to our AI provider to generate a reply — sections 9.1 and 15 set out exactly what that means.
No system is perfectly secure, and we do not claim otherwise. We commit to reasonable safeguards, not to invulnerability.
Breach notification. If a personal data breach occurs, we will notify the Data Protection Board of India and each affected Data Principal in the manner and within the timelines the DPDP Act and its Rules require. Separately, and on a much shorter clock, we are required to report certain cyber incidents to CERT-In within 6 hours of noticing them, under the CERT-In Directions of 28 April 2022, and to retain ICT system logs for 180 days within India.
13. Your rights
Under the DPDP Act, you have the following rights. Exercise any of them by writing to our Grievance Officer (section 17) or through your account settings where available.
| Right | What it means | How to use it |
|---|---|---|
| Access | Get a summary of the personal data we process about you, what we do with it, and who we've shared it with | Account settings, or email us |
| Correction & completion | Correct data that is inaccurate or misleading, complete data that is incomplete, and update data that is out of date — including derived reflections you believe are wrong | Email us |
| Erasure | Have your personal data deleted, unless we're required by law to keep it | Account settings, or email us |
| Withdraw consent | Withdraw consent at any time, as easily as you gave it. Processing before withdrawal stays lawful; processing after it stops. | Account settings, or email us |
| Grievance redressal | Complain to us, and get a response | Section 17 |
| Nominate | Nominate another person to exercise your rights if you die or become incapacitated | Email us |
Export. Beyond what the DPDP Act requires, you can export everything — your conversations and your Passport — in a portable format, at any time, from your account settings. We think you should be able to take it with you, so we built it that way rather than waiting to be made to.
Our response times: we will acknowledge your request within 48 hours and resolve it within 30 days.
Verification: we will need to verify your identity before acting on a request, in proportion to the sensitivity of what's requested. We will not use verification as a delaying tactic.
Your duties: the DPDP Act also places duties on you — notably, not to impersonate someone else, not to suppress material information, and not to file false or frivolous grievances. We mention this because the Act provides for penalties against Data Principals who breach them.
14. How long we keep your data
The DPDP Act requires us to erase personal data once the purpose is served and retention is no longer necessary for a legal purpose.
| Data | Retention |
|---|---|
| Conversation transcripts | For as long as your account is active — Remi's whole value is that it remembers you. Deleted within 30 days of you deleting the conversation or your account. |
| Professional Passport & derived insights | Same as above |
| Account & identity data | Life of the account, then deleted within 30 days |
| Dormant accounts | If you don't use Remi for 24 months, we'll email you first, and delete your account and data 30 days later if we don't hear back |
| Feedback (ratings and comments) | Retained in de-identified form for product improvement after account deletion — de-identified feedback is no longer personal data |
| Aggregate / Organisation reports | Retained as anonymised statistical output. These contain no personal data and survive individual deletion — we cannot un-aggregate you out of a report, and there is nothing of yours in it to remove. |
| Billing, invoices, tax records | 8 years, as required under the Companies Act, 2013 and Income Tax Act, 1961 |
| ICT system logs | 180 days, within India, per CERT-In Directions |
| Records needed for a live legal claim | Until the claim and any appeal period resolves |
"Deleted" means deleted. Not hidden, not flagged, not soft-deleted with a deleted_at timestamp. Removed from the live database within 30 days, and aged out of routine backups on their own cycle.
"You keep Remi even after you leave the company" — what that actually means. Your Remi account is yours, not your employer's. If you leave the Organisation that introduced you to Remi, your account, your conversations, and your Passport stay with you. Your employer cannot ask us to close it, transfer it, or hand it over. We would refuse, and our contract with them says so.
One practical thing: if you signed up with a work email address, add a personal email to your account before you leave. Your account survives your job; your access to a work inbox doesn't. We'll remind you in-app, but the five seconds it takes are worth it.
15. Cross-border transfers
Remi runs in India. Your data is stored in Mumbai, and our server code executes in Mumbai. We chose Indian regions for both, deliberately.
Exactly one thing leaves the country:
| What crosses | Where | Why |
|---|---|---|
| Your conversation content, and the name/role/employer context we send with it | United States (Anthropic) | To generate Remi's replies. There is no way to run the conversation without this. Anthropic does not retain it by default — see section 9.1. |
Everything else stays in India:
| Where | |
|---|---|
| Your account and identity data | Mumbai |
| Your conversation transcripts, as stored | Mumbai |
| Your Professional Passport and derived insights | Mumbai |
| Your feedback | Mumbai |
| The servers that run Remi | Mumbai |
Under the DPDP Act, transfers outside India are permitted except to territories the Central Government restricts by notification. We monitor that list. If a provider's location becomes restricted, we will migrate rather than continue.
We contractually require overseas providers to maintain protections materially equivalent to those in this policy.
We are not relying on GDPR transfer mechanisms, because Remi is offered in India only and we do not target users in the EEA or UK (section 2).
16. Cookies and similar technologies
Remi sets only strictly necessary cookies. That's it.
| Type | Purpose | Consent needed? |
|---|---|---|
| Strictly necessary | Authentication, session management, security | No — Remi doesn't work without them |
| Analytics | We don't use any. No Google Analytics, no tracking pixels, no third-party analytics of any kind. | N/A |
| Advertising | We don't use any. | N/A |
There's no cookie banner because there's nothing to consent to — we don't set anything that isn't required to log you in and keep the session working. You can block cookies in your browser, but the app won't work if you do.
We do not respond to "Do Not Track" signals, as there is no common standard for them.
17. Grievance Officer, and how to complain
We are required to publish a point of contact who will answer your questions about how we process your personal data. That person is:
| Grievance Officer | J Sharma |
| Designation | Grievance Officer, EZ Lab Private Limited |
| legal@myremi.co | |
| Postal address | EZ Lab Private Limited, 5122, 12th Floor, Tower No. 05, ATS Kocoon, Sector 109, Gurgaon, Haryana 122006, India |
| Acknowledgement | Within 48 hours |
| Resolution | Within 30 days |
If we don't resolve it: you have the right to complain to the Data Protection Board of India. Under the DPDP Act you are generally expected to raise the matter with us first and exhaust our grievance process before approaching the Board.
You do not lose any right by complaining to us first, and we will not retaliate for a complaint — including one about how your own employer behaved around a session.
18. Changes to this policy
We will update this policy as Remi changes and as the law changes.
- For material changes — anything that alters what we collect, why, who we share it with, or the section 7 boundary — we will give you 30 days' advance notice by email and in-app, and where the change requires it, we will ask for fresh consent rather than assume it.
- For minor changes, we'll update the "Last updated" date.
- We keep prior versions available so you can see what changed.
We will never quietly weaken the section 7 boundary. If we ever propose to change it, it will be announced loudly, in advance, with a real chance to export and delete your data first.
19. Contact
| General | hello@myremi.co |
| Privacy / rights requests | legal@myremi.co |
| Grievance Officer | Section 17 |
| Post | EZ Lab Private Limited, 5122, 12th Floor, Tower No. 05, ATS Kocoon, Sector 109, Gurgaon, Haryana 122006, India |
| Web | myremi.co |