Privacy Policy

Draft

This is a draft pending legal review. It is not yet in effect. Last updated: 6 October 2026.

Who we are

Rein's hosted services are operated by M.D.N Tech FZE, Al Shmookh Business Center, One UAQ, UAQ Free Trade Zone, Umm Al Quwain, United Arab Emirates, licence no. 7813 ("we", "us"). We are the controller of the personal data described here. Contact: reinconsole@proton.me, or by post to the address above. Supervisory authorities: the UAE Data Office; for users in the EU, EEA or UK, your local data protection authority. We have not yet appointed a representative in the EU or UK; we will name one here when we do.

What this policy covers

The hosted services: the policy engine at engine.reinconsole.com, the console at app.reinconsole.com, the reference vendor at vendor.reinconsole.com and this website. It does not cover the open-source @reinconsole/* packages when you run them yourself: a self-hosted engine sends us nothing, and none of the packages contains analytics or telemetry.

Rein never holds your funds or your wallet key

Rein decides whether an agent may pay; it does not move money. Wallets created by npx @reinconsole/init are generated on your machine, and their private keys never reach us. We never ask for a private key or a seed phrase. Your owner file (~/.rein/owner-*.json) also stays on your machine.

What we collect, and why

When you create a sandbox (npx @reinconsole/init):

When you sign in to the console and claim an org:

Sanctions checks. When you claim an org, and again when you move its agent to mainnet, we check your wallet address (if you signed in with one) and every agent wallet in the org against the Chainalysis sanctions oracle, a public list on Ethereum. A listed address is refused. For each address we keep a screening record: the address, the org, whether it is the owner's or an agent's, what triggered the check, the result, the time, and which source answered.

Where a request comes from. The engine and the console look up the country or region of each request's IP address in a table that ships with the software, and refuse requests from territories under comprehensive sanctions. The lookup happens in memory: the address is not sent to a lookup service and is not stored. IP geolocation by DB-IP, licensed under CC BY 4.0.

When your agent uses the engine (this is the service itself):

When an agent pays the reference vendor: the paying wallet address, the resource, the amount and the transaction hash, so the vendor can prove what it was paid for.

Data about other people. Sellers' hostnames and the wallet addresses that pay the reference vendor may relate to people who are not our users; we hold them only as part of the payment record.

Application logs. The engine, console and vendor write operational logs, which our host keeps for a limited time set by its plan. For your org, engine logs record only the ids of an escalation, not its details.

This website sets no cookies, has no forms and runs no analytics. It reads one public status figure from the console.

Cookies

The console sets two cookies, both needed to keep you signed in. Neither is used for tracking or advertising.

Legal basis

We process the data above because it is necessary to provide the service you asked for: to create and run your sandbox or org, to answer your agent's payment requests, to keep a verifiable record of those decisions, and to keep the service secure, including the per-address sandbox limit and protection against abuse. We also process data where the law requires it, for example to respond to a lawful request from an authority or to comply with sanctions rules.

For users in the EU, EEA and UK, the bases under the GDPR are: performance of a contract (Art. 6(1)(b)) for providing the service; our legitimate interests (Art. 6(1)(f)) in keeping the service secure, preventing abuse and keeping an accurate audit record of payment decisions; and compliance with a legal obligation (Art. 6(1)(c)) where one applies. We do not rely on consent for any of this processing, and we do not use your data for marketing or profiling.

For users in the UAE, we rely on the exceptions in Article 4 of the Personal Data Protection Law for processing necessary to perform our contract with you and to comply with legal obligations.

Who else receives data

We share data only with the providers that run the service, and we do not sell it.

We will disclose data where the law requires it, for example to a court order or a sanctions authority.

International transfers. We are based in the United Arab Emirates. Our database is hosted in the European Union. Some of our providers process data in the United States or in other countries. Where data about users in the EU, EEA or UK leaves those territories, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum or International Data Transfer Agreement) in our agreements with those providers, or on the EU-US Data Privacy Framework where the provider is certified under it. Where data leaves the UAE, we rely on the same contractual safeguards as permitted by the UAE Personal Data Protection Law. You can ask us for a summary of the safeguards that apply to a given provider.

Public blockchains

Payments, test USDC transfers and wallet addresses on Base are public and permanent. Anyone can read them, and neither we nor anyone else can delete them.

How long we keep data

If you ask us to delete your data, see "Your rights" for what we delete and what we must keep.

Your rights

Depending on where you live, you can ask to access, correct or delete your personal data, to object to or restrict its processing, and to receive a copy. Write to reinconsole@proton.me, or by post to the address above. We will answer within one month. To verify a request we may ask you to sign a message with your owner wallet or to sign in with the GitHub account that claimed the org. You can also complain to your data protection authority.

If you ask us to delete your data, we will delete your sign-in identity and any record that links your org to you, so that we can no longer connect the decision log to you. Entries in the decision log itself, which contain wallet addresses, payment amounts and decision outcomes, are kept, because each entry is cryptographically linked to the ones before and after it: removing one would destroy the verifiability of every later record for every user, and the log is the evidence of what the service decided. We treat this as retention necessary for the integrity of the service and for the establishment and defence of legal claims. Records on a public blockchain are outside our control and cannot be deleted by anyone.

You can object to processing based on legitimate interests; we will stop unless we have compelling grounds, such as the integrity of the decision log.

Automated decisions

The engine's decisions are about your agent's payment requests, made under rules you set. We make no automated decisions about you as a person that have legal or similarly significant effects.

Security

API keys are stored only as digests. Sessions are signed. The decision log is signed and hash-linked, so tampering is detectable. See SECURITY.md for how to report a vulnerability. If a security incident affects your personal data, we will notify the relevant authority and, where the law requires, you, without undue delay.

Children

The services are not intended for anyone under 18. If we learn that we hold personal data about someone under 18, we will delete it.

Changes

We will post changes on this page and update the date above. If a change materially affects how we use your data, we will say so on this website before it takes effect.