Who we are
Rein's hosted services are operated by M.D.N Tech FZE, Al Shmookh Business Center, One UAQ, UAQ Free Trade Zone, Umm Al Quwain, United Arab Emirates, licence no. 7813 ("we", "us"). We are the controller of the personal data described here. Contact: reinconsole@proton.me, or by post to the address above. Supervisory authorities: the UAE Data Office; for users in the EU, EEA or UK, your local data protection authority. We have not yet appointed a representative in the EU or UK; we will name one here when we do.
What this policy covers
The hosted services: the policy engine at engine.reinconsole.com, the console at
app.reinconsole.com, the reference vendor at
vendor.reinconsole.com and this website. It does not cover the open-source
@reinconsole/* packages when you run them yourself: a self-hosted engine
sends us nothing, and none of the packages contains analytics or telemetry.
Rein never holds your funds or your wallet key
Rein decides whether an agent may pay; it does not move money. Wallets created by
npx @reinconsole/init are generated on your machine, and their private keys
never reach us. We never ask for a private key or a seed phrase. Your owner file
(~/.rein/owner-*.json) also stays on your machine.
What we collect, and why
When you create a sandbox (npx @reinconsole/init):
- Your agent's wallet address, stored with the agent, so we can send it test USDC and record payments.
- An org, an agent, a starter policy and an API key. We store only a cryptographic digest of each key, never the key itself, plus when it was created, last used and when it expires.
- Your IP address, used only in memory to limit how many sandboxes one address can create per day. We do not write it to our database.
When you sign in to the console and claim an org:
- With GitHub: your numeric GitHub user id and your GitHub username. We request no GitHub permissions beyond your public profile, and we do not keep the GitHub access token.
- With an Ethereum wallet: your wallet address and a signed sign-in message. The signature moves no funds.
- Claiming binds your org to that identity. We store it as
github:<id>oreth:<address>in the name of the org's owner key. Your username is kept only in your session cookie, not in our database.
Sanctions checks. When you claim an org, and again when you move its agent to mainnet, we check your wallet address (if you signed in with one) and every agent wallet in the org against the Chainalysis sanctions oracle, a public list on Ethereum. A listed address is refused. For each address we keep a screening record: the address, the org, whether it is the owner's or an agent's, what triggered the check, the result, the time, and which source answered.
Where a request comes from. The engine and the console look up the country or region of each request's IP address in a table that ships with the software, and refuse requests from territories under comprehensive sanctions. The lookup happens in memory: the address is not sent to a lookup service and is not stored. IP geolocation by DB-IP, licensed under CC BY 4.0.
When your agent uses the engine (this is the service itself):
- Each payment decision: the outcome, the reason, the rules that matched, a hash of the payment request, and a timestamp and signature.
- Spending records: the vendor's host, the resource, the amount and time, used to enforce your budgets.
- Escalations (payments your policy parks for a person): the vendor, resource, amount, asset, chain and reason, and the approver's signed answer.
- Settlements your agent reports: the transaction hash, chain and amount.
When an agent pays the reference vendor: the paying wallet address, the resource, the amount and the transaction hash, so the vendor can prove what it was paid for.
Data about other people. Sellers' hostnames and the wallet addresses that pay the reference vendor may relate to people who are not our users; we hold them only as part of the payment record.
Application logs. The engine, console and vendor write operational logs, which our host keeps for a limited time set by its plan. For your org, engine logs record only the ids of an escalation, not its details.
This website sets no cookies, has no forms and runs no analytics. It reads one public status figure from the console.
Cookies
The console sets two cookies, both needed to keep you signed in. Neither is used for tracking or advertising.
rein_session: your sign-in identity and display name, signed so it cannot be altered. It lasts 7 days, or until you sign out.rein_oauth: a one-time value that protects the GitHub sign-in. It lasts 10 minutes.
Legal basis
We process the data above because it is necessary to provide the service you asked for: to create and run your sandbox or org, to answer your agent's payment requests, to keep a verifiable record of those decisions, and to keep the service secure, including the per-address sandbox limit and protection against abuse. We also process data where the law requires it, for example to respond to a lawful request from an authority or to comply with sanctions rules.
For users in the EU, EEA and UK, the bases under the GDPR are: performance of a contract (Art. 6(1)(b)) for providing the service; our legitimate interests (Art. 6(1)(f)) in keeping the service secure, preventing abuse and keeping an accurate audit record of payment decisions; and compliance with a legal obligation (Art. 6(1)(c)) where one applies. We do not rely on consent for any of this processing, and we do not use your data for marketing or profiling.
For users in the UAE, we rely on the exceptions in Article 4 of the Personal Data Protection Law for processing necessary to perform our contract with you and to comply with legal obligations.
Who else receives data
We share data only with the providers that run the service, and we do not sell it.
- Railway: hosts the engine, console and vendor, and receives their logs. For your org, engine logs record only the ids of an escalation, not its details.
- Supabase: hosts the engine's database, in the EU (Central, Frankfurt).
- Vercel: hosts this website.
- GitHub: provides GitHub sign-in, and stores our nightly full database backups in a private repository. Backups run on GitHub Actions.
- Telegram: delivers escalation and alert notifications for Rein's own orgs to the Rein operator. Nothing about your org is sent to Telegram.
- Payment facilitators (x402.org on testnet; PayAI or Coinbase on mainnet): receive the signed payment when an agent pays the reference vendor, in order to settle it.
- Blockchain RPC providers (Base and Ethereum): receive wallet addresses when we send test USDC, read the chain, or run a sanctions check.
We will disclose data where the law requires it, for example to a court order or a sanctions authority.
International transfers. We are based in the United Arab Emirates. Our database is hosted in the European Union. Some of our providers process data in the United States or in other countries. Where data about users in the EU, EEA or UK leaves those territories, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum or International Data Transfer Agreement) in our agreements with those providers, or on the EU-US Data Privacy Framework where the provider is certified under it. Where data leaves the UAE, we rely on the same contractual safeguards as permitted by the UAE Personal Data Protection Law. You can ask us for a summary of the safeguards that apply to a given provider.
Public blockchains
Payments, test USDC transfers and wallet addresses on Base are public and permanent. Anyone can read them, and neither we nor anyone else can delete them.
How long we keep data
- Decision log: kept indefinitely. Each decision is hash-linked to the one before, so removing one would break the verifiable record for everyone. This is how Rein proves what was and was not allowed.
- Spending records, settlements and API key records: kept indefinitely, as part of the same record.
- Resolved escalations: pruned after they are no longer needed for enforcement.
- Screening records: kept indefinitely, as the evidence that a sanctions check ran and what it found.
- Unclaimed sandboxes: their keys stop working after 7 days. The records stay in the decision log.
- IP addresses: held in memory only. The location check uses an address only while it answers the request; the sandbox limit keeps it until the limit resets or the service restarts.
- Sign-in cookies: 7 days at most.
- Application logs: kept by our host for a limited time set by its plan, then deleted.
- Backups: today we keep full backups indefinitely. We are moving to a 90-day rolling retention and will update this page when it is in place.
If you ask us to delete your data, see "Your rights" for what we delete and what we must keep.
Your rights
Depending on where you live, you can ask to access, correct or delete your personal data, to object to or restrict its processing, and to receive a copy. Write to reinconsole@proton.me, or by post to the address above. We will answer within one month. To verify a request we may ask you to sign a message with your owner wallet or to sign in with the GitHub account that claimed the org. You can also complain to your data protection authority.
If you ask us to delete your data, we will delete your sign-in identity and any record that links your org to you, so that we can no longer connect the decision log to you. Entries in the decision log itself, which contain wallet addresses, payment amounts and decision outcomes, are kept, because each entry is cryptographically linked to the ones before and after it: removing one would destroy the verifiability of every later record for every user, and the log is the evidence of what the service decided. We treat this as retention necessary for the integrity of the service and for the establishment and defence of legal claims. Records on a public blockchain are outside our control and cannot be deleted by anyone.
You can object to processing based on legitimate interests; we will stop unless we have compelling grounds, such as the integrity of the decision log.
Automated decisions
The engine's decisions are about your agent's payment requests, made under rules you set. We make no automated decisions about you as a person that have legal or similarly significant effects.
Security
API keys are stored only as digests. Sessions are signed. The decision log is signed and hash-linked, so tampering is detectable. See SECURITY.md for how to report a vulnerability. If a security incident affects your personal data, we will notify the relevant authority and, where the law requires, you, without undue delay.
Children
The services are not intended for anyone under 18. If we learn that we hold personal data about someone under 18, we will delete it.
Changes
We will post changes on this page and update the date above. If a change materially affects how we use your data, we will say so on this website before it takes effect.