RheXaBack to Home

On this page

IntroductionInformation We CollectHow We Use Gmail DataData Storage & SecurityData SharingData Retention & DeletionRevoking Gmail AccessYour RightsCookiesChanges to This PolicyContact Us

Need a summary?

Contact our compliance team for any specific security or data handling questions.

rhexorg@gmail.com
Legal Documentation

Privacy Policy

Last updated: April 27, 2026Effective immediately

01Introduction

RheXa ("we," "our," or "us") provides an AI-powered email management platform. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service at rehxa.com (the "Service").

Your trust is our most valuable asset. We are committed to transparency and handle your data with the highest level of security and professional integrity.

02Information We Collect

We collect the following types of information to provide and improve our services:

Account Information

Email address, name, and profile details when you register.

Gmail Data

Email metadata and content processed for classification and replies.

Knowledge Base

Documents, PDFs, and data you upload to train your AI instance.

Usage Analytics

Statistical data on how you interact with our features.

* Payment information is securely handled by LemonSqueezy. RheXa does not store full credit card details.

03How We Use Gmail Data

We use your Gmail data exclusively for functional purposes:

  • Classify incoming emails by category and urgency
  • Extract lead information from relevant business inquiries
  • Generate AI-powered reply drafts grounded in your private knowledge base
  • Send authorized replies through Gmail on your explicit behalf

Zero Advertising Policy

We do not sell, share, or use your Gmail data for advertising or marketing. Your content is processed via secure AI channels and is never used for general model training by our providers.

04Data Storage & Security

Supabase (PostgreSQL) with Row-Level Security (RLS)
Symmetric encryption (Fernet) for OAuth tokens
Logical data isolation between organizations
HTTPS/TLS encryption for all data in transit
JWT-based stateless authentication
Strict CORS and input validation protocols

05Data Sharing

PartnerPurpose
OpenAIAI classification and draft generation.
GoogleDirect interaction with your Gmail inbox.
SupabaseEncrypted storage and secure hosting.
LemonSqueezyGlobal payment processing and billing.

06Data Retention & Deletion

We retain your data for as long as your account is active. Upon account deletion, all organization data is removed from our live systems within 30 days. This includes email indices, knowledge base vectors, and access tokens.

Request permanent deletion by contacting our support team below.

7. Revoking Gmail Access

You can disconnect your inbox at any time from Settings. You may also revoke access at the platform level via Google account security settings.

8. Your Rights

Data ExportAccuracy CorrectionUsage RevocationPermanent ErasureSubscription Control

9. Cookies

We use zero tracking or advertising cookies. Our cookies are strictly functional and used solely for session persistence and identity verification.

10. Changes to This Policy

Updates will be posted here. Material changes will be communicated via the platform dashboard or email notification.

11. Contact Us

For all privacy, security, or data handling inquiries, please reach out directly to our compliance officer:

rhexorg@gmail.com
RheXa
Terms of ServiceContactLive Demo

© 2026 RheXa. All rights reserved.