Privacy Policy
How Reforion collects and uses account, workspace, crawl, and billing data while you turn a public site URL into a Next.js frontend.
Who we are
Reforion (reforion.com) is an AI Frontend Refactor service. You paste a public website URL; we crawl it, run structured audits, generate a component-driven Next.js project, and let you preview and export the result.
Questions about this placeholder policy: privacy@reforion.com.
What we collect
Account data: email, optional display name, password hash (Argon2id — we never store plaintext passwords), and session metadata.
Workspace and project data: workspace membership, project URLs you submit, generation settings, and usage/billing records tied to your workspace.
Crawl artifacts: final HTML, screenshots, SEO/style summaries, and derived page models for URLs you ask us to process. Cookies and Authorization headers from crawled sites are not stored.
Operational logs: request IDs, job/generation identifiers, and redacted error messages for debugging. Secrets and API keys are stripped from logs.
Billing: plan, subscription status, and provider customer identifiers when you check out (for example via Stripe). Card details are handled by the payment provider, not stored by Reforion.
How we use data
To operate the product: authenticate you, scope data by workspace, run the crawl → audit → generate → preview → export pipeline, and enforce plan limits.
To call LLM providers with crawled site content treated as untrusted input (prompt-injection isolation). Site text is sent as data for structured generation, not as instructions that can change system behavior.
To improve reliability: diagnostics, cost tracking, and admin support when you report an issue (scoped by workspace and generation IDs).
Retention and deletion
Preview and crawl artifacts are subject to retention limits and will be cleaned up according to product retention policy.
You may delete a project from the project page, or delete a workspace from Workspace settings (owner only). Soft-deleted workspaces are removed from the product immediately; object storage cleanup runs asynchronously. For assistance, email privacy@reforion.com with your account email and workspace ID.
Scheduled retention cleanup for previews, crawl artifacts, and failed build workspaces follows product retention limits (see Operations retention policy).
Security highlights
Workspace tenancy is enforced on API and database access. Crawls block private networks and other SSRF targets. Builds run in an isolated sandbox without production secrets.
Session cookies are HttpOnly; CSRF protection applies to state-changing requests.
Your choices
Access and correct account profile data via the product where available. Delete a workspace from settings, or contact privacy@reforion.com for export assistance.
Do not submit URLs you are not authorized to process. You remain responsible for the rights to crawled content and assets.