Reforion
PrivacyTerms

Placeholder for the pilot MVP. This is not a final, counsel-reviewed legal document. It describes how Reforion intends to handle data during early access.

Privacy Policy

Last updated 2026-08-11 · Placeholder for pilot MVP

How Reforion collects and uses account, workspace, crawl, and billing data while you turn a public site URL into a Next.js frontend.

Who we are

Reforion (reforion.com) is an AI Frontend Refactor service. You paste a public website URL; we crawl it, run structured audits, generate a component-driven Next.js project, and let you preview and export the result.

Questions about this placeholder policy: privacy@reforion.com.

What we collect

Account data: email, optional display name, password hash (Argon2id — we never store plaintext passwords), and session metadata.

Workspace and project data: workspace membership, project URLs you submit, generation settings, and usage/billing records tied to your workspace.

Crawl artifacts: final HTML, screenshots, SEO/style summaries, and derived page models for URLs you ask us to process. Cookies and Authorization headers from crawled sites are not stored.

Operational logs: request IDs, job/generation identifiers, and redacted error messages for debugging. Secrets and API keys are stripped from logs.

Billing: plan, subscription status, and provider customer identifiers when you check out (for example via Stripe). Card details are handled by the payment provider, not stored by Reforion.

How we use data

To operate the product: authenticate you, scope data by workspace, run the crawl → audit → generate → preview → export pipeline, and enforce plan limits.

To call LLM providers with crawled site content treated as untrusted input (prompt-injection isolation). Site text is sent as data for structured generation, not as instructions that can change system behavior.

To improve reliability: diagnostics, cost tracking, and admin support when you report an issue (scoped by workspace and generation IDs).

Processors and sharing

We use subprocessors required to run the service (hosting, database, object storage, queue, LLM providers, and payment processing). We do not sell personal data.

Crawled content may be sent to configured LLM providers only to produce redesign plans and generated frontend artifacts for your workspace.

Retention and deletion

Preview and crawl artifacts are subject to retention limits and will be cleaned up according to product retention policy.

You may delete a project from the project page, or delete a workspace from Workspace settings (owner only). Soft-deleted workspaces are removed from the product immediately; object storage cleanup runs asynchronously. For assistance, email privacy@reforion.com with your account email and workspace ID.

Scheduled retention cleanup for previews, crawl artifacts, and failed build workspaces follows product retention limits (see Operations retention policy).

Security highlights

Workspace tenancy is enforced on API and database access. Crawls block private networks and other SSRF targets. Builds run in an isolated sandbox without production secrets.

Session cookies are HttpOnly; CSRF protection applies to state-changing requests.

Your choices

Access and correct account profile data via the product where available. Delete a workspace from settings, or contact privacy@reforion.com for export assistance.

Do not submit URLs you are not authorized to process. You remain responsible for the rights to crawled content and assets.

Back to Reforion
Privacy PolicyTerms of Service