Privacy Policy

Updated: 30 May 2026, Effective: 30 May 2026.

This Privacy Policy ("Policy") describes how Rewamil ("we", "us", or "our"), operated by Humayoun Kabir, Dhaka, Bangladesh, collects, uses, stores, discloses, and protects personal data in connection with the Rewamil platform ("Platform").

This Policy applies to all users who register for or access the Platform. By creating an account, you acknowledge that you have read and understood this Policy.

This Policy is incorporated by reference into the Rewamil Terms of Service. Defined terms used but not defined here have the meanings given in the Terms of Service.


1. Data Controller

Rewamil is the data controller for personal data processed in connection with the Platform. All inquiries regarding this Policy or your personal data may be directed to:

Rewamil
Operated by: Humayoun Kabir
Dhaka, Bangladesh
Mobile: +880 1764 662457
Email: rewamilapp@gmail.com


2. Personal Data We Collect

We collect personal data in the following categories:

2.1  Account and Registration Data

  • Full name
  • Email address
  • Professional designation and employer (where provided)
  • Password (stored in hashed form; never stored in plain text)

2.2  Payment and Wallet Data

  • Wallet transaction records (top-up amounts, dates, deduction history)
  • Payment channel metadata (bank transfer reference or bKash transaction ID)
  • Email address linked to financial transactions, retained for VAT compliance and dispute resolution

We do not collect or store credit card numbers, debit card numbers, or bank account credentials. All payment processing through bKash and bank transfer is handled by those providers under their own privacy policies.

2.3  Usage and Technical Data

  • Chat session metadata (timestamps, model selected, reasoning settings, token usage)
  • Device type and operating system (collected at login for security purposes)
  • IP address (collected at login; used for fraud detection and abuse prevention)
  • Log data generated by your use of the Platform

2.4  Content Data

  • Chat content (Input and Output) stored on Rewamil's servers at your direction for as long as you retain those Chats
  • Saved prompts and prompt library entries
  • Folder names and chat organizational structure

2.5  Communications Data

  • Support correspondence and help requests submitted to Rewamil
  • Email address used to send operational and, where consented, marketing communications

3. How We Use Your Personal Data

We process personal data only for the following purposes and on the following legal bases:

3.1  Provision and Operation of the Platform

Legal basis: Performance of contract.

We use your Account data, payment data, usage data, and content data to authenticate you, operate your Wallet, route AI requests, store your Chats, and deliver the features described in the Terms of Service.

3.2  Billing and Financial Compliance

Legal basis: Legal obligation; legitimate interests.

We retain financial transaction records and associated email addresses to calculate and remit VAT, satisfy applicable financial record-keeping requirements under Bangladesh law, and resolve payment disputes. These records are maintained for the duration required by applicable law regardless of account or chat deletion.

3.3  Security and Fraud Prevention

Legal basis: Legitimate interests.

We use IP addresses, login metadata, and device information to detect unauthorized access, prevent fraud, investigate abuse, and enforce the Terms of Service.

3.4  Platform Communications

Legal basis: Performance of contract (operational); consent (marketing).

We send operational communications (account status, renewal alerts, service notices) as necessary to operate your Account. We send marketing communications (product updates, new features, promotional offers, training programs) only to users who have not opted out under Section 9 of the Terms of Service.

3.5  Legal and Regulatory Compliance

Legal basis: Legal obligation.

We may process and disclose personal data where required by applicable law, regulation, court order, or lawful request of a competent governmental authority in Bangladesh.


4. Data We Do Not Use

The following uses of your personal data are expressly prohibited and will not occur:

  • Training, fine-tuning, or improving any AI model, whether operated by Rewamil or any third party.
  • Sale, rental, or transfer of your personal data to any third party for commercial purposes.
  • Sharing your personal data with advertising networks, marketing agencies, data brokers, or any third party for profiling, targeting, or advertising purposes.
  • Behavioral profiling for any purpose other than fraud and abuse detection.

These commitments are unconditional and not subject to opt-out or override by Rewamil.


5. AI Provider Data Processing

5.1  Stateless API Architecture

Rewamil transmits your Input to AI Providers (OpenAI and DeepSeek) via stateless API calls. This architecture is designed so that AI Providers do not retain your Input or Output in their model training systems. Rewamil, not the AI Provider, is the custodian of your Chat history.

5.2  Provider-Side Retention Limitations

Notwithstanding the stateless architecture, the following provider-side processing occurs by operation of provider policy and is outside Rewamil's direct control:

  • OpenAI retains API inputs and outputs for up to 30 days for abuse monitoring purposes, after which such data is deleted from OpenAI's systems unless longer retention is required by applicable law.
  • DeepSeek processes and retains data in accordance with its published Privacy Policy. DeepSeek stores data on servers located in the People's Republic of China, which may be subject to Chinese law, including data access requests by Chinese governmental authorities.

By using the Platform, you acknowledge and accept these provider-side processing limitations. Users handling highly sensitive or regulated data are advised to review the current privacy policies of both AI Providers before use.

5.3  No Rewamil Control Over Provider Systems

Rewamil has no ability to audit, modify, or enforce data handling within AI Provider systems beyond the contractual commitments those providers have made in their API terms. Rewamil's liability for provider-side processing is limited as set out in the Terms of Service.


6. Data Storage and Retention

6.1  Chat Data

Chat content is stored on Rewamil's servers for as long as you retain the relevant Chat. When you delete a Chat, it is permanently deleted from the active database. Monthly database backups are maintained for disaster recovery; a Chat deleted after its inclusion in a backup cycle may remain on the backup medium until the next monthly refresh. Backup data is not accessed, queried, or used for any purpose.

6.2  Account Data

Account registration data is retained for the duration of your active Account. Following Account closure, account data is retained for a period of up to thirty (30) days, reflecting the monthly database backup refresh cycle described in Section 6.1. After the next backup refresh following closure, account data is permanently deleted, subject to Section 6.3.

6.3  Financial Records

Financial transaction records, including your email address linked to those transactions, are retained for the period mandated by applicable Bangladesh tax and VAT law, irrespective of Account closure or Chat deletion. These records are used exclusively for regulatory compliance and dispute resolution.

6.4  Security Logs

IP address logs and login metadata are retained for a period not exceeding ninety (90) days, unless a specific incident requires extended retention for investigation or legal proceedings.

6.5  Marketing Opt-Out Records

If you opt out of marketing communications, a record of your opt-out preference is retained indefinitely to ensure your preference is honored.


7. Data Sharing and Disclosure

We do not sell, share, or disclose your personal data to third parties except in the following limited circumstances:

7.1  AI Providers

Your Input is transmitted to OpenAI and DeepSeek solely to generate Output in response to your request. This transmission constitutes the core function of the Platform. Provider data handling is governed by Section 5 of this Policy and by each provider's own terms and privacy policy.

7.2  Payment Processors

Payment metadata is processed by bKash and participating banks to the extent necessary to complete Wallet top-up transactions. Rewamil does not transmit Chat content or profile data to payment processors.

7.3  Legal and Regulatory Disclosure

Rewamil may disclose personal data where required by applicable law, court order, or formal request of a competent governmental or regulatory authority in Bangladesh. Where permitted by law, Rewamil will notify you of such a request before complying.

7.4  Business Transfer

In the event of a sale, merger, or transfer of Rewamil's business or assets, personal data held by Rewamil may be transferred to the acquiring party as part of that transaction. Users will be notified at least thirty (30) days in advance of any such transfer in accordance with Section 14 of the Terms of Service. If you do not wish to continue under the new operator, you may close your Account before the effective date of the transfer.

7.5  No Other Disclosure

No other disclosure of your personal data to third parties occurs. Rewamil has no affiliation with advertising networks, data brokers, or marketing agencies and will not share your data with any such entity.


8. International Data Transfers

Rewamil is incorporated and operated in Bangladesh. The Platform's database and servers are hosted in Singapore. When your Input is transmitted to AI Providers, it is further processed on servers operated by those providers in additional jurisdictions - the United States (OpenAI) and the People's Republic of China (DeepSeek). None of these jurisdictions may have data protection laws equivalent to those of Bangladesh.

Rewamil mitigates the risks associated with cross-border data processing by:

  • Hosting Platform data on servers in Singapore, a jurisdiction with a robust statutory data protection framework (Personal Data Protection Act 2012);
  • Transmitting to AI Providers only the Input necessary to generate the requested Output;
  • Using stateless API calls that do not authorize persistent storage at the provider level;
  • Contracting with providers whose API terms include confidentiality and limited-use commitments.

By using the Platform, you consent to the storage of your data on servers in Singapore and to the transmission of your Input to AI Providers in the jurisdictions described above for the sole purpose of generating Output.


9. Data Security

Rewamil implements appropriate technical and organizational measures to protect your personal data against unauthorized access, loss, destruction, or alteration. These measures include:

  • Encryption of data in transit using industry-standard protocols (TLS);
  • Passwords stored exclusively in hashed and salted form;
  • Access controls limiting internal access to personal data to authorized personnel only;
  • Regular review of security practices in line with the nature and sensitivity of data held.

No method of electronic storage or transmission is completely secure. Rewamil cannot guarantee absolute security but will notify affected users and, where required, the relevant authority, without undue delay in the event of a personal data breach that is likely to result in risk to your rights and interests.


10. Cookies and Tracking Technologies

Rewamil uses a limited set of cookies and similar technologies strictly necessary for Platform operation, including:

  • Session authentication cookies, to maintain your logged-in state;
  • Security cookies, to detect and prevent fraudulent or unauthorized access.

Rewamil does not use advertising cookies, tracking pixels, third-party analytics scripts, or any technology designed to track your activity across websites or build behavioral profiles. No cookie consent banner is triggered for strictly necessary cookies; these are placed automatically as a condition of accessing the Platform.

If Rewamil ever introduces non-essential cookies, it will obtain your explicit consent before doing so and update this Policy accordingly.


11. Your Data Rights

You have the following rights in respect of your personal data held by Rewamil, exercisable by contacting us at the address in Section 1:

Right of access You may request confirmation of whether we hold your personal data and a copy of that data.
Right to rectification You may request correction of inaccurate or incomplete personal data.
Right to erasure You may request deletion of your personal data. We will comply to the extent that data is not required to be retained for legal, tax, or regulatory purposes (see Section 6.3).
Right to restriction You may request that we restrict the processing of your personal data in certain circumstances, for example while a rectification request is being assessed.
Right to object You may object to processing carried out on the basis of legitimate interests, including marketing communications. You may opt out of marketing communications at any time as described in Section 9 of the Terms of Service.
Right to data portability You may request a machine-readable copy of personal data you have provided to us, where processing is based on contract or consent.
Right to withdraw consent Where processing is based on your consent (including marketing communications), you may withdraw that consent at any time without affecting the lawfulness of prior processing.

Rewamil will respond to verifiable requests within thirty (30) days. We may require identity verification before fulfilling any request.


12. Minors

The Platform is intended exclusively for users aged 18 and above. Rewamil does not knowingly collect personal data from persons under the age of 18. If we become aware that a minor has registered an Account, we will delete that Account and all associated data without delay. If you believe a minor has created an Account, please notify us at the address in Section 1.


13. Changes to This Policy

Rewamil may update this Policy from time to time to reflect changes in our practices, legal obligations, or AI Provider arrangements. Material changes will be communicated to you by email or by prominent notice on the Platform at least fourteen (14) days before the change takes effect.

Your continued use of the Platform after the effective date of any revision constitutes acceptance of the updated Policy. If you do not accept the revised Policy, you must close your Account before the effective date.

The "Last Revised" date at the top of this Policy indicates when it was most recently updated.


14. Governing Law

This Policy is governed by the laws of the People's Republic of Bangladesh, including the Cyber Security Act 2023 and applicable financial and tax regulations. Any dispute arising from this Policy is subject to the exclusive jurisdiction of the courts of Dhaka, Bangladesh.


15. Contact

For any questions, complaints, or requests relating to this Policy or your personal data, please contact:

Rewamil - Privacy
Operated by: Humayoun Kabir
Dhaka, Bangladesh
Mobile: +880 1764 662457
Email: rewamilapp@gmail.com