Legal

Privacy Policy

What Rexli Labs collects when you use Rexli, why we collect it, and how workspace and client data stays separated. Last updated 18 August 2026.

About this policy

Rexli is a client management platform for service businesses, provided by Rexli Labs. Businesses use Rexli to manage clients, projects, schedules, messages, files, forms, inquiries, services and client portals in one workspace.

This policy explains what we collect, why we collect it, and how workspace data stays separated. Rexli Labs is the controller of account and billing data for our own customers. When a customer stores information about their own clients inside their workspace, that customer is the controller of that information and Rexli Labs acts as their processor.

Information you provide

Almost everything in a workspace is there because someone typed it, uploaded it or submitted it. We do not buy personal data, and we do not enrich your records from outside sources.

Account information

When you create an account we collect your name, email address and either a password (stored only as a hash by our authentication provider) or an identifier from your chosen sign-in provider. We also store basic account metadata such as sign-in timestamps and the workspaces you belong to.

Workspace and business information

Workspace records include your business or workspace name, time zone, the kind of work you do, appearance and module preferences, team membership and roles, and the settings that shape your workspace.

Client and client portal information

Customers may store information about their own clients, including names, business names, email addresses, phone numbers, notes, status and assigned team members.

When a customer invites a client contact to a portal, we process that contact's name and email to create their portal login. Client portal users can only access information connected to their own client relationship. They cannot see other clients, other workspaces, or internal-only records.

Files and content you upload

Uploaded files, images, proofs, deliverables and attachments are stored in a private bucket and are reachable only through short-lived signed links generated for authorized users. We do not use your files to train models and we do not scan them for advertising.

Forms, messages, inquiries, services and packages

We process the content of forms and questionnaires you build and the answers submitted to them, messages exchanged in workspace and portal conversations, public inquiry submissions including the answers to your own questions, and the services, packages, prices and requests you configure.

Public inquiry forms are filled in by people who may not have an account. Their submitted contact details and answers are stored in the workspace whose inquiry link they used.

Authentication information

Authentication is handled by our authentication provider. We store the email address, provider identifier and session tokens needed to keep you signed in and to secure your account. Passwords are hashed and are never stored in plain text or visible to us.

Google Sign-In

If you sign in with Google, we receive your name, email address, Google account identifier and profile picture URL from Google so we can create or match your Rexli account. Google Sign-In is used for authentication only.

We do not request access to your Gmail, Google Drive, Calendar, Contacts or any other Google data. If additional Google permissions are ever introduced, they will be requested explicitly and this policy will be updated first.

Payment and subscription information

Paddle.com Market Ltd (Paddle) is our merchant of record and handles checkout, billing, invoicing, sales tax and refunds for Rexli subscriptions. Payment card details are entered with Paddle and are processed by Paddle, not by us. Rexli Labs does not receive or store full card numbers.

We receive and store billing metadata from Paddle, such as your subscription plan, status, renewal dates, customer and transaction identifiers, billing email and country, so we can apply your plan and entitlements.

Technical and usage data

To run, monitor and secure the platform we process technical data such as IP address, browser and device information, request and error logs, and basic usage events like which workspace actions were performed and when. This supports reliability, debugging, abuse prevention and security investigations.

Cookies and similar technologies

We use only cookies and local browser storage that are essential to the service: keeping you signed in, keeping your session secure, and remembering basic preferences such as appearance. We do not run third-party advertising or marketing trackers. You can clear or block this storage in your browser, but signing in will not work without it.

How we use data

We use data to create and secure accounts, provide and operate workspace features, deliver client portals and public inquiry pages, send transactional and notification email you have asked for, apply plan limits and billing status, respond to support requests, investigate abuse and fraud, meet legal and tax obligations, and improve reliability and usability of the product.

We do not sell personal data, we do not share workspace content with advertisers, and we do not use your workspace content to train artificial intelligence models.

Rex

Rex is Rexli's AI workspace assistant and is only used when you ask it something. We send the minimum information needed to our contracted AI infrastructure: your request, recent messages in that Rex conversation and the specific workspace records needed to answer. Only records you already have permission to open are included.

Rex never sends workspace content for model training or performs background AI processing unless a separately enabled automation requires it. Rex answers and drafts are generated content: they are clearly marked and nothing is sent, published or changed in your workspace until you confirm it where confirmation is required. Rex conversations are stored in your workspace so you can revisit or archive them.

Service providers and subprocessors

We share data only with providers who help us run the service: cloud hosting, managed database and authentication, private object storage, transactional email delivery, error monitoring, contracted AI infrastructure for Rex, and Paddle.com Market Ltd (Paddle) for the sale of subscriptions, payments, invoicing and tax compliance. We also share data with professional advisers such as legal and accounting where necessary, and with authorities where the law requires it.

Workspace separation

Every record belongs to a workspace and is protected by database-level row security, so a request can only return rows the signed-in user's membership allows. Client portal users are further restricted to the single client relationship they were invited to. This separation is enforced in the database, not only in the interface.

Security

We apply appropriate technical and organizational measures, including encryption in transit and at rest, hashed passwords, restricted and logged administrative access, private file storage with short-lived signed links, and least-privilege database roles. No online service can promise perfect security, and we make no certification or audit claims we have not completed.

Data retention

Workspace data is retained while the account exists, including during read-only periods after a trial ends or a subscription is canceled, so nothing is lost if you return. When a workspace is deleted, its data is removed within a reasonable operational window, after which it is deleted or anonymized. Backups age out on their own schedule. Billing records are kept as long as tax and accounting law requires.

Your rights

Subject to applicable law, you may request access to your personal data, correction of inaccurate data, deletion, restriction of processing, a portable copy, or you may object to certain processing, and you may withdraw consent where processing relies on it. We aim to respond within one month. Where local law provides it, you may also complain to your data protection supervisory authority.

If you are a client contact rather than an account holder, the business that invited you controls your records. Contact that business first, and we will help them respond.

Deletion requests

You can delete individual records from your workspace at any time. To delete your account or an entire workspace, email support@rexlilabs.com from the address on the account or use the in-app help page. We will confirm the request, delete the data as described above, and keep only what billing, tax or legal obligations require.

Children

Rexli is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child's data has been submitted to us, contact support@rexlilabs.com and we will delete it.

If a customer's own service involves minors, that customer is responsible for obtaining any consent required before entering their information into a workspace.

International users

We operate from the United States, and our infrastructure and subprocessors may process data in the United States and other countries. If you use the service from outside the United States, you understand that your data will be transferred and processed there. Where transfers from the UK or EEA occur, we rely on appropriate safeguards such as standard contractual clauses or an adequacy decision.

Changes to this policy

We may update this policy as the product changes. The update date at the top of the page always reflects the current version, and material changes will be communicated in the product or by email before they take effect.

Contact

Privacy questions, data requests and deletion requests can be sent to support@rexlilabs.com or raised through the in-app help page. Address them to Rexli Labs.