Legal

Privacy, without the fine-print fog.

This page explains what Refinements processes, where session content goes when you use connected services, and what is deleted when the work is done.

Last updated September 4, 2026

Session content and retention

Drafts, suggestions, Grill questions and answers, refined documents, decisions, and session activity are stored in Convex to run the shared workspace. Refinements deletes that stored session content when the host closes the session or automatically after 24 hours of inactivity. This is what the zero-retention promise means for the session copy stored by Refinements.

Account records, billing records, and free-preview usage counters are separate from session content and remain after a session is deleted. Files you export and data already sent to a connected provider are also outside the session-deletion process.

AI and your content

When you ask for an AI review, Grill questions, or a refined-ticket proposal, Refinements sends a prompt to OpenRouter. Depending on the action, that prompt can include the current document, session title, selected text, your instruction, template structure, and Grill context, questions, and answers. OpenRouter routes the request to the configured model provider, which also receives the prompt and processes the response.

OpenRouter and model providers have their own retention and model-training rules. We do not extend Refinements' 24-hour deletion promise to copies they process, and we do not promise that a selected model provider will not use inputs or outputs for training. Do not enter personal, confidential, or regulated information unless you are allowed to send it to those providers.

Accounts, preview, and billing

Clerk handles sign-in. Refinements keeps the account identifiers and profile details needed to recognize you, apply the once-per-account free-preview allowance, prevent abuse, and operate the service. The free preview does not require a payment card.

When a host starts the 7-day trial, Stripe receives the payment and billing details entered at checkout. Refinements stores Stripe identifiers, subscription status, and relevant dates, but does not store the full payment-card number.

Guests and e-mail invites

Guests join free through a private session link. Anyone with a working link may be able to reach the join flow, so hosts should share it only with the intended team.

If a host sends an e-mail invitation, Resend receives the recipient's e-mail address, the session title, and the private join link to deliver that message. The session activity records a masked version of the recipient address and is deleted with the rest of the session.

Google Drive export

Drive export is optional. If you choose it, Refinements uses the Google OAuthdrive.file scope and sends the exported HTML ticket and its filename to Google Drive. That scope is limited to the specific Drive files you use with this app; it does not provide general access to every file in your Drive.

The exported file remains in your Google Drive after its Refinements session is deleted. You control that copy through your Google account and can revoke the connection in your Google account settings.

Analytics and operations

PostHog receives page views, browser and device information, an opaque account identifier after sign-in, and explicit product events such as starting a preview or requesting an AI review. Autocapture and session recording are disabled. Analytics events do not include document content, feature titles, Grill answers, recipient e-mail addresses, or private invite codes.

If enabled, Google Analytics and Umami receive pageview and standard technical information such as browser, device, and referrer data on the marketing pages and signed-in app shell. Refinements sends a normalized page path and a fixed, non-content title. It does not send them document or session titles, query strings, private session ids, or application user ids. Automatic pageview tracking is disabled for both; the Google tag requests IP anonymization and disables Google Signals, and Umami automatic tracking is disabled entirely.

Sentry may receive error and request metadata so we can keep the service reliable. We do not intentionally include document content in analytics or error logs.

Service providers

Refinements currently relies on Clerk for authentication, Convex for the realtime application and stored session data, Vercel for web hosting, Stripe for billing, OpenRouter and its routed model provider for AI processing, PostHog for product analytics, Sentry for error monitoring, Resend for e-mail delivery, Google for optional Analytics and Drive export, and Umami when its analytics are enabled. Each provider processes data under its own terms and privacy policy.

Your choices

You can request access to, correction of, or deletion of eligible account data. You can also ask questions about data handling by emailing privacy@refinements.app.

Policy changes

If this policy changes materially, we will update this page and the date above. We will provide additional notice when required by law.