← RewireMe

Privacy

Last updated: July 23, 2026

RewireMe is built as a private protocol. We collect only what we need to run your account, deliver the 120-day map, and process payments you choose to make.

What we store

  • Account email and password hash (never plaintext passwords)
  • Protocol progress, onboarding answers, and journal notes you submit — journal text and sensitive profile fields are encrypted at rest (AES-256-GCM with a per-user key derivation). A database dump alone does not yield readable notes.
  • Entitlement / payment references from our payment provider
  • Optionally, AI-tailored day content generated from your profile and notes to personalize the next day's practices (processed on our servers; not used to train public models)

Journal encryption

Your typed journal notes are encrypted before they are written to storage. Encryption uses AES-256-GCM. Keys are derived per account from a server-held master secret so one compromised row does not unlock another user's notes. We do not log note plaintext. The running application must hold the master secret to show you your own notes and to generate personalized next-day practices — this is not end-to-end encryption against the operator of the service, but it does protect notes if the database alone is stolen.

What we don't do

  • We do not sell your personal data
  • We do not run a public social feed of your recovery content
  • We do not use your journal text to train public AI models

Processors

Infrastructure may include Cloudflare (hosting), a transactional email provider (password reset / receipts), and NOWPayments (crypto checkout). Each processor only receives data required for that function.

Your choices

You may request export or deletion of your account data by emailing privacy@rewireme.cc. We will respond within a reasonable period.

Contact

Questions: support@rewireme.cc