Privacy Policy

Last Updated: June 18, 2026

1. Introduction

Refinix ("Company," "we," "us," or "our") operates the Refinix platform (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website and use our Service.

Please read this Privacy Policy carefully. If you do not agree with our policies and practices, please do not use our Service. Your continued use of the Service following the posting of revised Privacy Policy means that you accept and agree to the changes.

2. Information We Collect

2.1 Account and Authentication Data

When you create an account, we collect:

  • Email address and password (securely hashed)
  • Full name and display name
  • Avatar/profile image (optional)
  • Telegram User ID (optional, for data collection features)
  • X (formerly Twitter) User ID (optional, for data collection features)
  • Professional profile information and user preferences
  • Account creation and modification timestamps

2.2 Usage and Activity Data

We automatically collect information about your interactions with the Service:

  • Number of messages analyzed from Telegram and X (formerly Twitter)
  • Insights generated and viewed
  • Agent queries executed
  • Chat interactions and query history related to use of the Service
  • Search queries and filters applied
  • Last active timestamp
  • Login timestamps and authentication events
  • API usage and request patterns

2.3 Content and Communication Data

To provide analytics and insights, we process content from monitored sources:

  • Telegram group IDs, names, and descriptions (when you elect to monitor)
  • Aggregated message counts and metadata from monitored sources
  • X (formerly Twitter) profile information and engagement metrics
  • Trending token and market data derived from monitored sources
  • Generated summaries and AI-processed insights

Raw message content from X and Telegram may be temporarily processed to generate summaries and insights. See Section 6.1 for retention periods.

2.4 Technical and Device Data

We collect technical information for security and optimization:

  • IP address
  • Browser type and version
  • Device type and operating system
  • Referring/exit pages
  • Session duration
  • Geographic location (derived from IP)

2.5 Data from Third-Party Platforms

When you link your Telegram or X (formerly Twitter) accounts, or when you subscribe to public sources:

  • We receive your User ID and publicly available profile information from Telegram and X APIs
  • We do not store your Telegram or X account credentials
  • For private sources, we only access data from groups and accounts you explicitly authorize
  • For public sources, we may collect publicly available content without requiring your account connection
  • Raw X tweet content is stored in our database for up to 30 days to generate insights, then deleted (see Section 6.1)
  • Raw Telegram message content is stored for up to 90 days for processing, security, and service delivery, then deleted
  • Generated insights, metadata, and usage records are retained according to the periods in Section 6.1
  • Users are responsible for ensuring they have the necessary permissions and legal basis to monitor or analyse third-party communities, channels, or accounts

3. How We Use Your Information

We use the information we collect for:

  • Service Provision: Creating and maintaining your account, processing requests, and delivering features
  • Personalization: Tailoring content, insights, and recommendations to your preferences
  • Analytics and Insights: Summarizing and analyzing data from monitored sources to generate insights
  • AI Processing: Using third-party LLM APIs (OpenAI, OpenRouter) to process and summarize content
  • Authentication and Security: Verifying your identity, detecting unauthorized access, and preventing fraud
  • Communications: Sending account notifications, technical updates, and support responses
  • Usage Monitoring: Understanding subscription plan compliance and feature usage patterns
  • Service Improvement: Optimizing features, fixing bugs, and developing new functionality
  • Legal Compliance: Complying with applicable laws, regulations, and legal processes

4. How We Share Your Information

4.1 Third-Party Service Providers

We share information with trusted service providers who assist in operating our Service:

  • LLM Providers (via OpenRouter): Message content summaries and insights are sent to AI models for processing. We configure no-training settings with our AI subprocessors where available and do not allow content processed through our service to be used for training third-party AI models. Individual provider terms and retention policies apply; see our Subprocessors page for details.
  • Cloud Infrastructure (PostgreSQL, Redis): All data is stored in encrypted databases on secure cloud infrastructure
  • Telegram and X (formerly Twitter) APIs: We access these only when you authorize it and only to retrieve the data you specify
  • Analytics Providers: Aggregated, anonymized usage data (no personal information shared)

4.2 Legal Obligations

We may disclose your information when required by law or to protect the rights, property, and safety of Refinix, our users, or the public. This includes compliance with subpoenas, court orders, and other legal processes.

4.3 Business Transfers

If Refinix is involved in a merger, acquisition, bankruptcy, or asset sale, your information will be transferred as part of that transaction. We will notify you via email or prominent notice on our website of any such change.

4.4 What We Do NOT Share

  • Your password (we store only a secure hash)
  • Raw message content from Telegram or X (formerly Twitter) (except where temporarily necessary for processing, security, or service delivery)
  • Your personal information to third parties for marketing purposes
  • Your Telegram or X (formerly Twitter) credentials
  • Sensitive financial or personal data beyond what's necessary for the Service

5. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to enhance your experience. See our Cookie Policy for detailed information about:

  • Authentication tokens
  • Session management
  • User preferences and settings
  • Analytics and performance monitoring

6. Data Retention and Deletion

6.1 Retention Periods

  • Active Account Data: Retained for the duration of your account
  • Raw X Content: Up to 30 days from ingestion for processing and insight generation, then permanently deleted
  • Raw Telegram Content: Up to 90 days for processing, security, debugging, and service delivery, then permanently deleted
  • Generated Insights and Metadata: Retained for 24 months (or duration of account, if shorter)
  • Usage Tracking: Retained for 24 months for billing and analytics purposes
  • Session Tokens: Refresh tokens retained up to 30 days after last use; access tokens expire after 1 hour
  • Login History: Retained for 12 months for security auditing
  • Deleted Account Data: Soft-deleted (marked inactive) for 90 days, then permanently removed from operational systems

6.2 Data Deletion

You may request deletion of your account and associated data at any time. Upon deletion:

  • Your account is immediately disabled
  • Personal information is soft-deleted (retained for 90 days in case of accidental deletion)
  • After 90 days, all data is permanently removed from live systems
  • Backups may retain data for an additional 30 days for disaster recovery
  • Aggregated, anonymized data may be retained for analytics

7. Data Security

We implement comprehensive security measures to protect your data:

  • Encryption: All data in transit uses TLS 1.2+ encryption. Data stored in our managed database and storage infrastructure is encrypted at rest by our cloud provider.
  • Password Security: Passwords are hashed using industry-standard algorithms (bcrypt/Argon2)
  • JWT Authentication: Signed HS256 JWT tokens with expiration and validation
  • Access Control: Role-based access control (admin, user, system) with principle of least privilege
  • Database Security: Secured PostgreSQL database with connection pooling, timeouts, and query parameterization
  • Monitoring: Monitoring systems designed to detect suspicious activity and unauthorized access attempts
  • Security Reviews: We periodically review and improve our security practices and infrastructure

Important: While we implement robust security measures, no system is completely secure. We cannot guarantee absolute security of your data. You are responsible for maintaining the confidentiality of your password.

8. Your Privacy Rights

8.1 General Rights

Depending on your jurisdiction, you may have the following rights:

  • Access: Request a copy of personal information we hold about you
  • Correction: Update or correct inaccurate information
  • Deletion: Request deletion of your data (right to be forgotten)
  • Data Portability: Request your data in a portable, machine-readable format
  • Withdraw Consent: Withdraw consent for data processing (where applicable)
  • Object to Processing: Object to certain types of processing

8.2 GDPR Compliance (EU/EEA Users)

If you are located in the EU or EEA, you have additional rights under GDPR. Our legal basis for processing your information includes:

  • Contract Performance: Processing necessary to provide the Service
  • Legal Obligation: Compliance with applicable laws
  • Legitimate Interests: Fraud prevention, security, and service improvement
  • Consent: Where you have explicitly consented (e.g., for marketing communications)

You have the right to lodge a complaint with your local data protection authority.

8.3 Legal Basis for Processing Activities

The following table summarises the main processing activities, the data involved, the purpose, and the legal basis:

Processing activityDataPurposeLegal basis
Account creationEmail, name, password hashProvide accountContract
Source monitoringTelegram/X source dataGenerate insightsContract / Consent
Security logsIP, login eventsProtect serviceLegitimate interests
BillingPayment/customer recordsSubscription/paymentContract / Legal obligation
Product updatesEmailService communicationsLegitimate interests
AI processingMessage summariesGenerate insightsContract

8.4 UK GDPR and Data Protection Act 2018

Users in the United Kingdom are afforded similar rights under the UK GDPR and Data Protection Act 2018. Our legal bases for processing are equivalent to those described in Section 8.2, and you have the right to lodge a complaint with the UK Information Commissioner's Office (ICO).

8.5 California Users

If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA), including the right to know, delete, and opt-out of the sale of personal information. Refinix does not sell personal information.

8.6 How to Exercise Your Rights

To exercise any of these rights, contact us at: privacy@refinix.ai

We will verify your identity and respond within 30 days (or as required by applicable law). We may require additional information to verify your request.

9. Financial Disclaimer

Refinix does not provide financial, investment, legal, or tax advice. All insights, summaries, and data provided through the Service are for informational and research purposes only. AI-generated summaries and insights may contain inaccuracies or omissions and should not be relied upon as the sole basis for financial or investment decisions. You should consult qualified professionals before making any financial or investment decisions.

10. Children's Privacy

Refinix is not intended for minors or individuals under the age required to consent to data processing in their jurisdiction. We do not knowingly collect personal information from minors. If we become aware that a minor has provided us with personal information, we will delete such information and terminate the account.

11. International Data Transfers

Your information may be transferred to, stored in, and processed in countries outside the United Kingdom, including the United States and European Union, where our service providers operate. We rely on appropriate transfer safeguards where required by UK GDPR, including the UK Extension to the EU-US Data Privacy Framework and Standard Contractual Clauses (SCCs) with our subprocessors. For more information about the specific mechanisms we use, contact us at privacy@refinix.ai.

12. Updates to This Privacy Policy

We may update this Privacy Policy periodically to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes by updating the "Last Updated" date and, for significant changes, by sending you an email or displaying a prominent notice on our website.

Your continued use of Refinix after any changes constitutes your acceptance of the updated Privacy Policy.

13. Contact Us

If you have questions about this Privacy Policy or our privacy practices, please contact us at:

Refinix Ltd

Company number: 17198874

Registered office: 124-128 City Road, London, United Kingdom, EC1V 2NX

Email: privacy@refinix.ai

Website: www.refinix.ai

Refinix Ltd is the data controller for the purposes of the UK GDPR and Data Protection Act 2018.

We will respond to privacy inquiries within 10 business days.


This Privacy Policy is effective as of the Last Updated date. We recommend reviewing this policy regularly to stay informed about how we protect your privacy.