Privacy Policy
ReferenceOS, Inc. · Effective September 3, 2026
1. Information we collect
- Account and profile — name, email, password credentials handled by our authentication provider, business profile details, and profile photo.
- Connections and references — people you add: names, contact details, roles, relationship context, and reference status.
- Project photos and media — images and files you or your customers upload, stored privately.
- Notes and stories — private notes, project history, and testimonial text.
- Matching identifiers and preferences — attributes such as location, project type, or traits used to match the right reference to the right prospect.
- Permissions and consent records — whether a person agreed to be contacted, photographed, quoted, or shown publicly, and when that changed.
- Generated and shared page activity — privacy-safe events such as a page being viewed or a contact link being tapped.
- Referral and invitation submissions — information submitted through your referral forms, portals, and invitation links.
- Billing account metadata — subscription status, plan, renewal dates, and a payment-processor customer identifier. We do not receive or store raw payment card numbers; card data goes directly to our payment processor.
- Usage, device, and security logs — IP address, browser and device information, timestamps, and error or security events.
- Communications — messages you send us, support requests, and feedback.
2. How we use information
- provide, operate, and maintain the Service;
- authenticate you and protect accounts and workspaces;
- generate the pages, matches, portals, and links you ask for;
- process subscriptions and payments;
- provide support and respond to your requests;
- monitor performance, debug, and improve and secure the Service;
- detect, prevent, and investigate abuse or fraud;
- send service and account communications, and marketing you can opt out of;
- comply with legal obligations and enforce our Terms.
3. Private by default
A ReferenceOS Personal/Pro workspace belongs to its individual owner. Connections, notes, identifiers, project history, private media, referral records, and reference eligibility are private. Nothing becomes public or shareable automatically: a person is not activated as a reference, contact details are not exposed, and photos are not published unless the owner takes a deliberate action and the required permission is recorded.
4. Pages you choose to share, and their risks
Trust Pages, reference pages, and customer portal links are designed to be shared. When you share one, the information on it can be seen by anyone with the link, and recipients may forward it. Please share only what you and the people involved are comfortable making visible, and revoke or update a link when circumstances change. Public and shared surfaces are permission-checked on every request, so revoking a permission removes the content going forward.
5. Service providers and subprocessors
We use vetted providers to run the Service, and share only what they need:
- Supabase — database, authentication, and file storage;
- Stripe — subscription billing and payment processing;
- Lovable — application development and deployment infrastructure;
- hosting, content delivery, product analytics, error monitoring, and email or messaging providers, as applicable.
We may also disclose information in connection with a merger, acquisition, or sale of assets, or where required by law or valid legal process.
6. We do not sell your personal information
We do not sell personal information to advertisers, and we do not share your connections' contact details with advertisers or data brokers.
7. Retention
We keep information for as long as your account is active and as needed to provide the Service. After deletion, data may persist briefly in encrypted backups and logs before being removed on a routine cycle. We may retain limited records where necessary for legal, tax, security, or dispute-resolution purposes.
8. Security
We use access controls, row-level database authorization, private storage with short-lived signed links, encryption in transit, and server-side permission checks on public surfaces. No system is perfectly secure, and we do not claim any certification or formal compliance attestation we have not independently completed. Report a concern to security@referenceos.app.
9. Roles: controller and processor
For your own account information and our marketing, ReferenceOS acts as a controller. For the information you store about your connections and customers, you are the controller and ReferenceOS acts as a processor handling that data on your instructions. If someone contacts us about data you control, we will generally refer them to you and support you in responding.
10. Your privacy requests
Depending on where you live, you may have the right to access, correct, delete, port, or restrict processing of your personal information, and to withdraw consent or object to certain uses. Email privacy@referenceos.app and we will verify your request and respond within the time required by applicable law. We will not discriminate against you for exercising these rights.
11. Cookies and local storage
We use cookies and browser local storage for essential purposes: keeping you signed in, remembering workspace preferences, and preserving link or attribution context through signup. We may use limited first-party analytics to understand product usage. We do not run advertising trackers or cross-site advertising cookies.
12. Children
The Service is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has provided us information, contact privacy@referenceos.app and we will delete it.
13. International processing
We are based in the United States and our providers may process information in the United States and other countries. Where required, we rely on appropriate safeguards for cross-border transfers.
14. Changes and contact
We may update this Policy. Material changes will be announced with reasonable notice and a new effective date. Questions: privacy@referenceos.app or support@referenceos.app.