Last updated: 2 August 2026
Who we are
ReOpenly is operated by SENZAFINE DESENVOLVIMENTO DE SISTEMAS LTDA, CNPJ 08.212.387/0001-51, Rio de Janeiro, Brazil (“ReOpenly”, “we”). We are the controller of the personal data described here, under Brazilian Law 13.709/2018 (LGPD).
For anything in this policy, including requests about your data, write to reopenly@gmail.com.
What we collect
Account data. Your email address and the identifier issued by our authentication provider when you sign in. We do not store a password.
Content you create. Projects, datasets, chats, fine-tuning jobs and the models you host. This is the material you upload or author.
Prompts and responses. The text you send for inference and the text the model returns. These are processed to answer your request. They are stored in three cases, and in no others:
- Playground conversations. Conversations you have in the Playground are saved to your account so you can return to them, and are listed there under History. You can delete any of them yourself, at any time, and doing so removes the conversation and every message in it.
- Auto-save. When you have switched it on for a project, a sampled share of that project’s inference is saved into that project’s dataset, for that project’s owner only, described below.
- Datasets you author or upload, which are content you created.
Requests made through the API outside those cases are not stored.
Usage and billing records. Credit purchases, credit consumption per request or training job, and API key usage. These form your billing history.
Analytics. If you accept analytics cookies, product analytics about how you use the interface, associated with your account identifier. If you decline, no analytics are collected.
Why we process it, and on what basis
| Purpose | LGPD basis |
|---|---|
| Providing the service you asked for | Execution of a contract (Art. 7, V) |
| Charging for use, and keeping billing records | Execution of a contract, and compliance with a legal obligation (Art. 7, II) |
| Security, abuse prevention and fault diagnosis | Legitimate interest (Art. 7, IX) |
| Product analytics | Consent (Art. 7, I), which you may withdraw at any time |
We do not train on your data
We do not use your datasets, prompts or responses to train our own models, and no other customer can reach them.
If you switch on auto-save for a project, a share of the inference in that project is saved into that project’s dataset, so that you can fine-tune your model on it. It stays yours. Sharing a model with another user does not share the data it was trained on, and someone else calling a model you shared never has their prompts saved into your project.
Who else processes your data
We use third parties to run the service. We disclose them by category rather than by name, because the specific vendors are commercially sensitive:
- cloud hosting and storage;
- GPU compute providers, which process your prompts and datasets in order to run inference and fine-tuning;
- payment processing;
- authentication;
- product analytics, only with your consent;
- operational logging and monitoring.
They may process your data only on our instructions and for these purposes. If you want to know which specific companies have received your data, ask at reopenly@gmail.com and we will tell you, as LGPD Art. 18 provides.
Data outside Brazil
Some of these providers process data outside Brazil, primarily in the United States. That includes prompts and datasets sent for inference or fine-tuning, and stored files.
We require these providers to protect your data to the standard the LGPD sets.
How long we keep it
We keep your account, content and billing records for as long as your account exists.
Archiving a project does not delete it. Archiving hides a project and frees a slot; its datasets, jobs, models and records remain, because a project can be archived long after work was paid for and that history has to stay auditable.
Billing records are kept after an account closes, for as long as tax and commercial law requires, because they are the record of money that changed hands.
Your rights, and how to use them
Under LGPD Art. 18 you may ask us to confirm whether we process your data; access it; correct it; anonymise, block or delete unnecessary or excessive data; port it; delete data processed with your consent; tell you who we shared it with; tell you what happens if you refuse consent; and withdraw consent.
Write to reopenly@gmail.com. We will confirm who you are before acting, so that nobody else can make a request about your data.
Deletion. Ask, and we will delete your account, your datasets, your prompts and responses, your fine-tuned models and the adapters produced from them. We will keep billing records, because we are required to. We will tell you exactly what was removed and what was kept.
Deleted data is removed from our live systems immediately. It can persist in routine database backups until those expire on their normal rotation, after which no copy remains.
How long we take. If you ask us to confirm that we process your data, or to give you a copy of it, we answer in a simplified form straight away and provide the complete declaration within 15 days, as LGPD Art. 19 requires. For deletion, which takes manual work across several systems, we complete it within 30 working days and confirm when it is done.
Analytics consent can be withdrawn at any time from the cookie banner, without contacting us.
Security
Access requires authentication. API keys are stored as irreversible digests: we cannot recover your key, and a key is shown in full only once, when you create it. Traffic is encrypted in transit. Analytics do not run until you consent.
No system is perfectly secure, and we do not claim otherwise.
Changes
If we change this policy we will update the date above and post the new version here. Please check back from time to time.
Language
This policy is published in English and in Portuguese. The English version is the governing one. The Portuguese text is a translation provided for convenience, and where the two differ, the English text prevails.