Privacy Policy
Last updated July 18, 2026
This Privacy Policy for Agent Horizon, LLC ("we," "us," or "our") explains how and why we may access, collect, store, use, and share ("process") your personal information when you use our services (the "Services"), including when you:
- Visit our website at https://reanthesis.com, or any website of ours that links to this Privacy Policy
- Use Reanthesis — a spaced-repetition study application, available on the web and iOS, that schedules your flashcards with FSRS so what you learn keeps blooming back
- Connect Reanthesis to an AI assistant through our connector for the Model Context Protocol (MCP)
- Join our waitlist, contact us, or otherwise engage with us, including marketing and events
Reading this policy will help you understand your privacy rights and choices. We are responsible for deciding how your personal information is processed. If you do not agree with our practices, please do not use the Services. Questions? Email privacy@reanthesis.com.
Summary of key points
- What we process: account details (email, a password we store only in hashed form, an optional name), your study content (decks, cards, tags, attached images, review history), and technical data like server logs. Details in Section 1.
- Sensitive personal information: we do not request or require any, and we do not process sensitive personal information as a category of business data.
- Third-party sources: we do not collect information about you from third parties.
- Why we process it: to run your account, schedule your reviews, keep the Services secure, communicate with you, and comply with law — only where we have a valid legal reason. Details in Section 2.
- Sharing: only with the service providers who run our infrastructure and power our AI features (listed in Section 4; they never receive your account information), and with an AI assistant you choose to connect. We do not sell your personal information and we do not share it for advertising.
- Security: we use reasonable organizational and technical safeguards, but no system connected to the internet can be guaranteed 100% secure. Details in Section 9.
- Your rights: depending on where you live, you may have rights to access, correct, delete, or export your information. Details in Section 11, Section 13, and Section 14.
- Exercising rights: use the app's account settings or email privacy@reanthesis.com.
1. What information do we collect?
Information you give us
In short: we collect the personal information you choose to provide.
When you create an account, join the waitlist, use the Services, or contact us, we collect information you provide voluntarily. What we collect depends on how you use the Services and may include:
- Email address
- Password (we store only a one-way cryptographic hash, never the password itself)
- Name (optional — accounts work without one)
- Your study content: decks, cards, tags, notes you import (for example from Anki), images you attach to cards, and your review history
Sensitive information. We do not request or require sensitive personal information (such as racial or ethnic origin, health data, or religious beliefs), and we do not process any as a category of business data. Your Study Content is content you provide or authorize us to process; we process it only to provide the Services, as described in Section 15. This policy describes our data practices and does not grant rights to third-party content. Your rights and responsibilities for imported content are in our Terms of Service.
Payment data. Paid subscriptions are not yet enabled. When they launch, payments will be collected and stored by Stripe, our payment processor — we will not store your full card number. Stripe's privacy notice: https://stripe.com/privacy.
All personal information you provide must be true, complete, and accurate, and you should tell us when it changes.
Information collected automatically
In short: limited technical data — such as IP address and device characteristics — is collected automatically when you use the Services.
Like most online services, our servers automatically record certain information when you use the Services. This data does not reveal your specific identity on its own, and we need it mainly to keep the Services secure and operating. It includes:
- Log and usage data: IP address, browser or device type, operating system, timestamps, the pages or API endpoints you accessed, and error reports.
- Device data: basic characteristics of the computer, phone, or tablet you use — device model, operating system, and system configuration.
- Approximate location: a coarse region inferred from your IP address (never GPS — we do not collect precise location), and the timezone your device reports so review scheduling matches your day.
- Bot-protection signals: our signup, waitlist, and password-reset forms use Cloudflare Turnstile, which analyzes request characteristics to tell humans from bots.
We do not run third-party analytics or advertising trackers. See our Cookie Notice at https://reanthesis.com/cookies.
Face ID / Touch ID. If you enable biometric unlock in the iOS app, biometric processing happens entirely on your device through Apple's APIs. Biometric data never reaches our servers.
2. How do we process your information?
In short: to provide, improve, and secure the Services, communicate with you, and comply with law. We process personal information for the purposes below, and for other purposes only with your prior consent.
- Accounts and authentication — creating your account, signing you in, and keeping your account in working order (including emailing verification codes).
- Delivering the Services — storing your cards, running FSRS scheduling, syncing across your devices, and providing features you request.
- Support — responding to your questions and fixing problems.
- Administrative messages — telling you about changes to the Services, our terms, or our policies.
- Orders and billing — managing subscriptions, payments, and refunds once billing is available.
- Feedback — asking about your experience so we can improve.
- Marketing — sending occasional product news consistent with your preferences; you can opt out at any time (see Section 11).
- Security and fraud prevention — protecting the Services, our users, and their data, including monitoring for abuse.
- Usage trends — understanding, in aggregate, how the Services are used so we can improve them.
- Vital interests — where necessary to protect someone's life or safety.
- Legal compliance — meeting our obligations under applicable law.
3. What legal bases do we rely on?
In short: we process your personal information only when we have a valid legal reason — your consent, a contract with you, our legal obligations, your vital interests, or our legitimate interests.
If you are in the EU or UK, the General Data Protection Regulation (GDPR) and UK GDPR require us to name our legal bases:
- Consent. Where you have given permission for a specific purpose. You may withdraw consent at any time (see Section 11).
- Performance of a contract. Where processing is necessary to provide the Services you signed up for, or to take steps you request before entering a contract.
- Legitimate interests. Where processing is reasonably necessary for our business interests and those interests are not outweighed by your rights and freedoms — for example: analyzing aggregate usage to improve the product, diagnosing problems and preventing fraud or abuse, securing the Services, and telling users about relevant features or offers with the ability to opt out.
- Legal obligations. Where we must comply with law, cooperate with regulators or law enforcement, or defend our legal rights.
- Vital interests. Where necessary to protect your vital interests or someone else's, such as a threat to a person's safety.
If you are in Canada, we process your information with your express or implied consent, which you can withdraw at any time. In limited cases the law permits processing without consent — for example: where collection is clearly in an individual's interest and consent cannot be obtained in time; for fraud detection, investigations, or law enforcement; for certain business transactions; where required by subpoena, warrant, or court order; where the information is publicly available as specified by regulation; or where obtaining consent would compromise the accuracy or availability of information needed to investigate a breach of an agreement or contravention of law.
4. When and with whom do we share your information?
In short: with the service providers who run our infrastructure, with an AI assistant you choose to connect, and in a business transfer. We do not sell your personal information.
Service providers. We share data with third-party vendors who perform services on our behalf and need access to do that work. Each is bound by a contract that restricts them to processing your data only on our instructions, protecting it, and not sharing it with anyone else. They are:
| Provider | What they do for us |
|---|---|
| Amazon Web Services (AWS) | Cloud hosting — our servers, database, and file storage |
| Stripe | Payment processing and billing (when subscriptions launch) |
| Cloudflare | Bot protection (Turnstile) on signup and waitlist forms |
| Resend | Transactional email delivery (verification codes, waitlist invites) |
| AI service providers | Process portions of your study content to power AI features (see Section 6); they never receive your account information |
AI assistants you connect. If you connect Reanthesis to an AI assistant (for example Claude, ChatGPT, or GitHub Copilot) through our MCP connector, that assistant can — at your direction — read and write your decks, cards, and tags. This sharing happens only because you authorize it, and you can disconnect at any time. See Section 6.
Business transfers. We may share or transfer your information in connection with a merger, financing, acquisition, or sale of all or part of our business.
5. Do we use cookies and tracking technologies?
In short: only what sign-in and your preferences need. No advertising trackers, no third-party analytics.
We use first-party browser storage (cookies, localStorage, and similar device storage) to keep you signed in, remember your preferences, and keep the Services secure. Cloudflare Turnstile may use its own storage on pages where it protects a form. We do not permit third parties to place advertising or cross-site tracking technologies on the Services, and we do not use online tracking for targeted advertising — so we have no "sale" or "sharing" of personal information to opt out of under US state laws (see Section 13).
Details, including how to control or clear this storage, are in our Cookie Notice: https://reanthesis.com/cookies.
6. Do we offer AI-based features?
In short: yes. AI features process portions of your study content through third-party AI service providers — but never your account information. You can also connect your own AI assistant.
AI features. Some Reanthesis features are powered by artificial intelligence — for example, matching a description of what you studied against your dormant cards to suggest which ones to wake. To run these features, portions of your Study Content (such as tag names and card text) and the instructions you type into the feature are processed by third-party AI service providers as part of our pipeline, under our agreements with them. We do not transmit your account information, email address, name, or IP address to AI providers. These features run only when you use them.
Your own AI assistant. Reanthesis also provides a connector implementing the Model Context Protocol (MCP) at reanthesis.com/mcp. If you authorize an AI assistant against your account (via OAuth), that assistant can list, create, and manage your decks, cards, and tags on your behalf — for example, drafting flashcards from your lecture notes.
- The connection exists only if you create it, and only with the assistant you choose. You can revoke it at any time from your assistant's settings, and any content you share with the assistant itself (like the notes you paste into a chat) is governed by that provider's own privacy policy.
- We do not transmit your email address, password, IP address, or other account information to the assistant's provider beyond what the connection you authorize requires.
- We do not use your study content to train AI models, and we do not sell it. See Section 15.
7. Is your information transferred internationally?
In short: our servers are in the United States; if you use the Services from elsewhere, your information is processed in the US.
Our infrastructure runs in the United States. Wherever you are located, your information may be transferred to, stored in, and processed in the United States by us and by the service providers listed in Section 4. Some service providers — including the AI service providers described in Section 6 — may process data in other countries.
If you are in the European Economic Area (EEA), United Kingdom, or Switzerland, be aware that the countries where your information is processed may not provide data protections as comprehensive as your home country's. We protect your information in accordance with this policy wherever it is processed. Our infrastructure providers — AWS, Stripe, Cloudflare, and Resend — commit to recognized transfer safeguards, including the European Commission's Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework, in the data processing agreements we hold with them. Further details are available on request.
8. How long do we keep your information?
In short: as long as you have an account, unless the law requires longer.
We keep your personal information only as long as needed for the purposes in this policy — in general, no longer than you keep your account — unless a longer period is required or permitted by law (for example, tax or accounting rules). Waitlist emails are kept until we invite you, you ask to be removed, or the waitlist ends. When there is no ongoing legitimate need to keep your information, we delete or anonymize it; if immediate deletion is impossible (for example, in backup archives), we isolate it from further processing until deletion can occur.
9. How do we keep your information safe?
In short: with reasonable technical and organizational safeguards — but no internet service can promise perfect security.
We use appropriate technical and organizational measures designed to protect your personal information, including encryption in transit, hashed password storage, and access controls. However, no electronic transmission or storage technology is guaranteed 100% secure, and we cannot promise that hackers or other unauthorized parties will never defeat our defenses. You use the Services at your own risk and should access them from a secure environment.
10. Do we collect information from minors?
In short: no — the Services are for adults.
We do not knowingly collect data from, solicit, or market to anyone under 18 years of age (or the equivalent age of majority in your jurisdiction), and we do not knowingly sell such information. By using the Services you represent that you are at least 18, or that you are the parent or guardian of a minor user and consent to their use. If we learn we have collected personal information from someone under 18, we will deactivate the account and take reasonable steps to delete the data promptly. If you become aware of any such data, contact us at privacy@reanthesis.com.
11. What are your privacy rights?
In short: depending on where you live, you can review, change, export, or delete your personal information — and your account — at any time.
Regional rights. In some regions (including the EEA, UK, Switzerland, and Canada), applicable law gives you rights that may include: (i) access to and a copy of your personal information, (ii) correction or erasure, (iii) restriction of processing, (iv) data portability where applicable, (v) objection to processing, and (vi) the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects — if such a decision is ever made, we will tell you, explain the main factors, and offer a simple way to request human review. Exercise any of these by contacting us (Section 17); we will act on requests as applicable law requires.
If you are in the EEA or UK and believe we are processing your information unlawfully, you may complain to your national data protection authority. In Switzerland, you may contact the Federal Data Protection and Information Commissioner.
Withdrawing consent. Where we rely on consent (express or implied, depending on your jurisdiction), you can withdraw it at any time by contacting us. Withdrawal does not affect the lawfulness of processing before withdrawal, or processing based on other legal grounds.
Marketing opt-out. Unsubscribe any time via the link in our emails or by contacting us — we will remove you from marketing lists. We may still send non-marketing service messages your account needs (for example, verification codes and policy-change notices).
Account information. To review or change your account details, use the app's account settings or contact us. To close your account, use Delete account in the app's settings or contact us; on deletion we remove your account and study content from our active systems, though we may retain limited information as needed to prevent fraud, troubleshoot, enforce our terms, or comply with law.
Browser storage. You can clear or block cookies and site storage in your browser settings; parts of the Services (like staying signed in) may stop working. See our Cookie Notice.
12. Do-Not-Track signals
Most browsers, and some mobile operating systems, offer a Do-Not-Track ("DNT") setting. No uniform standard for honoring DNT signals has been finalized, so we do not currently respond to them. If a standard we must follow is adopted, we will describe our practice in a revised version of this policy. California law requires us to state how we respond to DNT signals: because there is no industry or legal standard, we do not respond to them at this time. Note that we do not track our users across third-party websites in the first place.
13. United States state privacy rights
In short: if you live in a state with a comprehensive privacy law (including California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, or Virginia), you may have rights to access, correct, delete, and export your personal information.
Categories of personal information we collect
The table below shows the categories defined by state law, with examples, and whether we have collected them in the past twelve months:
| Category | Examples | Collected |
|---|---|---|
| A. Identifiers | Name, email address, IP address, account name | YES |
| B. Personal information (California Customer Records) | Name, contact information | YES |
| C. Protected classification characteristics | Gender, age, race, national origin | NO |
| D. Commercial information | Transaction and payment records | NO — subscriptions are not yet enabled; this becomes YES (processed by Stripe) when billing launches |
| E. Biometric information | Fingerprints, faceprints | NO — Face ID/Touch ID never leaves your device |
| F. Internet or network activity | Usage of our Services, server logs | YES |
| G. Geolocation data | Device location | YES — coarse region from IP address only; no precise location |
| H. Audio, electronic, or similar information | Call recordings, voiceprints | NO |
| I. Professional or employment information | Job title, work history | NO |
| J. Education information | Student records and directory information | NO — your flashcards are content you author, not school records |
| K. Inferences from the above | Profiles about preferences and characteristics | NO |
| L. Sensitive personal information | Health data, precise geolocation, government IDs | NO |
We may also receive personal information outside these categories when you contact support, respond to surveys, or otherwise interact with us. We retain collected categories as long as you have an account with us (see Section 8).
Use, disclosure, and "sale"
We use and disclose personal information for the business purposes in Section 2, and disclose it to the service providers in Section 4 under written contracts. In the past twelve months we have not sold or shared (as those terms are defined under applicable state laws, including for targeted advertising) any personal information. Categories disclosed to service providers for business purposes: A, B, F, and G.
Your rights
Subject to legal limits, you may have the right to: know whether we process your personal data; access it; correct inaccuracies; delete it; obtain a copy of it; not be discriminated against for exercising your rights; and opt out of targeted advertising, sale, or profiling that produces significant effects (we do none of these). Depending on your state, you may also have rights to lists of the categories or specific third parties receiving your data, and to question or correct profiling decisions.
Exercising your rights
Email privacy@reanthesis.com. We will verify your identity against information we already hold before acting on a request, and may ask for more information solely for verification, security, or fraud prevention. You may use an authorized agent; we may deny an agent's request without written, signed proof of authorization. If we decline a request, you may appeal by emailing privacy@reanthesis.com; we will respond in writing with reasons, and if your appeal is denied you may contact your state attorney general.
California "Shine The Light"
California Civil Code §1798.83 permits California residents to request, once a year and free of charge, information about categories of personal information (if any) we disclosed to third parties for their direct marketing purposes. We do not disclose personal information to third parties for their direct marketing purposes. California residents may submit such a request using the contact details in Section 17.
14. Rights in other regions
Australia and New Zealand
We collect and process your personal information under the obligations of Australia's Privacy Act 1988 and New Zealand's Privacy Act 2020. This policy satisfies those Acts' notice requirements: what we collect, from which sources, for which purposes, and who receives it. If you do not provide information needed for a purpose, we may be unable to provide the relevant service — for example, creating your account, responding to requests, or protecting it. You may request access to or correction of your personal information at any time (Section 18). If you believe we are processing your information unlawfully, you may complain to the Office of the Australian Information Commissioner or the Office of the New Zealand Privacy Commissioner.
Republic of South Africa
You may request access to or correction of your personal information at any time (Section 18). If a complaint to us is not resolved to your satisfaction, you may contact the Information Regulator (South Africa): enquiries@inforegulator.org.za; complaints (POPIA/PAIA Form 5): PAIAComplaints@inforegulator.org.za and POPIAComplaints@inforegulator.org.za.
15. How is your study content managed?
Your decks, cards, tags, review history, imported collections, and attached images ("Study Content") are content you provide or authorize us to process. We store Study Content privately to deliver the Services — saving, syncing, scheduling, and displaying it to you. We do not sell Study Content, do not use it for advertising, and do not use it to train AI models. Our staff access it only when needed to operate the Services, such as debugging a problem or responding to your support request. Portions of Study Content are processed by third-party AI service providers when you use AI features, and shared with an AI assistant only when you connect one — both as described in Section 6; we never transmit your account information, email address, or IP address to AI providers. Deleting a card, deck, or your account removes the associated Study Content — including stored images — from our active systems.
16. Updates to this policy
In short: yes, we will update this policy as needed to stay compliant with relevant laws.
We may update this Privacy Policy from time to time; the revised version applies from the "Last updated" date above. For material changes we may post a prominent notice or notify you directly. Please review this policy periodically.
17. How to contact us
Email privacy@reanthesis.com, or write to:
Agent Horizon, LLC
254 Plainfield Rd Unit 11 #1006
West Lebanon, NH 03784
United States
18. Reviewing, updating, or deleting your data
You have the right to request access to the personal information we collect about you, details about how we process it, correction of inaccuracies, or deletion — and, where applicable, to withdraw consent to processing. These rights may be limited by applicable law. Use the app's account settings (including Delete account) or email privacy@reanthesis.com.