Reef

Privacy Policy

Last updated: 8 June 2026

Who we are

Reef is operated by Endos. We can be reached at dev@endos.io. Reef is a marketplace for AI agents. This policy explains what personal data we collect, why, and what rights you have.

What we collect

  • Account data — email address (always), and for sellers, the name, surname, phone, company name, company domain, and SSO identity you provide during onboarding.
  • Authentication data — session tokens and refresh tokens used to keep you signed in. Stored as HTTP-only cookies; not visible to client-side JavaScript.
  • Onboarding answers — your responses to the seller questionnaire (what kind of agents you build, your experience, etc.). Used to tailor the product to you.
  • Technical data— IP address, browser version, OS, and pages visited. Used for security, fraud prevention, and aggregate analytics. We do not store IP addresses against your account beyond what's needed for rate limiting.

How we use it

  • To create and maintain your account.
  • To authenticate you on sign-in.
  • To respond to support requests and product feedback.
  • To analyse aggregate product usage (without tracking individuals).
  • To prevent abuse, fraud, and unauthorised access.

We do not sell your personal data to third parties. We do not use your data to train AI models.

Third-party processors

We rely on these vendors to operate Reef:

  • SuperTokens — authentication. We self-host the auth core.
  • Google Workspace SSO — for sellers who choose to sign in with their corporate identity.
  • Neon — managed PostgreSQL database hosting in the EU (eu-west-2).
  • Railway — application hosting.
  • Cloudflare — DNS, edge security, and aggregate web analytics (cookie-free).

Each vendor processes data only on our instructions and is contractually bound to security and confidentiality terms.

How long we keep it

Account data is kept for as long as your account is active. If you delete your account (by emailing us), we delete the account row and associated profile within 30 days. Aggregate analytics that contains no personal identifier may be retained indefinitely.

Your rights

If you are in the EU/UK, you have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data
  • Object to or restrict processing
  • Request a portable copy of your data

To exercise any of these, email dev@endos.io. We respond within 30 days.

Security

We use HTTPS everywhere, HttpOnly + Secure cookies, anti-CSRF tokens, and rate limiting. Passwords are never stored — they're hashed by SuperTokens before they reach our database. We aim for industry-standard practices but no online service can guarantee absolute security.

Changes to this policy

We may update this policy. When we do, we'll change the "Last updated" date above. Material changes will be announced via email to active users.

Contact

Questions? Email dev@endos.io.