Reconstruct Privacy Policy
Effective date: October 11, 2026 Last updated: October 11, 2026
This Privacy Policy explains how Cryptify Corporation ("Cryptify", "we", "us") collects, uses and shares personal information when you use Reconstruct, including the website at reconstruct.dev, the Platform, documentation, status page, the Reconstruct MCP server, the public API and related services (together, the "Service").
Cryptify Corporation is a corporation organized under the laws of Delaware, file number 10430008, with its registered address at 8 The Green, STE R, Dover, DE 19901, USA. Phone: +1 323 554 8150. Contact us about privacy at [email protected].
1. Information we collect
1.1 Information you give us
- Account information. Email address (used as your login), first and last name, username, password (stored only as a hash by our identity service), email verification status and an optional profile picture. If you sign in with Google or Apple, we receive your name, email address and an account identifier from that provider.
- Capture requests. The URL of the product you ask us to capture, its topic, target platform and view, and any other details you enter in the request. Product requests are public. Resulting captures and analysis may enter the shared catalog. Public request views exclude account identity, private contact details and internal review notes. Do not include confidential information in public fields.
- Support, abuse and sales requests. Your name, email address and the content of your message when you use our support or abuse forms, and the details you provide when booking a call with our sales team.
- Status subscriptions. Your email address if you subscribe to status notifications.
1.2 Information collected automatically
- Sessions and tokens. Sign-in sessions, OAuth authorizations granted to AI agents and MCP clients, and personal access tokens you create (with their name, scopes and expiry of up to 365 days).
- Device and security information. After the required registration acknowledgement covering device identification is recorded, the Platform stores a device identifier in your browser (
device_seed) and reads browser characteristics such as screen parameters, canvas and graphics (GPU) characteristics, memory and CPU core count, user-agent client hints (platform, OS version, device model, architecture), time zone and languages. We also receive your IP address and approximate country from our network provider (Cloudflare). See Sections 3 and 6. - Usage information. Requests you make, API and MCP calls, quota usage, plan limits reached and similar service logs.
- Diagnostics. Error reports and performance traces (sampled at approximately 10% of requests) from our websites and APIs. We configure diagnostics not to collect passwords or sign-in tokens.
1.3 Information from third parties
- Payments. The provider identified at checkout processes payment information and may provide us with customer and transaction identifiers, billing contact/address, subscription status, plan, billing period and payment status. Providers and payment methods may differ by region. The recipients are listed in our provider notice. Card numbers are collected by the payment provider on its page, not typed into Reconstruct.
- Sign-in providers. Google and Apple, if you choose to use them.
1.4 Captured websites and application analysis
The Service captures the structure and appearance of lawfully accessible websites and applications (screenshots, layout, styles, fonts, page technologies and recorded flows). Captured pages may incidentally contain personal information of people who appear on those websites. We do not use captures to identify individuals. If you believe a capture contains your personal information, contact [email protected] and we will review and remove it where appropriate. Copyright complaints are handled under our Copyright and DMCA Policy.
For supported iOS, Android and desktop analysis, inputs may include lawfully obtained application files, source code, metadata and observations from test environments. These may contain personal information or confidential data even when the output is only a description. Do not submit production personal data, credentials or private code without an expressly agreed workflow. We distinguish analysis inputs from the behavioral descriptions, UI structure and original findings delivered to users. See our Analysis Methodology. Private application analysis runs only through a workflow we have expressly agreed with you.
2. How we use information
We use personal information to:
- create and manage your account and authenticate you, your AI agents and API clients;
- provide the Service, process capture requests and deliver captured data through the Platform, MCP and API;
- process payments, manage subscriptions and enforce plan limits;
- prevent fraud, abuse and multi-accounting, and secure the Service (Section 3);
- check that submitted URLs are not malicious (Section 4);
- respond to support, abuse, sales and legal requests;
- send service and status notifications you requested and important account or legal notices;
- diagnose errors, monitor availability and improve the Service, including model training on eligible public capture requests and captures, subject to applicable privacy law and third-party rights. Account credentials, payment information, support messages, confidential/private inputs and customer personal data processed under a DPA are excluded from that training;
- comply with law and enforce our Terms of Service.
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We do not use third-party advertising or analytics trackers on the Service.
3. Fraud prevention and automated decisions
To protect free and paid quotas and prevent abuse, the Platform links the device information described in Section 1.2 to your account, groups devices and accounts that appear to belong to the same person (up to five accounts per person), and computes a trust score from security events (for example, repeated quota denials, unusual session patterns or excessive automated use).
Depending on the trust score, we may automatically limit features, suspend capture requests, or suspend or ban an account. Device identification is collected only after the required registration acknowledgement covering this processing is recorded. Withdrawing it stops further collection of the device identifier and browser characteristics. It does not stop trust scoring of account activity, subject to any applicable right to object or opt out. You may exercise an applicable profiling opt-out separately from an appeal. If a restriction is based only on that score, you may ask us not to keep it in effect until a person reviews your appeal at reconstruct.dev/platform/trust. Scoring continues during the review. Some session-based checks assess activity within a rolling 24-hour window. Security records are retained for the periods in Section 7.
4. How we share information
We share personal information only as described below:
- Service providers and subprocessors that host, operate or support the Service on our behalf, under contractual confidentiality and security obligations. The current list is in our Subprocessors list.
- URL safety checks. URLs you submit for capture may be sent to threat-intelligence services (such as Google Web Risk / Safe Browsing, VirusTotal, urlscan.io, AlienVault OTX, PhishTank, URLhaus and domain registration (RDAP) services) to detect malware, phishing and newly registered domains. Do not include secrets, credentials or private query parameters in a URL you submit. A safety service may store the URL it receives and may share it with its own partners.
- AI processing and model improvement. We may use eligible public capture requests and captures for model improvement only where permitted by applicable law and third-party rights. We exclude credentials, account/payment information, support messages and confidential/private inputs from training. We may also send selected capture and analysis fields to third-party AI model providers (for example OpenAI, Anthropic or Google). Any use by a provider for its own model training is subject to the disclosures, contractual restrictions and legal requirements applicable to that service. Capture data can itself contain personal information. Customer personal data that we process only under a data-processing agreement is not used for this improvement or training. Private application inputs are not sent to an AI provider unless that workflow was expressly agreed.
- Payments and sign-in. The payment provider identified at checkout and any sign-in provider you choose, as described above.
- Legal reasons. When required by law, subpoena or other legal process, or to protect the rights, property or safety of Cryptify, our users or others.
- Business transfers. In connection with a merger, acquisition, financing or sale of assets, subject to this Policy.
- With your direction. For example, when you connect an AI agent or MCP client, that client receives the data you request through it under its own terms.
5. Where we store information
Cryptify is based in the United States. The Service's databases, capture files and identity service are hosted by Hetzner Online GmbH in Germany. Error diagnostics (Sentry), support tickets (YouTrack) and sales scheduling (Cal) run on servers in Poland operated by HostBiz. Backups and remote support access may be in those countries or elsewhere. Our other service providers may process information in the United States and other countries. Where we transfer personal information from the EEA, the UK or Switzerland, we use the safeguards required by applicable law, such as Standard Contractual Clauses and the UK Addendum where they apply. You may request a description of those safeguards at [email protected].
6. Cookies and similar technologies
We use strictly necessary cookies and browser storage for sign-in and security. We store a device identifier and read browser characteristics only after the required registration acknowledgement covering this security and abuse-prevention processing is recorded. Registration cannot proceed without that acknowledgement; it does not waive your mandatory rights. Details and withdrawal are in our Cookie and Device Notice.
Do Not Track. We do not track you across third-party websites and do not use advertising trackers, so we do not change our practices in response to browser Do Not Track signals.
7. Data retention
We keep personal information only as long as needed for the purposes above:
| Data | Retention |
|---|---|
| Account and profile | Until you delete your account, then up to 30 days for backups |
| Personal access tokens | Until expiry (max. 365 days) or revocation |
| Captures stored for your account | Until account deletion, then up to 30 days |
| Public catalog entries | While the entry remains useful for the catalog, subject to periodic necessity review and earlier removal where appropriate following a privacy, copyright or abuse request. Removal does not depend on account ownership |
| Application-analysis inputs and temporary files | While the analysis is active, then up to 30 days, unless a signed agreement sets a shorter period |
| Fraud-prevention sessions, devices, trust score, security events and appeals | For the life of the account, then 12 months. A rolling 24-hour window is used only to calculate session signals, not as the deletion period |
| Billing records | As required for tax and accounting (typically up to 7 years) |
| Support and abuse tickets | 24 months after the last message in the ticket |
| Status subscription email | Until you unsubscribe |
| Diagnostics (errors, traces) | 90 days |
8. Your choices and rights
- Access, correction and deletion. You can update your profile in the Platform. Request account deletion by emailing [email protected] from your account email. We process these requests manually. We will respond within the period required by applicable law, generally one month for GDPR requests, and explain any permitted extension. Account deletion revokes account access and initiates deletion or de-identification of personal account and request records under the retention schedule. Lawfully retained records and independently collected public catalog material are treated separately; personal information in catalog entries can also be the subject of a rights request.
- Tokens and agent access. You can revoke personal access tokens and agent authorizations in the Platform at any time.
- Emails. Every status email contains an unsubscribe link. We may still send essential account and legal notices.
- Subscriptions. You can manage or cancel your subscription through Billing using the method applicable to your payment provider, or contact [email protected] if that method is unavailable.
U.S. state privacy rights. Depending on your state of residence (for example California, Colorado, Connecticut, Virginia and others), you may have the right to know, access, correct, delete and port your personal information, and to opt out of the sale or sharing of personal information. We do not sell or share personal information as those terms are defined. You may withdraw device-identification consent as described in Section 6. Where applicable law grants an opt-out from certain profiling, you may exercise that right at [email protected]. You may also appeal an automatic restriction and request human review. An appeal is separate from any statutory opt-out. Fraud/security exceptions apply only to the extent the law permits. To exercise any right, email [email protected] or use the appeal page; you may use an authorized agent. We will verify your request and will not discriminate against you for exercising your rights. If we deny your request, you may appeal by replying to our decision.
European Economic Area and United Kingdom. The Service is not offered to people in the EEA or the UK. Cryptify has no establishment there and has not appointed a representative under Article 27 GDPR or the UK GDPR. Do not register an account or pay for the Service from the EEA or the UK.
If we nevertheless process personal data of a person in the EEA or the UK, the GDPR or UK GDPR may apply. We act as controller for account administration and our own catalog and security activities. Where we process customer personal data solely on documented customer instructions, the applicable Data Processing Addendum governs our processor role. Our independent account, catalog and security activities remain subject to this Privacy Policy. We rely on these legal bases:
| Purpose | Legal basis |
|---|---|
| Account, Service delivery, capture requests, payments | Performance of our contract with you |
| Device identifier and browser characteristics | Consent where required by applicable law, or a permitted basis for necessary security processing. The registration agreement does not waive applicable consent, withdrawal or objection rights |
| Fraud prevention, trust score, security, diagnostics, URL safety checks, IP address and approximate country | Our legitimate interests in securing the Service and preventing abuse |
| Improving the Service, including training models on capture requests and captures | Processing is limited to a legal basis permitted for the relevant training activity. Private/DPA inputs and account, payment and support information are excluded |
| Tax, accounting, responses to legal requests | Legal obligation |
| Requested status subscriptions and optional processing that requires consent | Consent where required; withdrawal does not affect prior lawful processing |
| Sign-in using a provider you choose | Service delivery at your request; the sign-in provider has its own role and privacy terms |
| Personal information incidentally included in public catalog material | Our legitimate interests in maintaining a shared catalog of interface references. You can ask us to remove your personal information from a catalog entry |
You have the right to access, correct, delete, restrict and port your personal information, to object to processing based on legitimate interests, and to withdraw consent. For an automatic trust-score restriction (Section 3), you can ask that it not stay in effect until a person reviews it, express your point of view and contest the decision through the appeal page or [email protected]. You may also complain to your local data protection authority.
You retain any protections under applicable law against significant decisions based solely on automated processing. The regional availability restrictions do not limit rights that otherwise apply to your personal data.
For legal enquiries, contact [email protected] in English.
Switzerland. If you are in Switzerland and we process your personal data, Swiss data protection law may apply. Your rights are determined by the applicable Swiss data-protection requirements. Contact [email protected] to exercise applicable rights. The EEA and UK availability restrictions do not include Switzerland.
Other countries. If you live elsewhere (for example Canada, Brazil, India, Australia or Japan), you may have similar rights under local law. Contact [email protected] to exercise them.
9. Security
We protect personal information with measures including encrypted connections, hashed passwords, encrypted storage of service secrets, access controls and monitoring. No system is completely secure; please keep your password and tokens confidential.
10. Children
The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us information, contact [email protected] and we will delete it. If you are under the age of majority where you live, you may use the Service only with the involvement of a parent or guardian. We do not ask for or check your age at registration.
11. Changes to this Policy
We may update this Policy. We will post the updated version with a new "Last updated" date and, for material changes, notify you by email or in the Service before they take effect.
12. Contact
Cryptify Corporation Delaware file number 10430008 8 The Green, STE R, Dover, DE 19901, USA Phone: +1 323 554 8150 Privacy: [email protected]