Privacy Policy
GDPR / UK GDPR Compliant
Full adherence to EU Regulation 2016/679 (Articles 6, 13, 15–22) with explicit legal bases and DPO oversight.
CCPA / CPRA Ready
California Consumer Privacy Act provisions including right to know, delete, and opt-out of data commercialization.
End-to-End Cryptography
Zero-knowledge AES-GCM-256 client-side message encryption. Unreadable by servers or third parties.
1. Information We Collect
D-R-E-I-N Space Inc. ("D-R-E-I-N", "We", "Us") collects information strictly necessary to operate our builder ecosystem, compute algorithmic synergy rankings, deliver real-time collaboration tools, and generate audience intelligence profiles.
1.1 Account & Identity Data
- Registration Profile: Email address, username, display name, biographical statement, builder mission, and skill tags.
- Authentication Artifacts: Cryptographic password hashes (salted SHA-256/PBKDF2), session bearer tokens, and MFA tokens.
- Subscription Status: Plan tier (Free, Pro, Recruiter), billing identifiers, and transaction records.
1.2 Public Builder Content
Public posts, build-in-public logs, code snippets, project status updates, comments, like interactions, and reputation scores submitted publicly across the Platform.
2. Geographic & Business Intent Telemetry Collection
TRANSPARENT DATA INTELLIGENCE DISCLOSURE: To power our recommendation algorithm, match co-founders across compatible timezones, and prepare our platform for future contextual partnership and sponsorship opportunities without deploying intrusive third-party banner ads, D-R-E-I-N collects granular behavioral signals and geographic telemetry as detailed below.
2.1 Geographic Location Signals
- Country & Region/State: Collected via user selection during registration, IP address geolocation mapping, and browser timezone resolution (e.g.,
America/New_York,Europe/London,Asia/Tokyo). - Timezone & Locale: Utilized for team matching synergy calculations, active build streak sync, and feed velocity normalization.
2.2 Business Interest & Category Affinities
We analyze interaction frequency, dwell duration, search queries, and bookmarking across key industry sectors:
- Artificial Intelligence & Machine Learning (AI/ML)
- Developer Tools & Cloud Infrastructure
- SaaS & Enterprise Automation
- FinTech, Decentralized Systems & Web3
- Consumer Platforms, Media & Gaming
- E-Commerce, Logistics & Marketplaces
- Hardware, Robotics & Embedded Systems
- Design Systems & Creative Productivity
3. How We Utilize Collected Data
We process your data for the following legitimate business purposes:
- Feed Ranking & Discovery: Computing the Drein Velocity Rank to surface high-relevance build logs, hiring posts, and co-founder opportunities tailored to your technical skills and industry preferences.
- Co-Founder & Squad Matching: Calculating synergy percentages based on complementary skills, timezone overlap, and build consistency.
- Audience Intelligence & Future Sponsorships: We collect and aggregate interest profiles to enable relevant, non-disruptive sponsor matchmaking and partner discovery. We do not display annoying third-party banner ads today, but we build structured telemetry to facilitate contextual sponsorships in future releases.
- Platform Security & Abuse Mitigation: Monitoring failed authentication bursts, preventing automated spam scripts, and enforcing rate quotas.
4. End-to-End Encrypted (E2EE) Messaging Privacy
All private conversations, direct messages, and team chat channels are encrypted client-side via the Web Cryptography API (SubtleCrypto) utilizing AES-GCM (256-bit) with authenticated encryption and ephemeral initialization vectors (IVs).
ZERO SERVER VISIBILITY: Message encryption occurs on your local browser before reaching our Supabase database. Our servers only store encrypted ciphertext, nonce IVs, and cryptographic salts. D-R-E-I-N employees, administrators, and database operators possess zero ability to read, decrypt, or analyze your private chat messages.
5. Legal Bases for Processing (GDPR Article 6)
We process personal data under the following recognized legal grounds:
- Contractual Necessity (Art. 6(1)(b)): Delivering core platform functionality, user authentication, profile hosting, and subscription features.
- Legitimate Interests (Art. 6(1)(f)): Platform security, fraud prevention, recommendation algorithm optimization, and aggregated telemetry analysis.
- Explicit Consent (Art. 6(1)(a)): Collected at registration for geographic and business interest audience telemetry and marketing communications.
6. Data Sharing & Sub-Processors
We do not sell, rent, or trade your personal data to third-party data brokers. Data is shared strictly with vetted infrastructure providers under binding Data Processing Agreements (DPAs):
- Supabase Inc.: Managed PostgreSQL database hosting, authentication, and Realtime synchronization (SOC 2 Type II compliant).
- NVIDIA Corporation: Hardware inference provider for AI Co-Founder queries (data processed ephemerally without training persistence).
7. Data Retention & Deletion Schedule
We retain your personal data only for as long as your account remains active. Upon receiving an account deletion request via Account Settings or by emailing dpo@drein.space:
- Your profile, projects, and public feed posts are permanently deleted within thirty (30) calendar days.
- Encrypted message ciphertext stored in Supabase is permanently purged.
- Aggregated telemetry events are anonymized so they can no longer be associated with your identity.
8. International Data Transfers
D-R-E-I-N operates globally with cloud infrastructure based in the United States. For users residing in the European Economic Area (EEA), the United Kingdom, or Switzerland, all cross-border data transfers are executed under European Commission Standard Contractual Clauses (SCCs) ensuring an adequate level of data protection.
9. Your Statutory Privacy Rights (GDPR & CCPA/CPRA)
Subject to applicable data protection laws, you possess the right to:
- Right of Access (GDPR Art. 15): Request a structured copy of all personal data held about you.
- Right to Rectification (GDPR Art. 16): Correct inaccurate or incomplete profile information via Account Settings.
- Right to Erasure / "To Be Forgotten" (GDPR Art. 17): Request total deletion of your builder account and associated data.
- Right to Data Portability (GDPR Art. 20): Export your project roadmaps, build logs, and profile records in machine-readable JSON format.
- Right to Opt-Out of Telemetry: Toggle audience intelligence telemetry collection in your Privacy Settings.
10. Local Storage & Session State
D-R-E-I-N avoids intrusive third-party cross-site tracking cookies. We utilize browser localStorage and secure HttpOnly session tokens strictly for user authentication, cryptographic key caching, dark/monochromatic theme state, and active workspace preferences.
11. Security Safeguards & Technical Measures
We deploy defense-in-depth security measures across all platform layers:
- Row Level Security (RLS) policies on all Supabase database tables.
- TLS 1.3 encryption in transit with strict HSTS preloading.
- Strict Content Security Policy (CSP), X-Frame-Options (DENY), and nosniff headers.
- Magic-byte validation on all uploaded avatars and media assets.
12. Data Protection Officer & Inquiries
If you have questions, complaints, or wish to exercise any statutory rights under this Privacy Policy, contact our Data Protection Officer at:
Data Protection Officer (DPO) — D-R-E-I-N Space Inc.
Email: dpo@drein.space • Legal Inquiries: legal@drein.space
Address: 1209 Orange Street, Wilmington, DE 19801, USA