Last updated: August 9, 2026
Reef (the “app”) is published by IVRYN (Victor Laybats), which is responsible for the processing described here. Contact: contact@reeftogether.com.
Reef does not request precise location or access to your address book. Network requests necessarily expose an IP address to the server or processor handling the request; it may be processed transiently for delivery and security.
Account, habit and progress data is used to provide, synchronise and secure the service. Optional content is used only when you choose the related profile, social, reflection, photo or notification feature. First-party product events and diagnostics are used to understand activation, maintain reliability, prevent abuse and improve Reef. Core processing is necessary to provide the service you request; reliability and first-party measurement support IVRYN’s legitimate interest in operating and improving Reef.
Reef contains no third-party ads and does not sell or rent personal data.
Your username, avatar and content posted to friends, crews or challenges may be visible to the users participating in those features. New avatar and challenge-proof uploads use private storage and time-limited signed links. Older uploads created before this storage change may still be accessible through legacy shareable URLs until they are migrated or deleted. Do not upload sensitive images. Private habits and reflections are not presented as public social posts.
Reef’s primary backend uses a self-hosted Supabase stack on infrastructure in France. Connections use HTTPS/TLS. Reef also uses:
IVRYN does not receive your full payment-card details. These providers process data under their own terms and may process it outside your country with the safeguards they make available.
Account content is kept while your account is active or as needed to provide the feature. Local content remains on your device until you delete it, clear app data or uninstall Reef. Remote error logs are scheduled for deletion after 30 days. When an account is deleted, its direct user identifier is removed from retained product events and diagnostics. First-party product events are scheduled for deletion after 180 days. Until that scheduled deletion, records whose direct account identifier has been removed may remain for aggregate analysis. Access is restricted and technical safeguards are used, but no online service can promise absolute security.
You may access or correct profile and product data in the app. You may also request access, correction, portability, restriction, objection or deletion where applicable. Use the in-app deletion control or follow the account deletion instructions. For help, partial deletion or removal of an uploaded media file, email contact@reeftogether.com. Verified support requests are handled within 30 days. You may also complain to your competent data-protection authority.
Reef is intended for people aged 13 and over. If you believe a child has provided personal data contrary to applicable law, contact us.
Reef’s public website counts aggregate page views and conversion actions without a tracking cookie, fingerprint or persistent visitor identifier. Query strings, email addresses and IP addresses are not written to the measurement store, and Do Not Track or Global Privacy Control disables the script. See the IVRYN portfolio measurement notice.
This notice may change when Reef’s features or providers change. The update date above identifies the current version. Questions can be sent to contact@reeftogether.com.