Reina: Privacy Policy
Reina is a local-first desktop application. This policy explains what stays on your device, what leaves it and why, and the choices you have. It covers the Reina app, our online services that power its cloud features, and our websites.
The short version
| Data | Where it lives | Leaves your device? |
|---|---|---|
| Conversations & Reina's memories | Your device | Only as cloud AI requests you initiate (processed, not stored by us) |
| Microphone audio | Your device (local speech-to-text) | Only if the local model is unavailable; see section 1 |
| Personas and settings | Your device | No |
| License key | Your device | Sent to our relay with each cloud request, to check it and meter usage |
| Screen captures (commentary / assistant vision) | Never written to disk | Sent to AI providers only while those features are on |
| Usage metering | Our servers | Counts and costs only; no conversation content |
| Payment details | Entered with our payment processor | We never see card numbers |
| Launch-list email | Our servers | Only if you ask to be told when it ships |
We show no ads, sell no data, and do not use your conversations to train models.
1. What stays on your device
Reina stores working data locally, in your Windows user profile
(%APPDATA%\Reina):
- Conversations and memories. Chat history and the things Reina remembers about you live in a local database. We cannot read it; it never reaches our servers as stored data.
- Your voice. Speech-to-text runs on your machine, and we never receive that audio. Two things are worth being precise about. The speech model is downloaded on first launch rather than shipped inside the installer, and until it is ready the App falls back to Google's public speech service, so the phrases you speak in that window are sent there to be transcribed. The same fallback is used if the local model later fails to load. That fallback is not encrypted in transit. Reina's spoken voice (text-to-speech) is also generated locally by default; if you select ElevenLabs as the voice provider in settings, each line about to be spoken is sent to ElevenLabs on your own account.
- Personas and settings. Everything you build in the Persona Studio, your configuration, and your license key are local files.
- Screen frames. Captured frames are processed in memory and are not written to disk. The local database keeps only small grayscale fingerprints used to detect that the screen changed, not readable images.
- Whether you are at the keyboard. Reina notices when you step away, from the time of your last keyboard, mouse or controller input and whether Windows is locked, so that commentary requests stop while nobody is there. That reading is made on your device and is not stored. Two small things derived from it travel with cloud requests like any other context: a short note of whether you are at the computer, in the assistant's own briefing when you talk to Reina, and how long you were gone, in rough words, in the request that writes the one welcome-back line. The switch in Settings decides what Reina does with the reading.
Deleting this data is in your hands: uninstalling the App and removing
%APPDATA%\Reina removes it completely.
2. What leaves your device, and why
2.1 Cloud AI requests
When you use cloud features (chat, the desktop assistant, game commentary, and web search), the App sends the content needed to generate a response through our relay service (hosted on Cloudflare) to third-party AI model providers. Depending on the feature, that content includes your messages, recent conversation context, and (for vision features) screen captures.
- Current providers: Anthropic for chat and the desktop assistant; Google, reached via OpenRouter, for vision, which is the default for screen captures; and the host of the voice model, also reached via OpenRouter. All three are reached through our relay. The exact models may change, and the App names the ones in use in its settings.
- On the Bring-Your-Own-Key tier, requests go directly to your own provider accounts once any credit carried over from a paid tier has been spent; until then they run through our relay like any other tier. See section 2.6.
- Conversation the App judges to be sexually explicit is held back from what we send to the reasoning provider through our relay. That judgment is made on your device, and nothing about it is transmitted, logged or reported. The only effect is that a turn is left out of a later request.
- Our relay forwards request content to the provider and streams the answer back. We do not store your request or response content on our servers.
- Providers process this content to generate the response, under their own terms. The providers we use do not train on API content by default.
Cloud requests are optional in the sense that they happen only for features that need them: on the Free tier, or when your budget is exhausted, no cloud requests are made.
2.2 Screen captures, and what is masked
Vision features see your screen. While game commentary is running, the App periodically captures the game; when you ask the assistant to do something that requires looking at the screen, it captures what is needed for that task. These captures are sent to the vision provider as part of the request.
Anything visible in a captured region can be included, including text on screen, such as other players' chat messages and names. Be as thoughtful about what is on screen while vision features run as you would be while streaming.
Two separate protections apply, and they are not the same rule. First, windows belonging to messaging apps, mail clients and password managers are painted over before a capture leaves your machine, and if such a window is in focus the capture is skipped entirely. Second, Reina will never comment aloud on what is in those windows. The second rule has no off switch, deliberately: a setting you turn off for one task is a setting you forget about before going live.
Discord is handled separately, by two switches that are both off by default, one allowing Reina to see it and the other to hear it, because "watch me play and talk about my server" is something people genuinely want and a password manager is not.
Hearing a video. A third switch, also off by default, lets Reina listen to what your speakers play while a video is in front and Talk during videos is on, so a film with no subtitle track can be followed by its dialogue instead of by a screen capture per beat. The audio is transcribed on your machine and never leaves it; the text of the dialogue is then sent to the AI provider as part of the commentary request, exactly as subtitle text is. Any stretch in which something Reina may not hear was audible - Discord without its own switch, a messaging app, a password manager, Reina's own voice - is thrown away whole and unheard, because a speaker mix cannot be separated afterwards.
Masking is best-effort and keyed on window identity: it cannot recognize every sensitive application. When you deliberately ask the assistant to look at something it will read what you point it at, which is the purpose of asking. Turn vision features off when working with content that must not leave your machine.
Other people in what is captured. A capture is whatever is on your screen, which can include another player's chat, their name, or a message from someone who is not you. Deciding whether that is all right to send is yours, because it is your screen and we cannot see it to judge. Section 9 of the Terms sets out what you are agreeing to about it.
The assistant cannot turn vision on. Reina can change the App's settings when you ask. The switches that protect you are held one way, though: Reina can turn them off, never on. See Section 10 of the Terms.
Window titles. When commentary is running, the App reads the title of the window you are watching and, if it looks like a film or a show, looks that title up in public media databases to find out what it is. The title leaves your machine; nothing else about the window does.
The lookup goes through our relay rather than from your computer, so the databases we ask see our address and not yours. They are told a title and nothing else — not your address, not your licence, and nothing that identifies you or your machine. We do not keep a record of what was looked up; answers are cached by title so that the same show is only ever fetched once for everybody. This is why there is no switch for it: the thing a switch used to protect you from no longer happens.
2.3 License checks and usage metering
To operate paid tiers, our relay validates your license key and meters spend. It does not keep a log of individual requests. For each license we maintain running totals only: spend so far in the current day, spend in the current calendar month, a lifetime spend total, and a count of requests made today. The model name and token counts returned by the provider are used to compute the cost of a call as it passes through, and are then discarded; they are never written to storage. These totals are what powers your in-app budget meter. They contain no conversation content. The daily and monthly figures reset on their own at each rollover; the lifetime total and the counter itself persist for as long as the license exists, and are deleted with it.
2.4 Purchases
Purchases are sold and invoiced by Sovereignty LLC: we are the seller of record, and we account for any sales tax or VAT that applies. Payment is taken by a payment processor acting for us, identified at checkout and on your receipt. It collects your card details under its own privacy policy and we never receive card numbers. The order information we hold is your email, the product purchased, and the license issued, and we keep it to deliver and support that license.
We keep order records for as long as we have to. Because we are the seller of record, the invoice, the amount, the tax charged and the country it was charged in are accounting records, and tax law requires us to keep those for seven years. The license record itself is kept while the license exists, so support can answer “I lost my key”, and it goes when the license does. Asking us to delete your data does not reach the accounting records, and we cannot make it: the duty to keep them is not ours to waive.
2.5 Update checks and websites
The App periodically fetches a signed update manifest from our update server. Like any web request, this exposes your IP address and the App version to our hosting provider (Cloudflare), which processes standard connection logs. Our websites use no third-party advertising or tracking: no analytics, no pixels and no embedded third-party scripts. The front page keeps two values in your browser's own storage: your light-or-dark choice, and the time of your last visit, so Reina can greet a return. Neither is sent anywhere, and clearing your browser's site data removes both.
2.6 Bring-Your-Own-Key tier
On the BYO tier, your provider API keys are stored locally on your device and your AI requests go directly from your machine to those providers under your own accounts. Their processing of that traffic is governed by your agreements with them, and their acceptable-use policies apply to you rather than to us. Our relay only handles license validation for the App itself.
Two things worth stating plainly:
- A BYO license may begin on our relay. If your license carries credit left over from a paid tier, requests run through the relay until that credit is spent, and section 2.1 applies to them in full. After that, everything goes direct.
- We filter what we send; we do not filter what you send. The explicit-conversation hold-back described in section 2.1 applies to requests made through our relay, because those are made on our account. On your own key we leave your conversation history intact. It is your account, and the choice of what to send is yours. It does mean that anything you and the App say to each other reaches your provider under your name and subject to their policies. The App’s reasoning stage supports Anthropic only, so there is no alternative provider to route it to.
2.7 Launch notifications
If you ask us to tell you when Reina is released, we store the email address you gave, when you gave it, the exact wording you agreed to, and a hashed form of your IP address. The hash exists only to stop the form being abused and cannot be turned back into an address.
The lawful basis is your consent, which you give by ticking a box that starts unticked. We never add an address any other way. We use the list to send one email, once, when the App is released. It is not a newsletter and we will not use it for anything else. Ask us to remove you at any time at privacy@sovereignty.cc, and we delete the list once the announcement has gone out.
2.8 Software Reina installs
Some of what Reina does needs a program that is not part of the App. Reina installs those for you, and the list of what Reina may install is fixed inside the App and is described in section 10 of the Terms.
To install one, Reina asks Windows Package Manager for the program by name. That is a component of Windows, and the request goes to Microsoft's package repository and then to whatever download host the publisher of that program uses. Like any web request, those parties see your IP address and which program was asked for, and their own privacy policies govern what they do with it. None of that traffic goes to us, and installing something does not report it to us - the App sends us nothing when it installs, and the list Reina works from is local.
Being exact about that, because there is a way we do learn what is on your PC and it is not this one: when the desktop assistant is on, the names of the programs installed on your machine are part of what the request carries through our relay, so that "open Spotify" opens the app you have rather than a website. That is described in section 2.1 and it happens whether or not Reina ever installs anything. We forward it and do not store it.
To find out whether a program is already there, the App looks at a path on your disk and asks Windows Package Manager. Neither leaves your machine except as described above.
If you would rather nothing were installed, "Install what Reina needs" is on the Settings page. On a computer joined to an organization's domain or directory, Reina installs nothing unless you ask for it.
3. What we don't do
- No advertising, and no sale or sharing of personal data for advertising.
- No training of AI models on your content. We do not do it, and we use our providers under API terms that do not grant them the right to do it either.
- No reading of your local data. The App's support flows never upload your conversation database.
- No voice recording. Audio is transcribed locally and discarded.
4. Legal bases (EEA/UK users)
Where GDPR or UK GDPR applies, we process personal data on these bases: performance of a contract (operating the App, Services, and licenses); legitimate interests (abuse prevention, metering integrity, securing the Services); consent (optional marketing emails, if offered); and legal obligation (accounting and tax records).
5. Your rights and choices
- Local data is under your direct control: read, export, or delete it on your own machine at any time.
- Server-side data (metering, order information, and your address if you joined the launch list): you may request access, correction, or deletion by emailing privacy@sovereignty.cc. We will respond within 30 days. Note that we may retain what is necessary to complete accounting or comply with law.
- Feature switches: vision features, web search and cloud chat can each be turned off in settings; three further switches control whether Reina may see Discord, hear Discord, and hear what your speakers play during a video, and all three are off until you turn them on, by hand, on the Settings page. The assistant cannot turn any of them on for you, and cannot be talked into it by anything Reina reads. The Free tier makes no cloud AI requests at all, though the App still checks for updates and may still use the speech fallback described in section 1.
- EEA/UK users also have the rights to object, to restrict processing, to data portability, and to lodge a complaint with a supervisory authority.
- We do not discriminate for exercising privacy rights. California users: we do not "sell" or "share" personal information as the CCPA defines those terms.
6. Security
Provider API keys for paid tiers live on our servers, never in the App; your device holds only your license key. Traffic to our services and to the AI providers uses TLS; the one exception is the fallback speech service described in section 1, which does not. Updates are cryptographically signed and verified before installation. License keys use modern public-key signatures and can be revoked if compromised. No system is perfectly secure; if we learn of a breach affecting your personal data, we will notify you as required by law.
7. Children
Reina is for adults. We do not knowingly process personal data of anyone under 18. If you believe a minor has provided us personal data (for example, an address on the launch list), contact privacy@sovereignty.cc and we will delete it.
8. International transfers
Our servers and providers operate globally (Cloudflare, Anthropic, Google and OpenRouter are U.S.-based companies with global infrastructure; our payment provider is identified at checkout).
Where data protection law requires safeguards for transfers, we rely on our providers' standard contractual clauses and equivalent mechanisms.
9. Changes to this policy
We will update this policy as the App evolves, in particular, the provider list in Section 2.1 as models change. Material changes will be announced in the App or by email before they take effect, and the date at the top of this page updated.
10. Contact
Privacy questions and requests: privacy@sovereignty.cc.
