Privacy Policy

Last updated: August 26, 2026

Scope

This policy explains how Reason Machines, Inc. ("Reason Machines," "we," "us," or "our") collects, uses, shares, retains, and deletes information when you use our websites, mobile and desktop apps, APIs, cloud agents, local-runtime controls, and related services (the "Service").

Information We Collect

Account and workspace information. We collect information such as your name, email address, profile image, account and authentication identifiers, organization memberships, roles, invitations, and settings. We receive some of this information from WorkOS or a supported federated sign-in provider. Organization administrators may also provide your email address when inviting you.

Customer content. When you use cloud features, Reason Machines processes and stores the prompts, messages, agent instructions, model outputs, source code, repository contents, branches, commits, pull requests, files, attachments, screenshots, recordings, and other content needed to run and resume your sessions. This content may include personal or confidential information that you choose to provide.

Connections and credentials. If you connect a source-control provider, communication or project-management service, MCP server, or another integration, we collect the connection identity, approved scopes, configuration, and encrypted access or refresh tokens. We process data returned by that service, and actions taken through it, according to the permissions and instructions you provide. API keys and other secret values are encrypted at rest.

Billing and communications. We collect subscription, usage, credit, invoice, and transaction records, along with information needed to send service, security, billing, and product communications. Stripe processes payment-card and bank details; Reason Machines does not directly store full payment-card numbers.

Usage, device, and diagnostic information. We collect page paths, feature usage, clicks and other interactions, account and organization identifiers, browser and device details, IP address and user agent, cookies or local-storage identifiers, request and run metadata, performance measurements, and error messages or stack traces. Operational logs may be linked to your user ID, email address, organization, repository, session, or run so we can operate and debug the Service.

Voice input. If you tap the microphone control, Reason sends a short recording to its transcription service to produce an editable transcript. Reason may log limited operational metadata such as recording size, duration, and transcript length for reliability and abuse prevention. The transcript becomes customer content if you send or save it.

Analytics and Session Replay

We use cookies, local storage, and similar browser technologies for authentication, security, preferences, diagnostics, and analytics. We use PostHog for product analytics. PostHog stores a persistent analytics identifier in browser storage and a cookie and receives product-interaction events. When you are signed in, Reason Machines identifies analytics with your account ID and email address and groups activity by organization. PostHog autocapture and session replay are enabled. A replay can include page structure, navigation, clicks, content visible on screen, and text entered in ordinary non-password fields. Password fields and fields Reason Machines marks as sensitive are masked or excluded, but you should enter secret values only in fields designated for secrets.

We use Axiom for application, security, performance, and error telemetry. Browser and server logs sent to Axiom can include the linked usage and diagnostic information described above. Vercel also processes website request and performance information. We do not sell this information, use it for third-party advertising, or share it with data brokers for cross-app advertising.

Reason CLI and Mac app installation and update telemetry uses a random per-installation identifier. It can include the CLI or app version, release channel, operating-system family, processor architecture, installation and launch timing, launch source, update result, background-access choice, whether a retired Device installation remains, and coarse country derived at network ingress. When you sign in to the Mac app, product analytics links Mac app use to your Reason Machines account as described above. This telemetry does not include local paths, filenames, hostnames, environment names, file contents, or secret values.

How We Use Information

  • Authenticate users, manage accounts, organizations, permissions, and integrations

  • Run, display, resume, secure, and support local and cloud agent workflows

  • Send code, prompts, and related context to the model and compute providers needed for a run

  • Connect to services and perform actions that you or your organization instruct Reason to take

  • Measure usage, bill accounts, provide credits, and prevent fraud or abuse

  • Diagnose errors, monitor reliability and security, and improve the Service

  • Communicate about the Service and comply with legal obligations

Local and Cloud Processing

Features expressly identified as local execute against files on your device. Using a Reason Machines account, the website or app, connected services, or a model provider can still transmit the account, telemetry, prompt, code, or integration data described in this policy. For cloud inference, Reason sends the context needed for your request through Concentrate to the model provider selected for the run. Depending on your selection and availability, that provider may include OpenAI or Anthropic. If you use your own provider account or credentials, the terms you accepted directly with that provider also apply.

Cloud sessions run in an isolated compute environment. Reason Machines stores cloud session messages, workspaces, attachments, and checkpoints so sessions can run and resume. Customer source code and prompt context are processed by the compute and AI providers required for the run. Automated systems necessarily access this content. Reason Machines personnel cannot assume your identity or use a hidden product path to enter an arbitrary customer workspace. If app-level support requires workspace access, you must invite the designated support address through the ordinary workspace membership flow, choose its tenant role, and may remove it at any time. Separately, authorized infrastructure personnel may access underlying content only when needed to protect the Service, investigate abuse or a security incident, comply with law, or fulfill a support request, subject to access controls.

Connected Services

Connections are optional. Reason Machines requests the OAuth permissions you approve and uses connected data to provide the features and actions you request. Depending on the connection, this can include repository data, messages, files, calendars, events, email, contacts, or other provider content. An agent can read, create, modify, send, or delete data when both the granted permission and your instruction allow it.

You can disconnect a service in Reason Machines settings and can also revoke access with the provider. Disconnecting stops future access but does not automatically undo actions already completed or delete content already saved in Reason session history, backups, or the connected service.

When We Share Information

We share information only as needed for the following purposes:

  • Service providers: WorkOS for identity; PlanetScale for the primary database; Railway and Vercel for hosting; Blaxel for agent compute; Tigris for object storage; PostHog and Axiom for analytics and observability; Concentrate for model routing; Deepgram for voice transcription; Stripe for billing; and Resend for transactional email.

  • AI and developer services: model providers such as OpenAI and Anthropic, and source-control providers such as GitHub and GitLab, when required to perform your requested workflow.

  • At your direction: connected communication, project-management, MCP, and other services you choose, and people or organizations with whom you share a workspace or session.

  • Legal, safety, and business needs: when reasonably necessary to comply with law, protect users or the Service, enforce agreements, or complete a merger, financing, acquisition, or sale with appropriate confidentiality protections.

We require service providers that process personal information for Reason Machines to protect it and use it consistently with their contracts with Reason Machines and applicable law. Providers may process information in countries other than your own.

Retention

We retain information for as long as reasonably necessary to provide and secure the Service, maintain account and workspace continuity, satisfy the purpose for which it was collected, comply with legal and accounting obligations, resolve disputes, and enforce our agreements. The period depends on the information's nature, sensitivity, purpose, workspace ownership, and legal or security requirements.

Credentials are retained until you remove, rotate, or revoke them or delete the owning account, connection, repository, or workspace. Certain run recordings are scheduled for deletion after 30 days, and terminal session checkpoint bundles are scheduled for deletion after 7 days. Analytics, operational telemetry, backups, billing records, and service-provider copies follow the applicable project, provider, security, and legal retention cycles.

We may retain limited records when required for tax, fraud prevention, security, dispute resolution, or another legal obligation. Content owned by a surviving workspace and actions or content already written to a connected third-party service are not deleted with an individual account.

Security

We use access controls, transport encryption, isolated compute, and encryption at rest for stored secret values. No system is completely secure, so please report suspected unauthorized access to contact@reasonmachines.com.

Your Choices and Rights

You can update account and workspace settings, remove credentials, disconnect integrations, unsubscribe from non-essential email using the message's unsubscribe control, and revoke device or provider permissions. Depending on where you live and subject to applicable exceptions, you may also have rights to know or access, correct, export, object to or restrict processing of, or delete personal information; opt out of certain sale, sharing, targeted advertising, or profiling; appeal a denied request; and withdraw consent where processing relies on consent. We will not discriminate against you for exercising an applicable privacy right.

To make a privacy request or ask us to stop non-essential analytics associated with your account, email contact@reasonmachines.com. We may need to verify your identity. Essential account, security, billing, and operational processing may continue where necessary to provide the Service or meet legal obligations.

Account Deletion

You can request permanent account deletion from account settings. If you cannot sign in, use our public account deletion request page. If you are the last owner of a workspace, you must transfer ownership or delete that workspace first. Deletion removes covered account data from Reason Machines' primary application store and starts applicable provider cleanup; it does not remove data owned by a surviving workspace or commits, pull requests, messages, files, or other actions already written to a connected third-party service.

Children

The Service is not intended for anyone under 18. If you believe a minor has provided personal information, contact contact@reasonmachines.com.

Changes

We may update this policy as the Service or legal requirements change. We will post the revised policy with a new date and provide additional notice when a change is material.

Contact

Reason Machines, Inc. — privacy questions and requests: contact@reasonmachines.com