← Back to Rebut
Rebut — Privacy Policy
Effective 29 July 2026. Last updated 29 July 2026.
Rebut helps merchants respond to payment card chargebacks. This policy explains exactly what the
app stores, where it goes, and how to get rid of it. It is written to be specific rather than
reassuring — if you want to know whether a particular piece of data leaves your device, the answer
should be findable below.
The two things most worth knowing up front.
1. If you connect a payment processor, Rebut stores an API key belonging to your processor
account, encrypted at rest. Use a read-only restricted key — Rebut never needs write
access and never submits a dispute response on your behalf.
2. When you ask Rebut to draft a response letter, the details of that dispute are sent to
Google's Gemini API to generate the text. If you do not want dispute details leaving our
servers, do not use the drafting feature — every other feature, including the win-likelihood
scoring, runs entirely on our own infrastructure with no third party involved.
1. Who we are
Rebut is operated by the publisher identified on the app's store listing ("we", "us"). Contact:
[email protected].
2. What we collect
Account information
- Your email address — used to identify your account, to sign you in, and to
reach you about the service.
- Your password, stored only as a salted PBKDF2-HMAC-SHA256 hash with 200,000
iterations. We cannot read it and cannot recover it for you.
- An optional business name, used only for display and in drafted letters.
- Account creation date, and your current subscription state.
Dispute information you enter or import
- Transaction amount, currency and date; the card network; the reason code; the product or
service type.
- Evidence checklist selections, your free-text notes, deadlines and case status.
- Any response letter generated for the dispute, and its computed win-likelihood score.
The amount, your notes and the generated letter are encrypted at rest with
AES-based Fernet encryption. Other dispute fields (reason code, network, dates, status) are stored
unencrypted so the app can sort, filter and analyse them.
Payment processor credentials
If you connect a processor such as Stripe, we store the API key you supply, encrypted at
rest, together with the processor type, your own label for the account, the account
identifier the processor echoes back, and sync status. We use it for one purpose: reading your
disputes so you do not have to type them in.
Please supply a read-only restricted key. Rebut is deliberately built so that it
never needs more. It does not submit representments, does not move money, and does not modify
anything in your processor account. Submission stays with you, in your processor's own dashboard.
Usage counters
A per-day count of AI drafting requests per account, used to enforce fair-use limits and control
cost. This is a number, not a log of content.
What we deliberately do not collect
- No card numbers, no bank details, no cardholder personal data. Rebut has no
field for them and no reason to hold them. Do not paste them into your notes.
- No payment details for your Rebut subscription. Subscriptions are billed by
Apple or Google. We never see your card.
- No advertising identifiers, no third-party analytics SDKs, no behavioural tracking, no
cross-app or cross-site tracking. Rebut does not sell or share personal information, and does
not use your data for advertising.
- No contacts, photos, location or device identifiers.
3. Third parties who process your data
This is the complete list.
- Google (Gemini API) — receives the details of a dispute when, and only when,
you request a drafted letter: the amount, reason code, network, product type, your notes and
your evidence selections. It does not receive your email address, your password, your
processor API key, or any other dispute. Sent over TLS to Google's API for generation. If you
never use the drafting feature, nothing is ever sent to Google.
- Apple and Google (app stores) — process your subscription payment and tell us
only whether your subscription is active and when it expires. We receive no payment details.
- RevenueCat — mediates subscription state between the app stores and our
server. It receives an anonymous subscriber identifier and purchase state.
- Cloudflare — carries traffic between your device and our server, and provides
TLS and abuse protection. It processes connection metadata such as IP address in transit.
- Your own payment processor (Stripe or similar) — contacted with the key you
supplied, to read your dispute data. You are already that processor's customer; their handling
of your data is governed by their agreement with you.
We do not use any of these parties to advertise to you, and none of them receive your data for
their own marketing.
4. Where your data lives
On our own server hardware in the United States — not a rented cloud instance — in an encrypted
SQLite database, reachable only over TLS through Cloudflare. Application ports are bound to
loopback and are not directly exposed to the internet. Encryption keys are held separately from the
database and are not stored in the same backup as the data they protect.
5. How long we keep it
- Account and dispute data — until you delete it, or delete your account.
- Sessions — expire automatically; signing out invalidates immediately.
- Backups — retained on a rolling basis for disaster recovery.
6. Deleting your data
You can delete your account from inside the app: sign in, then use the Delete account
link at the top right of the screen, next to Log out. It requires your password, and it removes your
account, every dispute, every drafted letter, your notes, your stored processor credentials and your
usage counters, immediately and permanently. We do not retain a shadow copy, and we do not require
you to email anyone to ask.
If you cannot sign in, email [email protected]
from your account's email address and we will delete it for you.
One honest limitation. Deleting your account removes your data from the live
system at once, but copies already written to encrypted disaster-recovery backups persist
until those backups age out on their normal rotation. Those backups are encrypted, access
controlled, and are only ever used to restore the service after a failure. We are telling you this
because it is true of essentially every service that takes backups, and most privacy policies
quietly omit it.
Cancelling a subscription is done through Apple or Google, not through us — we cannot cancel it
on your behalf. Cancelling billing does not delete your data; use Delete account for that.
7. Your rights
Depending on where you live, you may have the right to access, correct, export or erase your
personal data, to object to or restrict processing, and to complain to a supervisory authority.
Access and erasure are available directly in the app. For anything else, email
[email protected] and we will respond within 30
days. We will not discriminate against you for exercising any of these rights.
We do not knowingly collect data from anyone under 18. Rebut is a tool for businesses.
8. Security
TLS in transit. Field-level encryption at rest for processor API keys, dispute amounts, your notes
and generated letters. Passwords stored only as salted PBKDF2 hashes. Session tokens expire.
Subscription entitlements are verified server-side rather than trusted from the device. Keys are
stored by reference rather than copied alongside data.
No system is perfectly secure, and we will not claim otherwise. If we discover a breach affecting
your personal data, we will notify affected users and any required authority without undue delay.
9. Changes
If we change this policy materially — particularly if we add a third-party processor or begin
collecting a new category of data — we will update the date above and notify you in the app before
the change takes effect.
Questions about anything above:
[email protected] ·
Terms of Service