← Back to Rebut

Rebut — Privacy Policy

Effective 29 July 2026. Last updated 29 July 2026.

Rebut helps merchants respond to payment card chargebacks. This policy explains exactly what the app stores, where it goes, and how to get rid of it. It is written to be specific rather than reassuring — if you want to know whether a particular piece of data leaves your device, the answer should be findable below.

The two things most worth knowing up front.
1. If you connect a payment processor, Rebut stores an API key belonging to your processor account, encrypted at rest. Use a read-only restricted key — Rebut never needs write access and never submits a dispute response on your behalf.
2. When you ask Rebut to draft a response letter, the details of that dispute are sent to Google's Gemini API to generate the text. If you do not want dispute details leaving our servers, do not use the drafting feature — every other feature, including the win-likelihood scoring, runs entirely on our own infrastructure with no third party involved.

1. Who we are

Rebut is operated by the publisher identified on the app's store listing ("we", "us"). Contact: [email protected].

2. What we collect

Account information

Dispute information you enter or import

The amount, your notes and the generated letter are encrypted at rest with AES-based Fernet encryption. Other dispute fields (reason code, network, dates, status) are stored unencrypted so the app can sort, filter and analyse them.

Payment processor credentials

If you connect a processor such as Stripe, we store the API key you supply, encrypted at rest, together with the processor type, your own label for the account, the account identifier the processor echoes back, and sync status. We use it for one purpose: reading your disputes so you do not have to type them in.

Please supply a read-only restricted key. Rebut is deliberately built so that it never needs more. It does not submit representments, does not move money, and does not modify anything in your processor account. Submission stays with you, in your processor's own dashboard.

Usage counters

A per-day count of AI drafting requests per account, used to enforce fair-use limits and control cost. This is a number, not a log of content.

What we deliberately do not collect

3. Third parties who process your data

This is the complete list.

We do not use any of these parties to advertise to you, and none of them receive your data for their own marketing.

4. Where your data lives

On our own server hardware in the United States — not a rented cloud instance — in an encrypted SQLite database, reachable only over TLS through Cloudflare. Application ports are bound to loopback and are not directly exposed to the internet. Encryption keys are held separately from the database and are not stored in the same backup as the data they protect.

5. How long we keep it

6. Deleting your data

You can delete your account from inside the app: sign in, then use the Delete account link at the top right of the screen, next to Log out. It requires your password, and it removes your account, every dispute, every drafted letter, your notes, your stored processor credentials and your usage counters, immediately and permanently. We do not retain a shadow copy, and we do not require you to email anyone to ask.

If you cannot sign in, email [email protected] from your account's email address and we will delete it for you.

One honest limitation. Deleting your account removes your data from the live system at once, but copies already written to encrypted disaster-recovery backups persist until those backups age out on their normal rotation. Those backups are encrypted, access controlled, and are only ever used to restore the service after a failure. We are telling you this because it is true of essentially every service that takes backups, and most privacy policies quietly omit it.

Cancelling a subscription is done through Apple or Google, not through us — we cannot cancel it on your behalf. Cancelling billing does not delete your data; use Delete account for that.

7. Your rights

Depending on where you live, you may have the right to access, correct, export or erase your personal data, to object to or restrict processing, and to complain to a supervisory authority. Access and erasure are available directly in the app. For anything else, email [email protected] and we will respond within 30 days. We will not discriminate against you for exercising any of these rights.

We do not knowingly collect data from anyone under 18. Rebut is a tool for businesses.

8. Security

TLS in transit. Field-level encryption at rest for processor API keys, dispute amounts, your notes and generated letters. Passwords stored only as salted PBKDF2 hashes. Session tokens expire. Subscription entitlements are verified server-side rather than trusted from the device. Keys are stored by reference rather than copied alongside data.

No system is perfectly secure, and we will not claim otherwise. If we discover a breach affecting your personal data, we will notify affected users and any required authority without undue delay.

9. Changes

If we change this policy materially — particularly if we add a third-party processor or begin collecting a new category of data — we will update the date above and notify you in the app before the change takes effect.


Questions about anything above: [email protected] · Terms of Service