Skip to content
The projectContact

Last updated: 2 October 2026

Privacy notes

These notes describe the public website and the private Rheo prototype. They are not a security certification. Please use made-up or non-sensitive situations while testing.

This website

rheocracy.org is an informational website hosted on GitHub Pages. Its pages add no analytics, advertising, tracking pixels, cookies, account forms or browser storage. Images are served from this site, with no third-party embeds.

GitHub and network providers process connection information, such as IP addresses, to serve the website. See the GitHub privacy statement. Visiting this website does not send a question to the Rheo app or OpenAI.

Questions and AI requests

When you ask Rheo in the app, your question and context you choose to include travel over HTTPS through our Render-hosted service to OpenAI. Asking Rheo to reconsider also sends the selected review and relevant earlier question, explanation, choice and local context.

Research and drafting require a separate request. The approved instructions and relevant context go to OpenAI; public web research can also pass search terms to search providers. Rheo prepares material for you to review. It does not send a draft to anyone for you.

Our application server does not write question or response content to logs or permanent storage. Some results are held briefly in memory to support retries. Hosting and AI providers may process connection information and retain data under their own policies.

Requests ask OpenAI not to store Responses for later retrieval (store: false). This does not mean zero provider retention. See OpenAI's API data controls and Render's privacy policy.

What stays on your phone

Saved decisions, pathways, reviews and drafts use local app storage (AsyncStorage), not cloud sync. This storage is not an encrypted vault. Someone with access to your phone or its backups may be able to read it. There is no remote wipe.

You can delete saved material in the app. Deleting it locally cannot retract information already sent to a provider, copied elsewhere or included in a device backup. Saving a review does not automatically ask the AI again.

The private test access code is kept separately in the phone's secure storage. The server keeps invitation hashes and usage counts for access control and spending limits, not wellbeing scoring. Removing test access does not delete your saved decisions.

Optional location and nearby searches

You can use Rheo without location permission. Location is requested in the foreground when you ask it to look around you, not continuously or in the background. Precision is reduced on the phone before the local-search request is sent.

The current low-volume test can use OpenStreetMap's Nominatim service. It receives category search terms and an approximate search area, not your full question. See the OpenStreetMap Foundation privacy policy. Provider results are possibilities to check, not proof of availability or suitability.

Raw coordinate fields are not stored in decision records. Approximate area names and selected local evidence can be saved and sent with a question. Names, addresses or coordinates you type into free text are not automatically removed.

Voice

Live dictation starts when you tap to speak. Apple or your Android speech provider may process the audio; on-device-only recognition is not guaranteed. The resulting text is included when you submit a question.

The separate Expo Go development fallback records a voice note and uploads it through our server to OpenAI for transcription after your approval. This is different from native live dictation. The app attempts to remove the temporary recording after upload or cancellation; do not rely on this as secure deletion.

Current limits

The prototype has no user accounts, cloud sync, advertising, analytics SDK, background location history or public people graph. This does not make it anonymous or surveillance-resistant. Questions and reviews can reveal sensitive details even without a name.

Rheo is not ready for sensitive or high-risk use, including hostile-surveillance settings. Privacy and safety work with the people affected must come before any such pilot.

Contact and changes

Rheo is developed by Iwan Brioc. For privacy questions or a private demo, email info@rheocracy.org. Email uses ordinary email providers and is not a secure channel for sensitive stories.

These notes will need to change as the prototype, providers or testing arrangements change. A wider pilot will need a fuller privacy and consent process, not just this page.

Rheo ยท An experiment in reciprocal wellbeing

Back to Rheo