Privacy Policy
Last updated: July 16, 2026
This policy describes the current controlled preview. The formal operator identity and a final retention schedule must be published before paid public launch.
1 · Local-first boundary
Installing the RAAV CLI or MCP server does not by itself upload your repository. Local product memory, tasks, decisions, logs, and audit files stay in the repository or shared ledger location you configure.
Data leaves the local environment only when you choose a hosted action, such as signing in, syncing a project, importing an audit export, dispatching through the connector alpha, or contacting RAAV.
2 · Data the hosted service handles
- Account data: email address, account identifier, authentication session data, and profile fields you provide.
- Hosted project data: project identifiers and the product memory, work, decisions, comments, evidence, and audit events you choose to sync.
- Connector data: device label, platform, supported providers, heartbeat time, run requests, status events, logs, summaries, and outputs returned to RAAV.
- Support data: contact or waitlist details and the content of messages you submit.
- Protection data: IP address or account identifier used for abuse prevention and distributed rate limiting.
- Traffic and performance data: page, referrer, device, browser, approximate location, and web-vital measurements collected by configured hosting analytics.
Google Analytics loads only after analytics consent. RAAV also uses Vercel Web Analytics and Speed Insights for aggregated traffic and performance measurement. See the Cookie Policy for the current browser-storage details.
3 · Why the data is used
- Authenticate users and connect the correct projects, workspaces, and local agents.
- Store and render the founder console and synchronized product record.
- Operate agent-run status, cancellation, evidence, and audit history.
- Protect public and authenticated endpoints from abuse.
- Answer support messages and manage preview access.
- Understand aggregate site usage and diagnose performance or reliability problems.
- Meet legal obligations and investigate security or misuse reports.
RAAV does not sell or rent account, project, or repository data, and does not use it for third-party advertising. The providers listed below process only the data needed to deliver their configured service.
4 · Providers
RAAV currently relies on the following service categories:
- Supabase for hosted authentication and database storage.
- Vercel for web hosting, traffic protection, deployment logs, Web Analytics, and Speed Insights.
- Resend for contact and waitlist email when configured.
- Google Analytics only when a visitor grants analytics consent.
- Stripe only after paid checkout is enabled; checkout is disabled during the controlled preview.
These providers process data under their own infrastructure and privacy terms. Data may be processed in countries where those providers operate, subject to applicable transfer safeguards.
5 · Retention and deletion
Local files remain until you or your repository tooling remove them. Hosted account, project, run, and audit data remains while the preview account or project is active and may remain in backups or security logs for a limited period after deletion.
RAAV has not yet published a final category-by-category retention schedule. That schedule is a paid launch blocker. During the preview, request access, export, correction, or deletion by emailing privacy@raav.ai.
6 · Security
Hosted traffic uses HTTPS. Authentication, workspace membership checks, server-only credentials, request validation, payload limits, and distributed production rate limits protect hosted routes. Local agent credentials remain on the founder's machine by design.
No internet or local system is completely secure. Keep repository backups and revoke compromised credentials.
7 · Your choices and rights
- Keep RAAV entirely local and do not enable hosted sync.
- Decline optional Google Analytics in the cookie controls.
- Disconnect a local agent connector or stop using a hosted project.
- Ask for access, correction, export, restriction, objection, or deletion where applicable law gives you that right.
- Complain to your competent data-protection authority if you believe your rights were not respected.
Requests may require identity verification. Mandatory legal rights are not limited by this policy.
8 · Children
RAAV is a product-development service and is not directed to children. Preview accounts are intended for people who can enter a binding agreement in their jurisdiction.
9 · Changes
This page will be updated when data flows, providers, retention, or the operator's details change. Material changes will be communicated through the service or account email when practicable.
10 · Contact
Privacy questions and rights requests: privacy@raav.ai. The verified controller identity, registration information, and postal address must be added before paid public launch.