This Privacy Policy explains how RAGfly ("RAGfly," "we," "us," or "our") collects, uses, discloses, and protects personal information in connection with the RAGfly platform, websites, applications, APIs, and related services (the "Service"). It applies to visitors, account holders, and end users who sign in to the Service, including through third-party identity providers such as Microsoft (Microsoft Entra ID / Azure Active Directory), Google, GitHub, and Supabase.
This policy works together with our Terms of Service.
1. Roles: Who Controls the Data
Two different kinds of data are involved, and our role differs for each:
- Account and authentication data (described in Section 2). For this data we act as a data controller: we decide how and why it is processed to operate the Service.
- Customer Data — extracted content, references, metadata, chunks, embeddings, and configurations that you connect or process. We do not store your original files in RAGfly Cloud. We act as a data processor on your behalf and you retain ownership. RAGfly does not use this data for advertising or to train RAGfly-owned models; model-provider processing is limited to delivering the Service and is subject to the applicable provider's policies.
2. Information We Collect
Account and profile information. When you create an account or sign in through an identity provider, we collect identifiers such as your name, email address, and a unique user identifier. When you sign in with Microsoft, Google, GitHub, or Supabase, we receive this limited profile information from that provider to create and secure your account. We do not receive or store your identity-provider password.
Usage and device information. We collect technical data such as IP address, browser/device type, log data, timestamps, and actions taken within the Service (audit logs), to operate, secure, and improve the Service.
Customer Data. The documents and content you process through the Service. We handle this as a processor on your behalf (see Section 1). It may incidentally contain personal information that you choose to include; you are responsible for the lawfulness of that content.
Billing information. If you purchase a paid plan, payment is handled by Paddle; we receive limited transaction data, not full card numbers.
3. How We Use Information
We use personal information to:
- Create, authenticate, and secure your account.
- Provide, maintain, and improve the Service.
- Communicate with you about the Service, including security and service notices.
- Process payments and manage subscriptions.
- Detect, prevent, and address fraud, abuse, and security incidents.
- Comply with legal obligations.
We do not sell personal information or use Customer Data for advertising or to train RAGfly-owned models. Model providers may process content strictly to perform the requested operation, under their own terms and policies.
4. Legal Bases
Where required by applicable data-protection law, we rely on the following legal bases: performance of a contract (to provide the Service), our legitimate interests (to secure and improve the Service), your consent (where requested, e.g., certain cookies), and compliance with legal obligations.
5. Sharing and Disclosure
We share personal information only as needed to operate the Service:
- Subprocessors and service providers — such as cloud hosting, database, and infrastructure providers — bound by confidentiality and data-protection obligations.
- AI model providers — content strictly required for an operation may be processed by the configured provider. Providers and models may change. On Free, the active list is shown in My Account and requires explicit acceptance before first processing; other plans support the selection or configuration available to that plan.
- Identity providers — to authenticate your sign-in (for example, Microsoft Entra ID).
- Legal and safety — when required by law or to protect rights, safety, and the integrity of the Service.
- Business transfers — in connection with a merger, acquisition, or reorganization, with the protections of this policy preserved.
A current list of subprocessors is available on request at admin@ragfly.ai.
6. International Transfers
The Service may process data in countries other than yours. Where applicable law requires, we use appropriate safeguards (such as standard contractual clauses) for cross-border transfers. On supported plans, RAGfly Desktop keeps the processing of your original files within your own infrastructure; derived representations of their content (chunks, embeddings, and metadata) may still be processed by the Service as described in this policy.
7. Data Retention
We retain account and usage data for as long as your account is active and as needed to provide the Service, then for the period required by law or for legitimate business purposes. Customer Data is retained according to your instructions and the Terms of Service: after termination you have a grace period to export it, after which we delete it, subject to legal retention obligations.
8. Security
We apply reasonable technical and organizational measures, including encryption of document data at rest, encrypted communications (HTTPS), role-based access control (RBAC) with granular permissions, multi-factor authentication, structural isolation between organizations, and audit logging. No system is completely secure, but we will notify you without undue delay of any breach affecting your personal information or Customer Data, as required by law.
9. Your Rights
Depending on your jurisdiction, you may have rights to access, correct, delete, port, or restrict the processing of your personal information, and to object to certain processing or withdraw consent. To exercise these rights, contact us at admin@ragfly.ai. If your personal information is contained in Customer Data controlled by an organization, please direct your request to that organization; we will assist them as their processor. Note on portability: RAGfly does not store your original files (only encrypted derivatives such as text, chunks, and embeddings) — your original documents remain in your own possession at all times, so there is no separate data export for us to provide.
10. Cookies
The Service uses cookies and similar technologies that are necessary for authentication and security, and, where applicable, optional analytics cookies subject to your consent. You can manage cookies through your browser settings.
11. Children
The Service is not directed to children under 18 (or the age of majority in your jurisdiction), and we do not knowingly collect their personal information.
12. Google Drive Access (Limited Use)
When you connect a Google Drive folder, RAGfly requests read-only access (the `drive.readonly` scope) to read the documents in the folder you select and turn them into retrievable context for your own AI agents. RAGfly never modifies, creates, or deletes anything in your Google Drive.
File bytes are downloaded into the user's browser, text is extracted locally, and only the extracted text (encrypted) is sent to our backend; the original file is not stored on RAGfly's servers.
RAGfly's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell this data and do not use it to train generalized AI models.
13. Changes to this Policy
We may update this Privacy Policy. We will post the updated version with a new "Last updated" date and, for material changes, provide reasonable notice.
14. Language
RAGfly publishes this Privacy Policy in several languages. The English version is the authoritative version; translations are provided for convenience only, and in case of any discrepancy the English version prevails.
15. Contact
For privacy questions or to exercise your rights:
CAB Ltd. (RAGfly)
Website: ragfly.ai
Email: admin@ragfly.ai
RAGfly