This Privacy Policy explains how RAGfly (“RAGfly,” “we,” “us,” or “our”) collects, uses, discloses, and protects personal information in connection with the RAGfly platform, websites, applications, APIs, and related services (the “Service”). It applies to visitors, account holders, and end users who sign in to the Service, including through third-party identity providers such as Microsoft (Microsoft Entra ID / Azure Active Directory), Google, GitHub, and Supabase.
This policy works together with our Terms of Service.
1. Roles: Who Controls the Data
Two different kinds of data are involved, and our role differs for each:
- Account and authentication data (described in Section 2). For this data we act as a data controller: we decide how and why it is processed to operate the Service.
- Customer Data — the documents and content you upload, connect, or process through the Service. For this data we act as a data processor (or “encargado”) on your behalf. You (or your organization) are the controller. We process Customer Data only on your instructions and as described in the Terms of Service, and you own it at all times. We do not use Customer Data to train AI models or for any purpose other than providing the Service to you.
2. Information We Collect
Account and profile information. When you create an account or sign in through an identity provider, we collect identifiers such as your name, email address, and a unique user identifier. When you sign in with Microsoft, Google, GitHub, or Supabase, we receive this limited profile information from that provider to create and secure your account. We do not receive or store your identity-provider password.
Usage and device information. We collect technical data such as IP address, browser/device type, log data, timestamps, and actions taken within the Service (audit logs), to operate, secure, and improve the Service.
Customer Data. The documents and content you process through the Service. We handle this as a processor on your behalf (see Section 1). It may incidentally contain personal information that you choose to include; you are responsible for the lawfulness of that content.
Billing information. If you purchase a paid plan, payment is handled by Paddle; we receive limited transaction data, not full card numbers.
3. How We Use Information
We use personal information to:
- Create, authenticate, and secure your account.
- Provide, maintain, and improve the Service.
- Communicate with you about the Service, including security and service notices.
- Process payments and manage subscriptions.
- Detect, prevent, and address fraud, abuse, and security incidents.
- Comply with legal obligations.
We do not sell personal information, and we do not use Customer Data to train AI models or for advertising.
4. Legal Bases
Where required by applicable data-protection law, we rely on the following legal bases: performance of a contract (to provide the Service), our legitimate interests (to secure and improve the Service), your consent (where requested, e.g., certain cookies), and compliance with legal obligations.
6. International Transfers
The Service may process data in countries other than yours. Where applicable law requires, we use appropriate safeguards (such as standard contractual clauses) for cross-border transfers. On supported plans, you may restrict processing to your own infrastructure via RAGfly Desktop.
7. Data Retention
We retain account and usage data for as long as your account is active and as needed to provide the Service, then for the period required by law or for legitimate business purposes. Customer Data is retained according to your instructions and the Terms of Service: after termination you have a grace period to export it, after which we delete it, subject to legal retention obligations.
8. Security
We apply reasonable technical and organizational measures, including encryption of document data at rest, encrypted communications (HTTPS), role-based access control (RBAC) with granular permissions, multi-factor authentication, structural isolation between organizations, and audit logging. No system is completely secure, but we will notify you without undue delay of any breach affecting your personal information or Customer Data, as required by law.
9. Your Rights
Depending on your jurisdiction, you may have rights to access, correct, delete, port, or restrict the processing of your personal information, and to object to certain processing or withdraw consent. To exercise these rights, contact us at admin@ragfly.ai. If your personal information is contained in Customer Data controlled by an organization, please direct your request to that organization; we will assist them as their processor.
11. Children
The Service is not directed to children under 18 (or the age of majority in your jurisdiction), and we do not knowingly collect their personal information.
12. Changes to this Policy
We may update this Privacy Policy. We will post the updated version with a new “Last updated” date and, for material changes, provide reasonable notice.
13. Contact
For privacy questions or to exercise your rights:
[Provider legal name]
Website: ragfly.ai
Email: admin@ragfly.ai
This document is a general-purpose template and does not constitute legal advice. Have it reviewed by a lawyer before publication, in particular to complete the bracketed fields and adapt it to the applicable data-protection framework (e.g., GDPR, CCPA, or local law).