Legal & trust
Privacy Policy
Last updated September 6, 2026
This Privacy Policy explains how Rini ("we", "us") collects, uses, shares, and protects information when you use our website, applications, and services (the "Services"). By using the Services you agree to the practices described here.
1. Information we collect
Account information: your name, email address, password (stored only as a salted hash), and — if you sign in with Google — the basic profile information Google shares with us.
Organization information: the organizations you create or join, your role and membership, and your email domain when it is used to match you to an organization.
Content you provide: the digital people you configure (names, roles, instructions, guardrails), tasks you delegate, and the settings and connections you create.
Integration data: when you connect a third-party platform, we process the data required to perform the tasks you delegate (for example, repository contents, calendar events, or web page contents). We access only what is needed for the task and only for connections you enable.
Usage and device data: log data, IP address, browser type, pages viewed, feature usage, and diagnostic information, collected to operate and secure the Services.
Cookies and similar technologies: see our Cookie Policy.
2. How we use information
- To provide, maintain, and improve the Services.
- To authenticate you, manage sessions, and keep your account and organization secure.
- To perform the tasks you delegate to a digital person, using the integrations you have enabled.
- To communicate with you about your account, security, updates, and support.
- To monitor for abuse, fraud, and violations of our Acceptable Use Policy.
- To comply with legal obligations and enforce our agreements.
3. Legal bases (where applicable)
Where the GDPR or similar laws apply, we rely on: performance of a contract (to provide the Services you request), legitimate interests (to secure and improve the Services), consent (for optional communications and non-essential cookies), and compliance with legal obligations.
4. How we share information
Service providers: infrastructure, hosting, email delivery, analytics, and AI model providers that process data on our behalf under contractual confidentiality and security obligations.
Within your organization: other members of an organization can see the organization's digital people, connections, and activity according to the roles you assign.
Third-party platforms you connect: data is exchanged with those platforms only to carry out the tasks you delegate.
Legal and safety: when required by law, to protect rights and safety, or in connection with a merger, acquisition, or asset sale (with notice where required).
We do not sell your personal information.
5. Data retention
We keep account and organization data for as long as your account is active and as needed to provide the Services. Content and integration data are retained according to your settings and organization configuration. When you delete your account or an organization, we delete or de-identify the associated data within a commercially reasonable period, except where retention is required by law.
6. Security
We use technical and organizational measures designed to protect information, including encryption in transit, hashed passwords, access controls, tenant isolation between organizations, and least-privilege handling of integration credentials. No method of transmission or storage is completely secure.
7. International transfers
We may process and store information in countries other than the one in which you reside. Where required, we use appropriate safeguards such as Standard Contractual Clauses for cross-border transfers.
8. Your rights and choices
Depending on your location, you may have the right to access, correct, delete, restrict, or port your personal information, and to object to certain processing. You can manage most information directly in your account settings, or contact us at privacy@example.com. You may withdraw consent for optional communications at any time.
9. Children
The Services are not directed to individuals under 16, and we do not knowingly collect personal information from them.
10. Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated version with a new effective date and, for material changes, provide additional notice.
11. Contact
Questions about this policy or your information can be sent to privacy@example.com.
Other policies