Privacy Policy
Last updated 18 August 2026
This policy explains what we collect, why, and how it is protected. The short version: your data is encrypted in transit and at rest, we do not sell it, we do not advertise against it, and we never use it to train AI models.
01The short version
- Your content is encrypted in transit and at rest.
- We do not sell or rent your data to anyone.
- We do not use your content to train AI or machine learning models.
- We do not run ads, and we do not profile you for advertising.
- We share data only with the providers needed to run the service, listed in section 6.
02What we collect
Account information. Your name and email address. If you sign in with Google, we receive your email, name, and profile picture from Google — never your Google password. If you sign up with an email and password, we store your email and a one-way cryptographic hash of your password. We cannot read your password.
Billing information. Subscription status, plan, and invoice history. Payments are handled by our payment provider, and full card numbers never reach our servers.
Your content. The documents, embeddings, indexes, and queries you send to the service so that we can store and retrieve them for you.
Technical and usage data. Log data such as IP address, timestamps, API endpoints called, request volume, and error traces. We use this to operate, debug, secure, and meter the service.
03How we use it
- To provide, maintain, and improve the service.
- To authenticate you and keep your account secure.
- To process payments and manage subscriptions.
- To respond to support requests you send us.
- To send service messages such as password resets, billing notices, and material changes to this policy.
- To detect, investigate, and prevent abuse, fraud, and security incidents.
- To meet legal and accounting obligations.
04What we never do
We do not sell, rent, or trade your personal information or your content. We do not use your content to train, fine-tune, or evaluate AI or machine learning models, whether our own or anyone else’s. We do not serve advertising, and we do not build advertising profiles from what you store with us.
Our staff do not access your content except where you explicitly ask us to for support, or where it is strictly necessary to investigate a security incident or comply with a legal obligation. Such access is limited and logged.
05Security and where data is held
Data is encrypted in transit using TLS, and encrypted at rest in our storage systems. Access to production systems is restricted to personnel who need it, and database access is scoped so that one customer’s records cannot be read through another customer’s session.
We do not operate our own data centres. The service runs on established third-party cloud infrastructure providers, whose facilities carry recognised industry security certifications. Encryption at rest and in transit applies regardless of which provider hosts a given workload.
No system is perfectly secure. If a breach affects your data, we will notify you and any relevant regulator as required by law.
06Who we share data with
We share data only with service providers that help us run GigaRAG, and only to the extent they need it. They are bound by contract to protect it and may not use it for their own purposes. These fall into the following categories:
- Cloud infrastructure and storage providers that host the service.
- Our payment processor, for subscriptions, invoices, and refunds.
- Email delivery providers, for transactional messages such as password resets.
- Error monitoring and analytics tooling used to keep the service reliable.
We may also disclose information where we are legally required to, for example in response to a valid legal request, or to protect the rights and safety of our users or the public. If GigaRAG is involved in a merger or acquisition, data may transfer as part of that transaction; we will give notice before your data becomes subject to a different privacy policy.
07Cookies
We use a small number of strictly necessary cookies. The main one is a signed, HTTP-only session cookie that keeps you logged in. We do not use advertising or cross-site tracking cookies.
08Retention and deletion
We keep your account information and content for as long as your account is active. When you delete content, it is removed from the live service and purged from backups within a reasonable period. When you close your account, we delete or de-identify your data, except where we must keep records to meet legal, tax, or accounting obligations.
Export anything you want to keep before closing your account.
09Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, to object to or restrict certain processing, and to withdraw consent where processing relies on it. You also have the right to complain to your local data protection authority.
To exercise any of these, email [email protected]. We will respond within the period required by applicable law and may need to verify your identity first.
10International transfers
Our providers may process data in countries other than yours. Where data moves across borders, we rely on appropriate safeguards, such as standard contractual clauses, to protect it.
11Children
GigaRAG is not intended for anyone under 18, and we do not knowingly collect data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
12Changes to this policy
We will update the date at the top when this policy changes. For material changes we will notify you by email or in the product before they take effect.
13Contact
For any privacy question or request, email [email protected] and we will get back to you.
Questions about this document? Email [email protected].
See also our Terms of Service and Privacy Policy.