Last updated September 2, 2026
This policy explains what personal data Raiw AI handles when you use raiw, why, who else sees it, and what you can do about it. It covers the whole service, and it is the notice required by the GDPR, the California Consumer Privacy Act, and the state privacy laws that followed it.
1. Two different roles
This distinction governs everything below, so it comes first.
- For your account, we are the controller. Your email address, your name, your sign-in method and your billing records are data we decide the purposes for, and this policy is our notice to you about them. In California's vocabulary we are the "business" for this data.
- For the documents you upload, we are a processor. If your files contain personal data about other people, your organization is the controller of it and we handle it on your instructions — a "service provider" under California law, which is why we may not use that data for our own purposes. Those instructions and our obligations are in the Data Processing Addendum. If you are one of those other people and want your data removed from a customer's documents, contact that customer; we will help them but we cannot act on their data without them.
2. What we collect
Account data
- Email address, display name, and profile picture URL.
- Where you sign in with Google, your Google account identifier and the email on that account.
- Your password, if you use one, stored only as a salted hash.
- The date you joined and the time you last signed in.
- Your organization and workspace memberships, and your role in each.
Content you upload
- The files themselves, stored as uploaded.
- Text extracted from them, including by optical character recognition of scans.
- Passages of that text, and the numeric vector representations derived from each passage.
- Generated thumbnail images, page counts and file metadata.
- Questions you ask and the answers generated for you.
We do not choose what is in your documents, and we do not inspect them beyond the automated processing described here. Whatever personal data they contain, we hold as a processor for your organization.
Credentials
- API tokens you create, stored only as a SHA-256 hash. The value is shown once and never again, because we do not keep it.
- Any third-party provider API keys you choose to store, held encrypted at rest.
Billing data
- Stripe customer, subscription, checkout and invoice identifiers, and a ledger of credit movements.
- We never receive or store your card number. Card details go directly to Stripe, whose own privacy notice covers them.
Technical and audit data
- IP address and browser user agent, recorded when you accept a policy and on audited actions.
- A record of significant actions: sign-ins, uploads, document access, deletions, and membership changes.
- Server logs.
We collect this from you directly, or from Google if that is how you sign in. We do not buy personal data, and we do not enrich your account from third-party data brokers.
3. Why we process it, and on what legal basis
| Purpose | Data | Legal basis (UK/EU GDPR) |
|---|---|---|
| Providing the service: storing, indexing and searching your documents | Account data, content | Performance of a contract, Art. 6(1)(b) |
| Authenticating you and keeping accounts separate | Account data, technical data | Performance of a contract, Art. 6(1)(b) |
| Taking payment and keeping accounts | Billing data | Contract, Art. 6(1)(b); legal obligation, Art. 6(1)(c) |
| Security, abuse prevention, and investigating incidents | Audit and technical data | Legitimate interests, Art. 6(1)(f) |
| Proving you agreed to our terms, and defending legal claims | Consent records, IP, user agent | Legitimate interests, Art. 6(1)(f) |
| Telling you about changes to the service or these policies | Email address | Contract, Art. 6(1)(b); legitimate interests, Art. 6(1)(f) |
| Complying with law and responding to lawful requests | As required | Legal obligation, Art. 6(1)(c) |
Where we rely on legitimate interests, we have weighed them against the impact on you and concluded they do not override your rights. You can object, and section 7 says how.
4. What we do not do
- We do not sell or share your personal data as those terms are defined in the California Consumer Privacy Act, and we have not done so in the twelve months before the date at the top of this page. We do not sell or share the personal data of anyone we know to be under 16.
- We do not use your documents to train models. We send text to model providers under API terms that do not permit them to train on it either, and where your organization needs that guaranteed rather than assumed, the zero-data-retention setting in section 5 restricts the service to models offered on those terms.
- We do not run advertising or analytics trackers. The only cookies set are the ones that keep you signed in and protect forms against cross-site request forgery. That is why you are never asked to accept cookies: there are none to refuse. Because there is no tracking to opt out of, a Do Not Track or Global Privacy Control signal has nothing to act on — we have nothing to stop doing.
- We do not profile you. We do not make decisions producing legal or similarly significant effects about you by automated means alone, and we do not draw inferences from your data to build a profile of your characteristics or predict your behavior.
- We do not send marketing email unless you ask us to. Mail from us is transactional: what you did, what it cost, and what changed.
5. Who else processes your data
We use third-party providers to run the service. Which of them are involved depends on the models selected for your organization or workspace. The current list, with what each one receives and where it is, is at Subprocessors, and we update that page before a new provider starts processing.
Text from your documents is sent to model providers. That is how extraction, embedding and answering work: the passages relevant to a question go out, not your whole corpus. Where your organization requires it, the service can be restricted to models offered under zero-data-retention terms, which is a setting on the organization or the workspace and is enforced both when a model is chosen and when it is called.
We also disclose data where we are legally required to — and we will tell you unless we are prohibited from doing so — and to professional advisers or a successor entity in connection with a merger, acquisition or sale of assets. A successor takes on the commitments in this policy.
6. International transfers
Our providers are largely in the United States, so personal data is transferred outside the United Kingdom and the European Economic Area. Where it is, we rely on the European Commission's Standard Contractual Clauses (Decision 2021/914) and the UK International Data Transfer Addendum, together with the transfer mechanisms our providers maintain, and we have assessed the destinations for the protections available there. You can ask us for details, including a copy of the clauses with commercial terms redacted, at [email protected].
7. Your rights
Depending on where you live you have some or all of the following rights. Two of them are self-service in the privacy center, which is the fastest route and needs no correspondence with us at all.
- Know and access. Find out what we hold about you, where it came from, why we have it, and who we disclose it to — most of which is this document — and get a copy.
- Portability. Get a machine-readable copy of your data. Available immediately in the privacy center; the archive is a zip of your documents and JSON files, and it expires after 7 days.
- Deletion. Delete your account and the data attached to it. Available in the privacy center, with a 14-day window in which you can change your mind. Section 9 lists the few things that survive it, and why.
- Correction. Fix inaccurate data. Most of it is editable in the app; otherwise write to us.
- Objection and restriction. Object to processing based on legitimate interests, or ask us to restrict it while a dispute about accuracy or grounds is resolved.
- Withdraw consent where we relied on it, without affecting processing already carried out lawfully.
- Non-discrimination. We will not give you a worse service, a worse price, or a worse anything for exercising a privacy right.
- Appeal. If we refuse a request, reply to our response and a person will reconsider it. Virginia, Colorado, Connecticut, Texas and several other states give you this right explicitly; we offer it to everyone. If we refuse again we will tell you how to complain to your attorney general.
Write to [email protected] for anything the privacy center does not cover. We respond within 30 days, and if a request is complex enough to need longer we will tell you inside that window and explain why. There is no charge unless a request is excessive or repetitive, in which case we will say so before doing any work.
We may need to verify who you are before acting, which protects you rather than obstructing you: we will match your request against the email on the account, and we will not act on a deletion request we cannot tie to the account holder. An authorized agent may act for you if you give them written permission and we can confirm it with you directly.
You can also complain to a regulator: in the UK the Information Commissioner's Office, in the EU the supervisory authority where you live or work, and in the US your state attorney general. We would rather you came to us first, and section 18 of the Terms is our commitment to actually answer.
8. California disclosures
This section restates the above in the categories the CCPA uses, for the account data we hold as a business. For the contents of your documents we are a service provider, and your organization's own notice governs.
| Statutory category | Do we collect it? | Disclosed to |
|---|---|---|
| Identifiers — name, email address, account identifier, IP address | Yes | Hosting, storage, sign-in and payment providers |
| Customer records — the same, plus your payment relationship | Yes, without card numbers | Stripe |
| Commercial information — what you bought, what you spent it on | Yes | Stripe |
| Internet activity — your interactions with the service, in audit records and logs | Yes | Nobody, other than our hosting provider |
| Sensory information — images of pages, where you upload scans | Only inside your content | OCR and model providers, as configured |
| Professional or employment information | Only inside your content | Model providers, as configured |
| Geolocation, biometric data, protected classifications, education records, inferences | No | — |
- Sensitive personal information. Your account password reaches us only to be hashed, and we hold no other category the CPRA treats as sensitive. We use it solely to authenticate you, which is a permitted purpose, so there is nothing for a "limit the use of my sensitive personal information" request to restrict. If your documents contain sensitive personal information, we process it as a service provider on your instructions.
- Sale and sharing. None, as section 4 says. We therefore publish no "Do Not Sell or Share My Personal Information" link, because there is nothing behind it.
- Retention. Section 9 gives the period for each category rather than a single number, which is what the statute asks for.
- How to exercise a right. The privacy center for access and deletion, or [email protected] for anything else. We are an online service, so email is the method we offer; we do not maintain a toll-free line.
9. How long we keep things
- Account and content data: for as long as your account is open. After you delete it, within 30 days.
- Data export archives: deleted automatically 7 days after they are built.
- Billing records: retained after account deletion for as long as tax and accounting law requires, and detached from your identity. This is the exception to deletion that Article 17(3)(b) of the GDPR provides for and that US tax law requires.
- Audit records: retained after account deletion with the identifying email replaced by a marker, so a security investigation into a past period is still possible. Article 17(3)(e).
- Consent records: the fact, version and date of your acceptance are retained, as the record that the agreement existed and that any erasure was carried out. Deleting the evidence that we honored a deletion request would leave us unable to show that we did.
- Server logs: kept only as long as they are useful for debugging and security, and not used to build any profile of you.
10. Security
- Traffic is encrypted in transit. Stored provider credentials are encrypted at rest with a key held outside the database.
- API tokens and passwords are stored as hashes, so a stolen database copy does not yield working credentials.
- Every document, passage and vector carries the organization that owns it, and every read is scoped to it.
- Access to documents is recorded, along with who did it and from where.
- Uploaded files are served through short-lived signed URLs rather than public links.
- Permissions are role-based, per organization and per workspace, at four levels of authority.
No system is perfectly secure, and anyone who tells you otherwise is selling
something. If we become aware of a breach affecting your personal data we will
notify you and the relevant regulator as the law requires, and tell you what we
know rather than the least we can get away with. Report a vulnerability to
[email protected]; our disclosure address is also published at
/.well-known/security.txt.
11. Children
The service is not for children. We do not knowingly collect data from anyone under 16, and we have no feature directed at children. If you believe a child has given us data, write to [email protected] and we will delete it.
12. Changes
We will post any change here and update the date at the top. For a material change we will ask you to review it before you carry on using the service, and the record of which version you accepted is in the privacy center.
13. Contact
Raiw AI
2800 E. Enterprise Ave, Ste 333, Appleton, WI 54913, United States
Privacy and data rights: [email protected]
Security: [email protected]