Legal
Privacy Policy
What this Railor deployment stores, why, and what you can do about it. Written to match what the code actually does.
What is collected
- Account
- Your email address and, if you sign in with Google or GitHub, the display name they return. No passwords — sign-in is by magic link or OAuth.
- Workspace
- What you create: corridors, monitors, alerts, policies, decisions, readiness answers, invitations and provider-connection metadata. Provider credentials, if you add any, are encrypted at rest (AES-256-GCM).
- API usage
- Per-key request counts, endpoints, status codes and latency — used for quotas, the usage dashboard and abuse prevention.
- Security
- Rate-limit counters keyed by a one-way hash of your IP or email. Raw IP addresses are not stored.
- Cookies
- Two strictly necessary cookies: a session cookie and the id of the workspace you last opened. No advertising or cross-site tracking cookies.
How it is used
To run the product for your organization: sign you in, show your workspace, deliver alerts you asked for, meter the API, and keep the service secure. Your workspace data is never sold.
When the operator enables them, the text of a search may be sent to a language-model provider to interpret it, and a corridor query to a web-research provider for fresh market discovery. Only the query itself is sent — never your workspace records, readiness profile or keys.
Email is sent only for sign-in links, invitations and alerts you configured, through the SMTP provider the operator sets up.
Your choices
- • Leave a workspace or remove members from Settings → Team.
- • Revoke API keys and provider connections at any time from the dashboard.
- • Ask the deployment operator to export or delete your account data.
See also the Terms of Service.