Loading

Privacy Policy

Last updated: November 10, 2025

Ragent Ltd. ("we", "our", or "us") is committed to protecting your privacy and complying with applicable data protection laws, including the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other relevant privacy regulations.

This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered project management application ("Service"). By using our Service, you agree to the collection and use of information in accordance with this policy.

Data Controller Information

Data Controller:

Ragent Ltd.

Data Protection Officer:

Contact us

General Contact:

Contact us

Legal Basis:

Contract performance, legitimate interests, consent

AI Processing & Training Policy

We use the following AI models to provide our Service:

Anthropic Claude
OpenAI GPT

The specific model used may vary based on service availability and your subscription plan.

AI models are used for:

  • Processing your requirements documents and conversations

  • Generating structured work items (Epics, Stories, Tasks)

  • Providing intelligent question generation

  • Validating and improving work item quality

  • Maintaining conversation context and history

When you use our Service, your content is sent to AI providers for processing. This is necessary to provide the Service functionality.

What is shared:

  • Your requirements and conversations

  • Uploaded documents (text extracted from PDFs, DOC, DOCX files, etc.)

  • Project context and configurations

Safeguards:

  • Data processing agreements with AI providers (where applicable)

  • Encryption in transit and at rest

  • No use of your data for training purposes

File Uploads & Processing

For main processing:

PDF (.pdf)
Microsoft Word (.docx, .doc)
Text files (.txt)

For reference context: In addition to the above, we also support image files (JPG, PNG) for reference purposes. Note: Image files are not processed by AI models and are used for reference only.

When you upload files:

  1. Files are received and temporarily stored on our servers

  2. Text is extracted from files (for PDFs and Word documents)

  3. Extracted text is processed by AI models to understand your requirements

  4. Files are stored securely in our database

  5. Files are associated with your projects and conversations

Files are stored securely in our cloud infrastructure (Firebase/Google Cloud), encrypted at rest, and retained for the duration of your account plus 2 years after account closure. You can delete files at any time through the Service interface.

Conversation History & Data Storage

We store your conversations to maintain context across multiple interactions, enable conversation history and retrieval, and provide continuity in your project work.

Active Conversations:

Stored for the duration of your account

After Account Closure:

Retained for 2 years, then permanently deleted

Deleted Conversations:

Permanently removed within 30 days

Access Controls:

Conversations are private to your account

Data Processing Activities

Processing your data to provide our AI-powered project management services.

User Data
Usage Data
Project Data
Conversations
Files

Retention: 2 years after account closure

Processing payment information and managing subscriptions through Stripe.

Payment Data
Billing Data
Subscription Data

Retention: 7 years (legal requirement)

Detecting and preventing fraudulent activity, monitoring for unauthorized access, and maintaining security.

IP Addresses
Device Fingerprints
Security Logs

Retention: 3 years

Analyzing usage patterns to improve our services and user experience (on anonymized data).

Usage Statistics
Performance Data
Error Logs

Retention: 2 years (anonymized)

Data Sharing & Third Parties

We share your information with the following third parties only as necessary to provide the Service:

Purpose: AI processing for service functionality

Data Shared: Requirements, conversations, documents, project context

Safeguards: Data processing agreements, encryption, no training use

Purpose: Payment processing and billing management

Safeguards: PCI DSS compliance, data processing agreement

Purpose: Data storage, authentication, and hosting

Safeguards: Data processing agreement, encryption, industry-standard security practices

Purpose: Website usage analysis (with consent)

Data Shared: Usage statistics, performance metrics (anonymized)

Legal Basis: Consent

Email Services: Brevo

All sub-processors are bound by data processing agreements that require them to process data only as instructed, implement appropriate security measures, and comply with applicable data protection laws.

International Data Transfers

Your data is primarily stored in the United States. For transfers from the European Economic Area (EEA) or United Kingdom, we use EU-approved Standard Contractual Clauses (SCCs) with all third-party processors and implement additional technical and organizational measures to protect your data.

If you are located in the EEA or UK, you have the right to request information about data transfers, object to transfers based on legitimate interests, and request additional safeguards for transfers.

Your Rights Under GDPR

Right of Access (Article 15):

Request a copy of your personal data. Use the data export feature in your account settings or contact us.

Right to Rectification (Article 16):

Correct inaccurate or incomplete data. Update your information in account settings or contact us.

Right to Erasure (Article 17):

Request deletion of your personal data. Use the data deletion feature in your account settings or contact us.

Right to Restriction (Article 18):

Limit how we process your data. Contact us to request restriction.

Right to Data Portability (Article 20):

Receive your data in a machine-readable format (JSON, CSV, XML). Use the data export feature in your account settings.

Right to Object (Article 21):

Object to processing based on legitimate interests. Update your consent preferences in account settings or contact us.

Security Measures

Encryption:

All data encrypted in transit (TLS 1.2+) and at rest using industry-standard encryption

Access Controls:

Multi-factor authentication (MFA) available, role-based access controls, least privilege principle

Infrastructure:

Enterprise-grade cloud infrastructure (Firebase/Google Cloud), 24/7 security monitoring

Compliance:

GDPR compliance, PCI DSS (via Stripe for payment processing)

Children's Privacy

If you are a parent or guardian and believe your child has provided us with personal information, please contact us. We comply with the Children's Online Privacy Protection Act (COPPA).

Automated Decision-Making

Our Service uses automated processing, including AI-powered work item generation, fraud detection, and usage tracking. You have the right to request human review of any automated decision that significantly affects you.

To request human review, contact us. We will provide human review within 30 days.

Cookies & Tracking Technologies

These cookies are necessary for the website to function and cannot be switched off.

Session Management
Authentication
Security

Retention: Session duration

These cookies enable enhanced functionality and personalization.

Preferences
Settings
User Interface

Retention: 1 year | Can Disable: Yes

These cookies help us understand how visitors interact with our website. We use Google Analytics and Firebase Analytics.

Usage Statistics
Performance Metrics
Error Logs

Retention: 2 years | Can Disable: Yes | Third Parties: Google Analytics, Firebase Analytics

We may use marketing platforms such as Google Ads, Facebook Pixel, and LinkedIn Insight in the future. You will be notified and can manage your preferences when these are implemented.

Retention: 1 year | Can Disable: Yes

Data Breach Notification

We are committed to protecting your data and will notify you promptly if a data breach occurs that may affect your personal information.

Within 72 Hours:

We will assess the breach and notify the relevant supervisory authority if required

As Soon as Possible:

We will notify affected users if the breach poses a high risk to their rights and freedoms

Notification will include information about the nature of the breach, the data that may have been affected, steps we are taking to address it, and steps you can take to protect yourself.

Marketing Communications

We may send you marketing communications if you have consented to receive them. You can opt-out at any time by:

  • Clicking "unsubscribe" in any marketing email

  • Updating preferences in your account settings

  • Contacting us

Even if you opt-out of marketing, we will still send you service-related notifications, billing information, important policy changes, and responses to your support requests.

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, applicable laws, new features, or user feedback.

We will notify you of material changes by email to your registered email address and/or by displaying a notification in the Service. Changes will become effective immediately or 30 days after notification for material changes.

Your continued use of the Service after changes become effective constitutes acceptance of the updated policy. You can review the current policy at any time at http://127.0.0.1:8000/privacy.

Contact Us

Privacy Inquiries:

Contact us

Response time: 30 days (or sooner if required by law)

General Support:

Contact us

Response time: 24-48 hours

Privacy Policy | Ragent

Learn how Ragent handles data for teams using AI Jira backlog generation and revenue systems workflows.