Privacy Policy
Last updated: November 10, 2025
Ragent Ltd. ("we", "our", or "us") is committed to protecting your privacy and complying with applicable data protection laws, including the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other relevant privacy regulations.
This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered project management application ("Service"). By using our Service, you agree to the collection and use of information in accordance with this policy.
Data Controller Information
Data Controller:
Ragent Ltd.
Data Protection Officer:
Contact usGeneral Contact:
Contact usLegal Basis:
Contract performance, legitimate interests, consent
AI Processing & Training Policy
We use the following AI models to provide our Service:
The specific model used may vary based on service availability and your subscription plan.
AI models are used for:
Processing your requirements documents and conversations
Generating structured work items (Epics, Stories, Tasks)
Providing intelligent question generation
Validating and improving work item quality
Maintaining conversation context and history
When you use our Service, your content is sent to AI providers for processing. This is necessary to provide the Service functionality.
What is shared:
Your requirements and conversations
Uploaded documents (text extracted from PDFs, DOC, DOCX files, etc.)
Project context and configurations
Safeguards:
Data processing agreements with AI providers (where applicable)
Encryption in transit and at rest
No use of your data for training purposes
File Uploads & Processing
For main processing:
For reference context: In addition to the above, we also support image files (JPG, PNG) for reference purposes. Note: Image files are not processed by AI models and are used for reference only.
When you upload files:
Files are received and temporarily stored on our servers
Text is extracted from files (for PDFs and Word documents)
Extracted text is processed by AI models to understand your requirements
Files are stored securely in our database
Files are associated with your projects and conversations
Files are stored securely in our cloud infrastructure (Firebase/Google Cloud), encrypted at rest, and retained for the duration of your account plus 2 years after account closure. You can delete files at any time through the Service interface.
Conversation History & Data Storage
We store your conversations to maintain context across multiple interactions, enable conversation history and retrieval, and provide continuity in your project work.
Active Conversations:
Stored for the duration of your account
After Account Closure:
Retained for 2 years, then permanently deleted
Deleted Conversations:
Permanently removed within 30 days
Access Controls:
Conversations are private to your account
Data Processing Activities
Processing your data to provide our AI-powered project management services.
Retention: 2 years after account closure
Processing payment information and managing subscriptions through Stripe.
Retention: 7 years (legal requirement)
Detecting and preventing fraudulent activity, monitoring for unauthorized access, and maintaining security.
Retention: 3 years
Analyzing usage patterns to improve our services and user experience (on anonymized data).
Retention: 2 years (anonymized)
Data Sharing & Third Parties
We share your information with the following third parties only as necessary to provide the Service:
Purpose: AI processing for service functionality
Data Shared: Requirements, conversations, documents, project context
Safeguards: Data processing agreements, encryption, no training use
Purpose: Payment processing and billing management
Safeguards: PCI DSS compliance, data processing agreement
Purpose: Data storage, authentication, and hosting
Safeguards: Data processing agreement, encryption, industry-standard security practices
Purpose: Website usage analysis (with consent)
Data Shared: Usage statistics, performance metrics (anonymized)
Legal Basis: Consent
Email Services: Brevo
All sub-processors are bound by data processing agreements that require them to process data only as instructed, implement appropriate security measures, and comply with applicable data protection laws.
International Data Transfers
Your data is primarily stored in the United States. For transfers from the European Economic Area (EEA) or United Kingdom, we use EU-approved Standard Contractual Clauses (SCCs) with all third-party processors and implement additional technical and organizational measures to protect your data.
If you are located in the EEA or UK, you have the right to request information about data transfers, object to transfers based on legitimate interests, and request additional safeguards for transfers.
Your Rights Under GDPR
Right of Access (Article 15):
Request a copy of your personal data. Use the data export feature in your account settings or contact us.
Right to Rectification (Article 16):
Correct inaccurate or incomplete data. Update your information in account settings or contact us.
Right to Erasure (Article 17):
Request deletion of your personal data. Use the data deletion feature in your account settings or contact us.
Right to Restriction (Article 18):
Limit how we process your data. Contact us to request restriction.
Right to Data Portability (Article 20):
Receive your data in a machine-readable format (JSON, CSV, XML). Use the data export feature in your account settings.
Right to Object (Article 21):
Object to processing based on legitimate interests. Update your consent preferences in account settings or contact us.
Security Measures
Encryption:
All data encrypted in transit (TLS 1.2+) and at rest using industry-standard encryption
Access Controls:
Multi-factor authentication (MFA) available, role-based access controls, least privilege principle
Infrastructure:
Enterprise-grade cloud infrastructure (Firebase/Google Cloud), 24/7 security monitoring
Compliance:
GDPR compliance, PCI DSS (via Stripe for payment processing)
Children's Privacy
If you are a parent or guardian and believe your child has provided us with personal information, please contact us. We comply with the Children's Online Privacy Protection Act (COPPA).
Automated Decision-Making
Our Service uses automated processing, including AI-powered work item generation, fraud detection, and usage tracking. You have the right to request human review of any automated decision that significantly affects you.
To request human review, contact us. We will provide human review within 30 days.
Cookies & Tracking Technologies
These cookies are necessary for the website to function and cannot be switched off.
Retention: Session duration
These cookies enable enhanced functionality and personalization.
Retention: 1 year | Can Disable: Yes
These cookies help us understand how visitors interact with our website. We use Google Analytics and Firebase Analytics.
Retention: 2 years | Can Disable: Yes | Third Parties: Google Analytics, Firebase Analytics
We may use marketing platforms such as Google Ads, Facebook Pixel, and LinkedIn Insight in the future. You will be notified and can manage your preferences when these are implemented.
Retention: 1 year | Can Disable: Yes
Data Breach Notification
We are committed to protecting your data and will notify you promptly if a data breach occurs that may affect your personal information.
Within 72 Hours:
We will assess the breach and notify the relevant supervisory authority if required
As Soon as Possible:
We will notify affected users if the breach poses a high risk to their rights and freedoms
Notification will include information about the nature of the breach, the data that may have been affected, steps we are taking to address it, and steps you can take to protect yourself.
Marketing Communications
We may send you marketing communications if you have consented to receive them. You can opt-out at any time by:
Clicking "unsubscribe" in any marketing email
Updating preferences in your account settings
Contacting us
Even if you opt-out of marketing, we will still send you service-related notifications, billing information, important policy changes, and responses to your support requests.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, applicable laws, new features, or user feedback.
We will notify you of material changes by email to your registered email address and/or by displaying a notification in the Service. Changes will become effective immediately or 30 days after notification for material changes.
Your continued use of the Service after changes become effective constitutes acceptance of the updated policy. You can review the current policy at any time at http://127.0.0.1:8000/privacy.
Contact Us
Privacy Inquiries:
Contact usResponse time: 30 days (or sooner if required by law)
General Support:
Contact usResponse time: 24-48 hours