What this policy covers
Ralti helps you organize work, collaborate, connect email and use AI-assisted tools. This app policy is separate from the public website’s early-access form and optional website analytics. Installing through TestFlight does not automatically approve app access; the beta is limited to approved accounts. Ralti’s operator handles app privacy questions at hello@getralti.com.
Account and sign-in information
Clerk provides sign-in and account authentication. Ralti receives account identifiers, your name, email address and verification information to recognize you, check early-access approval and associate you with workspaces and permissions. If you choose a social sign-in provider, that provider also processes the sign-in. Your Ralti account is used across the web and installed apps.
Workspace content and activity
We store the information you and authorized collaborators put into Ralti: workbooks, sheets, records, documents, uploaded files, comments, assignments, rules and helper configurations. We also retain supporting information such as membership, activity and version history, AI requests and results, helper run outcomes, and permission or review decisions. This information is used to provide the workspace, synchronize devices, retrieve information, recover work and enforce access rules. Only add information you are authorized to share and process.
Connected email
Connecting a mailbox authorizes Ralti to synchronize message information such as senders, recipients, subjects, timestamps and message content, and to support the available email actions. Ralti stores synchronized copies, record links, categories and drafts. Google and Microsoft connections use provider tokens; password-based IMAP/SMTP connections store the credentials needed to connect. Stored connection secrets are encrypted, but the service must decrypt them to use the connection. Email content is not end-to-end encrypted between you and Ralti.
- Mailbox access is separate from signing in to Ralti. Connect only accounts you are authorized to use.
- Your mailbox is private to your account unless you share conversations or explicitly grant a helper access. Content placed into shared records, documents or notifications follows those destinations’ permissions.
- Sending and other supported mailbox actions communicate with your email provider. Recipients receive the content you send. Existing connected mailboxes remain available during the beta; some new connection or reconnection flows are still being verified.
AI, search and helpers
Enabled AI features use OpenAI. Your request and relevant workspace or email context can be sent to OpenAI to generate an answer, propose changes, prepare a document or perform a configured agent task. Optional AI inbox sorting also sends message information for classification. Deterministic rules do not need an AI model.
- Semantic search can send workspace and synchronized email text to OpenAI in the background to create search representations, even when you are not submitting a chat message. Search results still follow the app’s access checks.
- Email agents require an explicit mailbox grant and use its approved selection. Review instructions, input sources, actions and mode before enabling a helper. Authorized automatic helpers can process their inputs without a separate prompt for every run.
- Ordinary AI proposals require review before changing your workspace. This review protects changes; it does not prevent the preceding AI processing of the information used to prepare them.
- The current response requests ask OpenAI not to store a retrievable response object. This is not a promise of zero provider retention, zero safety logging or zero processing. OpenAI’s applicable service terms and data controls also govern its handling.
Dictation, files and device features
On iPhone and iPad, dictation requests microphone and speech-recognition permission and uses Apple’s speech framework. The app does not force recognition to stay on the device, so audio may be processed by Apple depending on the device, language and service behavior. Ralti does not save an audio recording from this dictation feature; the resulting transcript becomes text input and is processed like other content when you submit or save it. You can type instead and change device permissions in Settings.
- File selection and uploads provide Ralti with the files you choose. Sharing, printing or exporting sends a copy to the destination you select. Those copies are controlled by that destination.
- The installed app uses browser storage and device security facilities to maintain its session. Browser-based dictation, when available, follows that browser’s speech service.
- Apple separately operates TestFlight and may process installation information, diagnostics or feedback under its own policies.
Where the beta runs
The current app uses a Supabase-hosted database for workspace and account-associated records. Its application server and background workers run on an operator-controlled Mac, and current uploaded attachment files are stored on that machine. Cloudflare provides the HTTPS connection to the beta server. This is an online beta: availability depends on that host remaining connected, and it does not support offline editing. Hosting and processing arrangements may change as the service develops; we will update this policy to reflect those changes.
Who can receive or access information
Authorized workspace members receive information according to the app’s sharing and role settings. Ralti’s operator can access server-stored information when operating, supporting or securing the service. Service providers process information necessary for their functions: Clerk for authentication, Supabase for the database, Cloudflare for network delivery and protection, OpenAI for enabled AI and semantic search, connected email providers for mailbox functions, and Apple for device and TestFlight services. Information may be processed in the countries where these services operate. This beta does not promise a user-selected storage region.
Clerk privacy information
Supabase privacy information
Cloudflare privacy information
Sessions, diagnostics and website analytics
The app uses session cookies, local browser storage and device storage for authentication, preferences, saved drafts and recovery. The application and its providers may process IP addresses, browser or device details, request information and error or security events to deliver and troubleshoot the service. The app does not include the public website’s Google Analytics integration. Optional analytics on getralti.com, including this policy page, are covered by the separate website notice and its consent controls.
Retention and disconnecting services
Account and workspace information is retained to operate the service, preserve shared work and support history, recovery and security. Archived records, saved versions, AI or helper results, operational records and backups can outlast their current appearance in the interface. During the beta, there is no published fixed retention period for every category.
- Disconnecting a mailbox stops its connection and removes the stored connection credentials; it does not automatically erase synchronized messages or content already copied into workspace records or results. You can also revoke access with the email provider.
- Removing a file from a record does not automatically erase its stored file bytes. Deleting or changing a record does not necessarily remove all historical or backup copies.
- Deleting the app, signing out or removing your website signup does not delete your Ralti account or workspace data. Copies already exported, printed, emailed or shared to another service cannot be recalled by Ralti.
Your choices and privacy requests
You can choose what to enter, which mailboxes to connect, what to share, which helpers to enable, and whether to use microphone access. Contact hello@getralti.com to request access, correction, account deletion or removal of stored app content, or to ask about a specific processing activity. We may need to verify your identity and your authority over a shared workspace before acting. We will explain the available steps and any retained copies relevant to your request. Please do not email passwords, access tokens or confidential message contents.
Security and policy updates
The beta uses HTTPS, authentication, workspace permissions and encrypted mailbox credentials. These measures do not make the service end-to-end encrypted or guarantee that every risk is eliminated. This policy does not claim a security certification or regulatory compliance status. We will revise the date and content when relevant practices change. Contact Ralti if a planned use requires guarantees that are not stated here.