Privacy Policy

Last updated: 24 July 2026

raggate is built to keep your sensitive data on your side of the wire. This policy explains what does and does not leave your machine.

What never leaves your machine

On the default local pipeline, the free scan runs fully offline: your corpus, queries, chunk text, document contents, and access-control snapshots are read and evaluated locally and are never transmitted to us. (If you point raggate at your own remote retrieval backend, queries reach your infrastructure — never ours.) When you run a paid action online — applying a remediation, or a scan beyond the free record cap — the checkpoint request contains only your license token, an idempotency id, and the resource kind and credit amount for the action (a count derived from the run size) — never chunk text, source content, or secrets. The local raggate ui dashboard binds to loopback and makes no outbound connection unless you explicitly pass --online.

What we collect

Service providers

We rely on a small set of processors: Clerk (authentication), Stripe (payments), Resend (transactional email), and Render (hosting). Each processes only what its function requires.

Cookies

The portal uses a session cookie from Clerk to keep you signed in. We do not use third-party advertising or tracking cookies.

Retention & your rights

We keep account and usage records for as long as your account is active and as needed for legal and accounting purposes. You may request access to, correction of, or deletion of your data by contacting us; we will respond within a reasonable time.

Contact

Privacy questions or requests: hitliqiwei@gmail.com.

This is a plain-language starting point, not legal advice. Have it reviewed by counsel before relying on it for compliance.