Privacy Policy
Last updated: August 11, 2026
This policy explains what Ruligent ("we") collects when you use www.ruligent.com and the Ruligent service, why we collect it, how long we keep it, and the rights you have. We aim to collect the minimum we need to run a governance product.
1. What we collect
- Account data. Your name, email address, password (stored only as a scrypt hash — we never store or see the plaintext), and your organization name.
- Account-recovery delivery data. When password recovery is enabled and you request a reset, we send your name, email address, and a short-lived reset link to Resend for transactional delivery. The link expires after 30 minutes and becomes invalid after a successful password change.
- Agent activity data. When your systems call the guard endpoint, we record tool-call metadata — agent ID, tool, action, decision, reason, risk level, cost, and timestamps — together with a bounded payload summary. We store summaries, not raw payloads; do not send regulated or unnecessary personal data in payloads (see the Acceptable Use Policy).
- Audit events. The append-only decision log described above, retained per plan (see Retention).
- Billing data. Payments are processed by Stripe. We never store card numbers; we keep subscription status and Stripe customer references.
- Optional telemetry. Error reports via Sentry and product analytics via PostHog. Both are optional, configurable, and off by default in privately deployed deployments.
2. Why we collect it
- To provide the service: evaluate guarded calls, run approval workflows, maintain audit logs, enforce spend limits, and deliver webhooks to the URLs you configure.
- To operate accounts, authentication, and billing.
- To keep the service reliable and secure (error reporting, abuse prevention).
- To understand product usage where analytics are enabled.
- To communicate with you about the service (transactional email, support, material changes).
3. Retention
- Audit events are retained per plan and then automatically purged: 7 days on Free, 30 days on Founder, 180 days on Operator, 1 year on Business. Enterprise retention is set by contract.
- Account data is retained until you delete your account or ask us to delete it.
- Billing records are retained as required by tax and accounting law.
4. Who processes it
We use a small set of subprocessors: Vercel (hosting), Supabase (Postgres database), Stripe (payments), Resend (transactional account-recovery email, when enabled), and — where enabled — Sentry (errors) and PostHog (analytics). The current list, with purposes, locations, and data categories, is maintained at /legal/subprocessors. Webhooks are sent to URLs your organization configures; the receiving systems are under your control, not ours.
5. What we do not do
- We do not sell personal data.
- We do not use your agent activity data to train AI models or for advertising.
- The marketing site sets no tracking cookies (see the Cookie Policy).
6. Your rights
Depending on where you live, you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To exercise any of these rights, email www.ruligent.com/contact from the address on your account. We will respond within 30 days. Deletion requests remove account data and any remaining audit events attributable to your organization, subject to legal retention obligations. If you are in the EU/UK you may also lodge a complaint with your supervisory authority.
7. Roles
For account and billing data we act as a data controller. For agent activity data processed on behalf of your organization we act as a processor; the terms of that processing are set out in our Data Processing Addendum.
8. Security
Data is encrypted in transit; passwords are scrypt-hashed and API keys stored as SHA-256 digests; every query is scoped to your organization. See the Security Policy for the full picture, including what we do not yet have (e.g., no SOC 2 certification yet).
9. Changes and contact
We will post updates to this policy here and, for material changes, notify account owners by email. Contact: Ruligent, New York, United States — contact page.