Plain reading: your documents, questions and answers stay in your workspace and are sent only to the model provider you chose, under your own key. We hold account, sign-in and usage records to run the service. Nothing is sold, nothing trains a model, and you can delete all of it yourself.
Summary of our approach
This policy explains what PrivateRAG, provided by David Wagih, collects, why, where it goes and how to remove it. It is written to be read, not skimmed past.
What we collect
Your email address, display name and password (hashed with scrypt), plus an optional authenticator secret and recovery codes (hashed) — to create and secure your account and to reach you about it, kept until you delete the account.
The documents you upload, the links you add, the questions you ask and the answers you receive — that is the Service: they are indexed so your questions can be answered from them, kept until you delete them or the account.
Model provider keys you connect — to send requests to your provider on your behalf; encrypted at rest and removed when you remove them.
Sign-in records (address, browser family, time, session lineage) — to show you your sessions, warn you of unusual sign-ins and detect a copied cookie. Usage counts per model call (tokens, cost) — to show you what your questions cost and to bill AI credit. Your browser's timezone and language — so answers use your currency, date format and language; never your location from your address.
What we never collect
We do not sell data, we do not show advertising, and we do not use your content to train any model. No account's material is visible to another account unless its owner offers to share it and the other side accepts.
Where it goes
To answer a question, excerpts of the relevant documents are sent to the model provider you chose (for example OpenAI, Anthropic, Google, or an OpenAI-compatible endpoint you configured) under your key and their privacy terms. If you turn on web search, the question is sent to a search API (Serper.dev) and the pages it returns are fetched by us. If you ask for scanned-page reading, the page images are sent to Amazon Textract. Transcription of audio you add may use your provider or a local model.
Payments are handled by Paddle.com as Merchant of Record; we receive your email, plan and payment status, never your card details. Paddle's own policy covers what they collect.
Where it is stored
On servers operated for us by our hosting provider. Backups are taken daily and kept for 14 days; the encryption key for stored provider keys is kept separately from the backups.
Cookies
One session cookie, needed to keep you signed in. It is HttpOnly and Secure, rotated regularly, and ends when you sign out or after a period of inactivity. There are no tracking or advertising cookies. Your side-panel and theme preferences are kept in your browser's local storage and never sent anywhere.
Sharing inside the service
Nothing in your workspace is visible to another account unless you offer to share it and they accept. Every shared item can be switched off or withdrawn by either side. Answers that quote shared material say whose it is.
Security
Passwords are hashed with scrypt, provider keys are encrypted at rest, session tokens are hashed at rest and rotated, sensitive actions ask for your second factor again, and the recovery process for a lost account never issues a sign-in to anyone who has not been verified. Tell us about a security problem at david@zobitas.com.
Your rights
You can see, export and delete your data yourself: every conversation can be exported, every document removed, and the whole account deleted from the Security page, which removes documents, chats, keys and sessions and tells anyone you were sharing with.
For anything else — a copy of the records we hold, a correction, a complaint — write to david@zobitas.com and we will answer within 30 days. If you are in the EU or UK you also have the right to complain to your data protection authority.
Children
The Service is not for anyone under 18.
Changes and contact
We will email you at least 14 days before a material change to this policy.
Data controller: David Wagih, 617 Zayed The First St, Al Hisn, W6, Abu Dhabi, United Arab Emirates — david@zobitas.com.
Access, export or erasure, answered within thirty days.