legal
Privacy Policy
This Privacy Policy explains how Raily LLC, a company registered in the Qatar Financial Centre, handles data when you use Raily AI Scoring.
Overview
Raily LLC is the controller for the Service and product data. Accounts are optional. Photographs use encrypted temporary processing storage; after a photograph is deleted, Raily retains only non-identifying derived scores and a random technical identifier. Raily does not verify the depicted person's identity or maintain a mapping from that identifier to a real-world identity. TEMNIKOVA LDA independently sells and bills Credits; Stripe processes card payments. This policy explains the purposes, recipients, choices and retention that apply.
Information We Collect
You choose whether to create an account, upload a photograph, import a public profile, save a report, enable Matching or connect a channel. Data needed for a feature is required to provide that feature; otherwise it is optional. We handle:
- Photographs you upload (full-face and profile images) — used only for the requested analysis and deleted when processing finishes. The remaining task record contains only a random technical ID, not the photograph.
- Non-identifying derived scores and a random technical identifier. A display label, if provided or explicitly saved from an import suggestion, is arbitrary user-supplied or user-confirmed text; Raily does not verify that it corresponds to the depicted person.
- Account, wallet, purchase, subscription, support, notification and connected-channel data when you use those features; and IP, browser, user-agent and security logs needed to operate and protect the Service.
- Language and consent preferences stored in your browser, plus temporary visible profile fields, canonical URL and photo when you deliberately use the extension or public-profile import.
Photographs — Our Commitment
We want to be explicit about how we handle your photographs:
- Raily does not add photographs to report or profile content. Once processing finishes, the photograph is deleted and the task record contains only a random technical ID.
- Raily does not use uploaded photos to train or improve its own models. Processor use is limited to delivering the requested analysis under the applicable provider terms and instructions.
- During processing, decrypted photos exist in transient memory and are sent to our deep analysis AI service (Raily Merlin) for feature extraction. The durable recovery copy is encrypted and access is restricted to the currently claimed task.
- The encrypted recovery copy is deleted when processing completes or finally fails, or when you delete your account. If a technical failure prevents processing from reaching that point, an automatic safety limit deletes the copy no later than 6 hours after upload. Encrypted remnants may remain in database backups or WAL until the database provider's bounded retention expires. Encryption keys are rotated operationally; old key material may remain in protected secret or configuration backups, so no exact key-deletion deadline is promised.
How We Use Your Information
We process data to perform our contract with you, pursue legitimate interests in operating and securing the Service, meet legal obligations, and rely on consent where law requires it, including optional analytics in the EEA and UK. The purposes are:
- Providing requested analyses, reports, comparisons, Matching, imports and AI explanations.
- Operating accounts, wallets, Credits, subscriptions, support, notifications, connected channels and saved user choices.
- Preventing abuse, enforcing rate and usage limits, debugging failures and maintaining service reliability.
- Protecting users and the Service, handling moderation and incidents, complying with law, and producing aggregate product analytics.
Third-Party Processors
Depending on the feature and launch configuration, recipients include Supabase (database, authentication and storage), Raily Merlin (deep photo analysis), LLM and AI inference providers (requested explanations and moderation), Upstash (rate limiting), Google Analytics/Tag Manager (optional web analytics), Stripe and TEMNIKOVA LDA (billing), Resend (email), Cloudflare (delivery and public-profile browser resolution), LinkedIn (optional sign-in/import connection), Telegram (optional connected channel), and DigitalOcean (hosting). Inactive or unconfigured integrations do not receive data.
Raily Merlin (api.raily.cloud)
Our deep analysis AI service. Raily sends the photo without an account name or verified real-world identity. Raily Merlin returns numerical features and deletes its processing copy after analysis. The Raily API's encrypted recovery copy follows the automatic safety rule described above.
LLM and AI inference providers
Used for narrative interpretations, comparison translation and other requested AI explanations. They receive non-identifying derived-score context or non-identifying report strings, not photographs, account names, email addresses or other direct personal identifiers. If you report a conversation, they may receive the reported text as moderation evidence after email addresses, links, phone numbers and handles are removed; the remaining text may still contain a name.
Sentry (error and performance monitoring)
Sentry receives errors and sampled performance traces from our website, API, and background workers so we can diagnose reliability problems. We send only sanitized exception types and stack source locations, parameterized routes, service/runtime/environment/release labels, timings and status classes, and hashed correlation identifiers. Sentry event fields do not include photos, report or psychometric payloads, prompts or completions, messages, names, email or IP addresses, raw URLs, queries or referrers, request or response bodies, local variables, cookies, authentication data, or tokens. When a browser sends an envelope directly to Sentry, Sentry necessarily processes the browser's source IP as transport metadata. Sentry Logs, Session Replay, and Profiles are disabled. We retain these events only for the bounded event-retention window included in our Sentry account plan and delete them sooner when no longer needed.
Google Analytics 4 (via Google Tag Manager)
Pseudonymous web analytics for page views, feature usage, and conversion funnels. When analytics is allowed, your browser stores a bounded landing-copy variant ID so the same version stays stable. While your analytics choice is pending or analytics is allowed, it may also keep a random one-time signup attempt ID for no more than 25 hours to prevent duplicate registration measurement; it is removed if you reject or withdraw. Google receives the experiment and variant IDs as the only experiment-specific fields, alongside bounded event parameters such as path-only page location, CTA location, and signup method. Events do not include names, email addresses, message content, photos, or analysis results. Google may process this data in the United States under its own terms.
Upstash Redis
Used for rate limiting and recovery coordination. It may receive short-lived personal or pseudonymous rate-limit identifiers, such as an IP-derived key, user or wallet identifier, plus counters and operation state. Rate-limit keys normally expire after approximately 25 hours; other operational keys use their documented short TTL.
Data Storage
Our architecture is designed to minimize data persistence:
- Accounts are optional — guests use an anonymous prepaid wallet that holds Raily Credits, identified only by a random token stored in your browser. If you choose to sign in, we store your email and link your wallet to it.
- We do use a database. During processing, a photo appears there only as a separate encrypted recovery copy and is deleted when processing finishes. If a technical failure prevents deletion at that point, an automatic safety limit removes it no later than 6 hours after upload. Saved reports, your numerical profile, Matching identity, cards, connections and messages, wallet and purchase records use the retention periods listed above.
- An unsaved analysis result is also kept in your browser's sessionStorage for the tab session; the authoritative copy is the one described above.
- Your language preference is stored in your browser's localStorage and can be cleared at any time.
Data Retention
All data has strict, minimal retention periods:
- Photographs: deleted when processing completes or finally fails, or on account deletion. If a technical failure prevents normal deletion, an automatic safety limit removes the encrypted recovery copy no later than 6 hours after upload. The remaining task record contains only a random technical ID. Backup/WAL remnants follow the database provider's bounded retention. Non-identifying derived scores are normally kept for 30 days unless you save the report or enable Matching. A Matching avatar you deliberately enable is separate derived imagery, stored until you turn it off; display stops immediately and file deletion follows the documented purge process.
- Analysis results: an unsaved report is deleted within 24 hours. A report you explicitly save is kept until you delete it or delete your account.
- Rate limit counters: Automatically expire after ~25 hours.
- Task metadata: Purged after 24 hours or when the task queue exceeds 100 entries.
Cookies and Tracking
Necessary browser storage supports language, session, wallet and security functions. Google Tag Manager and Google Analytics 4 may collect pseudonymous page, feature and conversion events; we do not send names, email addresses, message content, photos or analysis results to Google. In the EEA and UK, these analytics remain off until you accept them; you can reject or later withdraw through the privacy settings. We do not use advertising trackers. Our first-party product journal records bounded product events tied to wallet and session identifiers, never free text, message content or photos; identifiers are removed after 14 months and on account deletion, while aggregate counts may remain.
Chrome Extension (Raily AI - Send Profile)
The optional Raily AI Chrome extension is a capture client for your own Raily account. It does not create a separate product or advertising surface.
- What it may collect: the visible name, visible heading, canonical profile URL, and one profile photo from the single profile page you open — or one photo you choose via the panel file picker, a file drop, or a URI drop. A dropped file's filename (without extension) is sent as display_name for that photo-only import.
- When transfer happens: only after you click the extension icon or in-page action, review the local preview, confirm you have permission and that the person is over 18, and approve the one-time upload in your Raily account.
- Where data goes: only to your own Raily account on this website for a private insight. We do not sell the data, use it for advertising, or use it for purposes unrelated to that private analysis.
- What it never accesses: LinkedIn cookies, access tokens, passwords, messages, connections, posts, search history, full-page content, or any page data beyond the fields listed above (or the single photo you drag in).
- Retention: the pending local snapshot is cleared on cancel, after upload, or the next time the extension hydrates pending state after ten minutes of idle time (there is no separate expiry alarm). A server-side imported photo is deleted when processing finishes; if a technical failure prevents normal deletion, the same automatic 6-hour safety limit applies to its encrypted recovery copy.
- The extension is not affiliated with or endorsed by LinkedIn or any other third-party social network.
Your Rights (GDPR / CCPA)
Regardless of your jurisdiction, we extend the following rights to all users:
- Right to access — request a copy of any data we hold about you.
- Right to deletion — ask us to delete eligible account, report, Matching, message and connected-channel data. Photos are deleted when processing finishes or on account deletion; if a technical failure prevents normal deletion, an automatic safety limit removes the encrypted recovery copy no later than 6 hours after upload. Financial records for Raily Credits and security records may be retained where law or dispute handling requires it; bounded backups expire on the provider schedule.
- Right to correction — ask us to correct account information or a saved display label. Re-running a model is available but is not a substitute for correcting account data.
- Right to access and portability — request a copy of data associated with your account or wallet in a commonly usable format where applicable.
- Right to object, restrict or withdraw consent — ask us to assess an objection or restriction request and withdraw optional analytics consent without affecting earlier lawful processing.
Contact [email protected]. We may request information reasonably necessary to locate the account or wallet and verify that the request comes from the authorised account holder. You may also complain to the QFC Data Protection Office and, where applicable, your local data protection authority.
Children's Privacy
The Service is not directed at individuals under the age of 18 (or the age of majority in your jurisdiction). We do not knowingly collect data from children. If you believe a child has submitted personal data through the Service, contact us at [email protected] and we will take appropriate steps to address the matter.
International Data Transfers
The Service is operated from Qatar and providers may process data in other countries, including the United States. Where transfer restrictions apply, we use the applicable provider terms, contractual safeguards or other lawful transfer mechanism and assess them for the relevant entity and region. Contact [email protected] to request information about safeguards relevant to your data.
Changes to This Policy
We may update this Policy prospectively and will publish the revised version and effective date. We will provide reasonable notice of material changes and request renewed acceptance where applicable. Continued use alone will not replace consent or acceptance where law requires an affirmative choice.
Contact Us
For any privacy-related questions, data subject requests, or concerns, please contact us at:
Raily LLC
Al Shoumoukh Towers, 10th Floor, Tower B, Al Sadd, Doha, Qatar
Email: [email protected]
Effective date
August 25, 2026