Skip to main content

Legal

Design-partner privacy notice

Effective: August 11, 2026

This notice covers the public website, pilot contact request, invite-only preview accounts, and hosted control plane. Data handled inside a customer-run gateway requires a separate written pilot agreement before a live evaluation.

1. Scope

RANKIGI Inc. operates rankigi.com and an invite-only hosted control plane for the authority-gateway design-partner pilot. This notice explains the information RANKIGI handles on those surfaces. It does not claim that the pilot is generally available or approved for a regulated workload.

2. Information we collect

Contact requests. We receive the name, work email, and optional workflow context you submit. Our email provider returns message-acceptance metadata for that request.

Preview identity and security data. For manually provisioned accounts, we may process email address, organization membership, session and MFA state, passkey public-credential data, security events, and account-recovery records.

Hosted control-plane records. The pilot may store signed grants, policies, approval evidence, public keys, non-secret credential references, gateway registrations, and related history. The hosted control plane must not receive the governed provider credential.

Operational data. We may process IP address, timestamps, route and response metadata, browser or device data, rate-limit state, and application-error and performance diagnostics needed to operate and secure these surfaces. Session Replay is disabled.

3. Customer gateway boundary

The GitHub App private key, installation token, customer PostgreSQL ledger, issue plaintext used for execution, and provider contact occur in customer-controlled infrastructure. RANKIGI does not ask the agent or hosted control plane to hold the governed provider credential. If a customer intentionally exports evidence to the hosted service, the separate pilot agreement must define that transfer before it occurs.

4. Data the active pilot does not accept

Do not submit protected health information, payment-card data, raw bank-account information, production financial credentials, private signing keys, GitHub private keys, access tokens, or other provider secrets through the website, contact form, or hosted control plane. RANKIGI does not currently offer a Business Associate Agreement for this pilot.

5. How we use information

We use the information above to respond to a contact request, provision and authenticate an approved preview user, operate the hosted control plane, investigate security or reliability issues, prevent abuse, communicate about the evaluation, and meet legal obligations. We do not sell personal information or use customer pilot content to train a machine-learning model.

6. Service providers

The hosted surfaces currently rely on Railway for application hosting, Supabase for hosted database and authentication services, Resend for contact and transactional email, Upstash for rate-limit state where configured, and Sentry for application-error and performance monitoring. Session Replay is disabled. Sentry does not attach default PII and strips authorization, API-key, and cookie request headers; exception and breadcrumb content may still be processed when relevant to a captured diagnostic. These providers process information for their assigned function. Customer-controlled AWS and GitHub accounts are outside the hosted credential boundary and remain controlled by the participating organization.

7. Retention and deletion

RANKIGI keeps contact, account, security, and hosted control-plane information only as needed for the evaluation, security, troubleshooting, dispute handling, and applicable legal obligations. Exact pilot retention, export, backup, and deletion terms must be stated in the separate pilot agreement. We do not represent legacy subscription-tier schedules as the active pilot retention policy. You may request deletion, subject to records that must be retained for security or legal reasons.

8. Security and limits

We use access controls, protected session handling, database authorization, and secret-separation measures appropriate to the current preview. No internet service is completely secure. The customer is responsible for its gateway, provider account, secret manager, database, backups, endpoints, and authorized users. Report suspected vulnerabilities to security@rankigi.com without including secrets or customer evidence in the initial email.

9. Choices and requests

Depending on applicable law, you may request access, correction, deletion, or a copy of personal information associated with you. Send requests to privacy@rankigi.com. We may need to verify the request before acting on it. You may also decline to submit the contact form and email us directly.

10. Changes and contact

We may update this notice as the pilot changes. The effective date above identifies this version. Material data terms for an active design-partner evaluation must also follow the signed pilot agreement. Questions may be sent to privacy@rankigi.com or legal@rankigi.com.