RilobaseRilobase

Privacy Policy

Last Updated: August 2, 2026

1. Our Commitment to Privacy

Rilobase is built with a privacy-first architecture. We do not sell your personal data, and we do not use your prompts to train proprietary models. This policy explains exactly what data we collect, why we store it, and how we protect your most sensitive information.

2. Data We Store

Account Information

We store your email address and the full name you provide to create your account. This is used strictly for authentication and profile display.

Chat History

Your prompts and the AI's generated responses are stored in our database. This is necessary to provide the chat interface, display your history in the sidebar, and allow you to resume previous conversations. This data is tied exclusively to your user ID.

Verified Facts (The Cache)

To make the system fast and cost-effective, Rilobase extracts verified facts from web pages and stores them in a local cache. This cache stores the meaning of the question and the extracted answer so that future users asking the same question get an instant response. These cached facts are not linked to your user ID. They are stored globally to benefit all users.

3. How We Protect Your API Keys

Rilobase operates on a Bring Your Own Key (BYOK) model. We understand that API keys are highly sensitive financial credentials. Therefore, we employ a strict zero-knowledge encryption model for your keys:

  • AES-256 Encryption: The moment you submit an API key, it is encrypted on the server using AES-256 before being written to the database.
  • Memory-Only Decryption: The key is only decrypted in the server's RAM for the exact milliseconds it takes to forward your prompt to the AI provider. It is never written to disk, never logged, and is immediately purged from memory.
  • No Internal Access: Rilobase engineers and administrators cannot view, extract, or use your API keys. We do not have the ability to decrypt them outside of the live, automated request flow.

4. Third-Party Processors

To deliver the Service, your data is processed by the following trusted third parties:

  • Supabase: Used for user authentication and secure storage of chat history.
  • AI Providers (OpenAI, Anthropic, Groq): When you send a message, your prompt and the scraped web context are sent to the AI provider whose key you provided. These providers process the data according to their own privacy policies.

5. Data Retention and Deletion

We retain your data for as long as your account is active. You have full control over your data and can delete it at any time:

  • You can delete individual chats via the sidebar menu.
  • You can delete your entire chat history via the "Data & Privacy" tab in Settings.
  • You can permanently delete your account and all associated data via the Account Settings.

6. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any significant changes by posting the new policy on this page and updating the "Last Updated" date.