RilobaseRilobase

Privacy Policy

Last Updated: August 12, 2026

1. Our Commitment to Privacy

Rilobase is built with a privacy-first architecture. We do not sell your personal data, and we do not use your prompts to train proprietary models. This policy explains exactly what data we collect, why we store it, the legal basis for processing it (under GDPR and CCPA), and how we protect your most sensitive information.

2. Information We Collect

Account Information

We collect your email address and the full name you provide to create your account. This is used strictly for authentication and profile display.

AI API Keys

To operate our "Bring Your Own Key" model, we collect the API keys you provide (OpenAI, Anthropic, Groq, Google). These keys are encrypted immediately using AES-256 encryption.

Chat History & Attachments

Your prompts, uploaded files, and the AI's generated responses are stored in our database to provide the chat interface and history. This data is tied exclusively to your user ID.

Billing Metadata

When upgrading to Pro, our payment processor (Polar.sh) shares your subscription status with us. We do not store your credit card numbers.

3. The Global Semantic Cache (Anonymized Data)

To make the system fast and cost-effective, Rilobase extracts verified facts from web pages and your AI interactions. We strip this data of all Personal Identifiable Information (PII) using NLP scrubbing, and store the factual answer in a global semantic cache. This cached data is NOT linked to your user ID or email. It is stored globally and anonymously to benefit all users.

4. How We Protect Your API Keys

We understand that API keys are highly sensitive financial credentials. We employ a strict zero-knowledge encryption model:

  • AES-256 Encryption: Keys are encrypted on the server using Fernet (AES-128 in CBC mode) before being written to the database.
  • Memory-Only Decryption: The key is only decrypted in the server's RAM for the exact milliseconds it takes to forward your prompt to the AI provider. It is never written to disk, never logged, and is immediately purged.
  • No Internal Access: Rilobase engineers cannot view or extract your API keys.

5. Legal Basis for Processing (GDPR)

If you are a resident of the European Economic Area (EEA), we process your personal information under the following legal bases:

  • Performance of a Contract: Processing your data to provide the chat history and AI generation services you requested.
  • Legitimate Interests: Storing anonymized facts in the global cache to improve service efficiency for all users.
  • Consent: Using cookies to keep you logged in (you can withdraw consent via our cookie banner).

6. Your Privacy Rights (GDPR & CCPA)

Depending on your location, you have the following rights regarding your personal data:

  • The Right to Access: You can request a copy of your personal data.
  • The Right to Rectification: You can update your name or language settings via the Settings page.
  • The Right to Erasure (Right to be Forgotten): You can permanently delete your account, chat history, and API keys at any time via the Settings - Data & Privacy tab.
  • The Right to Opt-Out: You can opt-out of the global cache by asking subjective/generative questions, which are routed to an ephemeral 1-hour local cache instead of the global permanent database.

7. Third-Party Processors

To deliver the Service, your data is processed by the following trusted third parties:

  • Supabase: Used for user authentication.
  • Cloudflare: Used for hosting the frontend application and protecting against DDoS attacks.
  • Polar.sh: Used for processing Pro subscription payments.
  • AI Providers (OpenAI, Anthropic, Groq, Google): Your prompts and scraped web context are sent to the AI provider whose key you provided.

8. Data Retention

We retain your account data and chat history for as long as your account is active. Anonymized facts in the global cache are retained based on their volatility (e.g., stock prices expire in 1 day, historical facts expire in 365 days). Bad facts receiving negative user feedback are automatically quarantined and deleted.

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any significant changes by posting the new policy on this page and updating the "Last Updated" date.