Privacy Policy

Last updated: 1 May 2026 — DRAFT — pending legal review

1. Who We Are

Risicare is operated by [TBD-LEGAL: registered entity name and address] (“Risicare”, “we”, “us”). Our data protection contact is support@risicare.ai.

2. What Data We Collect

3. How We Use Your Data

We do not sell your data. We do not use your telemetry data to train models without your explicit written consent.

4. Sub-Processors

We share data with the following sub-processors to operate the service:

Sub-processorPurposeData transferred
Amazon Web Services (AWS)Infrastructure hosting (EC2, S3)All platform data
Together AILLM inference for error diagnosisThe error context of a diagnosed trace — its error message and stacktrace, and the prompts, completions, tool inputs and tool outputs of the spans around it. Credentials, and email, phone, SSN, card and IP patterns, are redacted before it is sent. Redaction is pattern-based and does not catch free-text personal data such as names or addresses.
GitHub / Google (OAuth)AuthenticationEmail, public profile

When Together AI receives anything: only when a diagnosis runs. A diagnosis runs when you ask for one on a specific trace, or — if you have asked us to turn it on for a project — automatically when a trace in that project errors. Automatic diagnosis is off by default. If neither applies, no trace content is sent to any LLM provider.

5. Data Retention

6. Your Rights (GDPR)

If you are located in the European Economic Area, you have the following rights under the General Data Protection Regulation (GDPR):

To exercise any right, email support@risicare.ai. We respond within 30 days.

7. Security

Data is encrypted in transit (TLS 1.2+) and at rest with AES-256, via EBS volume encryption for databases and server-side encryption for object storage. Encryption at rest protects against physical disk access and storage-snapshot exposure; it does not by itself protect data in use on a running server. API keys are stored as SHA-256 hashes. We operate a responsible disclosure programme at security@risicare.ai.

8. Breach Response

In the event of a personal data breach, we will notify affected users and, where required by GDPR Article 33, the relevant supervisory authority within 72 hours of becoming aware.

9. Cookies

We use one session cookie (__Secure-authjs.session-token) to maintain authentication. No third-party tracking cookies are set.

10. Changes

We will notify account holders by email at least 14 days before material changes take effect. Continued use after the effective date constitutes acceptance.

11. Contact

[TBD-LEGAL: registered address]
Email: support@risicare.ai
DPO (if applicable): [TBD-LEGAL]