Privacy Policy
Last updated: 1 May 2026 — DRAFT — pending legal review
1. Who We Are
Risicare is operated by [TBD-LEGAL: registered entity name and address] (“Risicare”, “we”, “us”). Our data protection contact is support@risicare.ai.
2. What Data We Collect
- Account data: email address and name provided via OAuth (GitHub or Google) at sign-up.
- Telemetry data you send: AI agent traces, spans, error reports, and evaluation scores you ingest via the SDK or API. This data is stored on your behalf and is controlled by you.
- Usage data: API call timestamps, endpoint paths, and response codes for rate limiting and abuse prevention. No request bodies are logged at the infrastructure level.
- PII detection flags: When PII redaction is enabled on a project, span content is scanned by regex; matching patterns are replaced with
[REDACTED:type]. We do not store the original PII.
3. How We Use Your Data
- Providing the observability and error-diagnosis platform you signed up for.
- Diagnosing agent failures using LLM-powered analysis (on your telemetry data).
- Sending product and security communications to your account email.
- Detecting abuse and enforcing rate limits.
We do not sell your data. We do not use your telemetry data to train models without your explicit written consent.
4. Sub-Processors
We share data with the following sub-processors to operate the service:
| Sub-processor | Purpose | Data transferred |
|---|---|---|
| Amazon Web Services (AWS) | Infrastructure hosting (EC2, S3) | All platform data |
| Together AI | LLM inference for error diagnosis | The error context of a diagnosed trace — its error message and stacktrace, and the prompts, completions, tool inputs and tool outputs of the spans around it. Credentials, and email, phone, SSN, card and IP patterns, are redacted before it is sent. Redaction is pattern-based and does not catch free-text personal data such as names or addresses. |
| GitHub / Google (OAuth) | Authentication | Email, public profile |
When Together AI receives anything: only when a diagnosis runs. A diagnosis runs when you ask for one on a specific trace, or — if you have asked us to turn it on for a project — automatically when a trace in that project errors. Automatic diagnosis is off by default. If neither applies, no trace content is sent to any LLM provider.
5. Data Retention
- Span and trace data: 90 days.
- Span content (prompts/completions): 90 days.
- Object-store archive of span records (a durable copy of the same spans, content included, encrypted at rest): 90 days, the same schedule as the span data it copies. Deletion requests reach it.
- Evaluation results and scorer results (automated quality scores computed about your traces): 365 days.
- Error diagnoses (when a diagnosis runs, a copy of the trace's error text is stored alongside the analysis): the analysis — root cause, error classification, confidence and suggested fixes — is kept for the life of the project; the raw error text, the reasoning quoting it and the trace context behind it are removed within ninety days of the diagnosis, the same schedule as the trace they came from. Erasure requests delete the diagnosis itself; generated fix records outlive it and are removed with the project.
- Account data: retained until account deletion.
- Audit logs: 1 year minimum.
6. Your Rights (GDPR)
If you are located in the European Economic Area, you have the following rights under the General Data Protection Regulation (GDPR):
- Access & portability: request a machine-readable copy of your project’s data. We produce it as JSON Lines — your spans, traces, agent data, diagnoses, evaluations, scores, alert rules and account metadata. Email us; there is no self-service export for the full corpus today. (The dashboard’s table views offer a CSV/JSON download of what is on screen, which is a convenience, not this.)
- Rectification: correct inaccurate data.
- Erasure (“right to be forgotten”): we erase the telemetry associated with a given user, session or set of traces on request, across every store that holds it — including the object-store archive. Email us. Deleting an account is also handled by us on request rather than from the dashboard. Telemetry you submitted is otherwise deleted on the retention schedule above.
- Restriction & objection: limit or object to processing.
- Lodge a complaint: with your local supervisory authority.
To exercise any right, email support@risicare.ai. We respond within 30 days.
7. Security
Data is encrypted in transit (TLS 1.2+) and at rest with AES-256, via EBS volume encryption for databases and server-side encryption for object storage. Encryption at rest protects against physical disk access and storage-snapshot exposure; it does not by itself protect data in use on a running server. API keys are stored as SHA-256 hashes. We operate a responsible disclosure programme at security@risicare.ai.
8. Breach Response
In the event of a personal data breach, we will notify affected users and, where required by GDPR Article 33, the relevant supervisory authority within 72 hours of becoming aware.
9. Cookies
We use one session cookie (__Secure-authjs.session-token) to maintain authentication. No third-party tracking cookies are set.
10. Changes
We will notify account holders by email at least 14 days before material changes take effect. Continued use after the effective date constitutes acceptance.
11. Contact
[TBD-LEGAL: registered address]
Email: support@risicare.ai
DPO (if applicable): [TBD-LEGAL]