Data Processing Agreement
Last updated: June 2026
1. Data Controller
Ratiocine operates as the data controller for personal data collected through the web application and browser extension. For questions about this agreement or data processing practices, contact us via the channels provided on ratiocine.com.
2. Types of Data Processed
We process the following categories of data:
- Email address — collected during Google OAuth authentication for account creation and communication.
- Prompt content — text prompts and sequences you create, save, publish, or share through the service.
- Collection metadata — titles, descriptions, and ordering of grouped prompts.
- Usage data — anonymized interaction metrics for service improvement.
3. Purpose of Processing
We process your data solely for the following purposes:
- Providing account access and authentication
- Storing and syncing prompts across devices (Pro vault sync)
- Enabling publishing and sharing in the community feed
- Organizing prompts into collections
- Service maintenance, security, and support
4. Retention Periods
Data is retained according to the following schedule:
- Account data — retained until account deletion or 2 years of inactivity, whichever comes first.
- Published prompts — retained until unpublishing or account deletion. Unpublished prompts are removed from the feed immediately.
- Local data — stored in your browser and never transmitted to our servers unless explicitly published or synced via Pro vault.
- Deleted data — permanently removed from active systems within 30 days. Backups may retain encrypted copies for up to 90 days.
5. Sub-processors
We engage the following sub-processors to deliver the service:
- Supabase — cloud database, authentication, and storage infrastructure.
- Google OAuth — identity verification and authentication.
All sub-processors are bound by data protection obligations consistent with this agreement. We do not sell or transfer personal data to additional third parties for marketing or unrelated purposes.
6. Security Measures
We implement the following technical and organizational security measures:
- Encryption in transit — all data transmitted between your browser and our servers uses TLS 1.2 or higher.
- Encryption at rest — stored data is encrypted using industry-standard algorithms.
- Row-level security (RLS) — database access is restricted so users can only access their own data.
- Secure authentication — OAuth 2.0 via Google with no plain-text password storage.
- Regular access reviews — administrative access is limited and audited.